Release Notes SD-WAN 8.2.0 Collector

The Release Notes for SD-WAN 8.2.0 collector are now available (release date: 2026-04-30). Contact your Technical Account Manager, Systems Engineering Team, or Support Team to plan the installation.

Note: Terminology usage...

In SD-WAN guides if there is,

  • [any reference to master] OR
  • [[if a CLI command (for NMS or Kubernetes or Redis) contains master] AND/OR
  • [its output contains master]], it means leader or control plane.

And, if there is any reference to slave or worker, it means follower or agent.

Browser Requirements

Minimum Resolution:1200x768 Browsers:

  • Modern, standards-compliant browser
  • JavaScript enabled
  • Pop-up blocker disabled for hostname/IP

The following browsers are supported in the current versions of SevOne.

Browser

Table 1. Browser Compatibility
Vendor Family
Google Chrome
Mozilla Firefox
Important: Please use the latest browser version for Chrome and Firefox.

Resources & Requirements

Contains the following topics.
Note:

Go to the IBM SevOne Solutions Sizing Sheet GitHub repository, then download the file named SDWAN_sizing_sheet_all_vendors_8.2.0.xlsx.

Table 2. Resources & Requirements
Resource Requirement
SevOne NMS Please refer toCompatibility Matrix below for SevOne NMS versions supported.
Helm v3.18.4
Kubernetes

1.28.10+k3s1 (for upgrade and new provisioning)

Important: If the installed Kubernetes version in your setup is not supported by SD-WAN collector you are provisioning, you will get an error message. Kubernetes must be upgraded prior to upgrading SD-WAN collector.
Kernel 4.18.0-553.87.1.el8_10
Ports Required Please refer toSevOne NMS Port Number Requirements Guide > sectionSolutions Deployment.
VMware vSphere Client >=6.5
Signature Tools
Note: The latest files can be downloaded from IBM Passport Advantage (https://www.ibm.com/software/passportadvantage/pao_download_software.html) via Passport Advantage Online. However, if you are on a legacy / flexible SevOne contract and do not have access to IBM Passport Advantage but have an active Support contract, please contact SevOne Support Team for the file.

Once you have downloaded the package, unpack the fix / install / upgrade packs to obtain the required files.

  • signature-tools-v2.0.3-build.1.tgz
  • signature-tools-v2.0.3-build.1.tgz.sha256.txt
Other
Note: The latest files can be downloaded from IBM Passport Advantage (https://www.ibm.com/software/passportadvantage/pao_download_software.html) via Passport Advantage Online. However, if you are on a legacy / flexible SevOne contract and do not have access to IBM Passport Advantage but have an active Support contract, please contact SevOne Support Team for the files.

Once you have downloaded the package, unpack the fix / install / upgrade packs to obtain the required files.

Aruba EdgeConnect, Cisco SD-WAN, Fortinet, Palo Alto Prisma and VeloCloud are packaged with SevOne NMS as SD-WAN plugins.
Note: The File Type details for the SD-WAN plugins are the same as those for SevOne NMS resources. Please refer to the Third-Party Packages / Resources Required section in Release Notes SevOne NMS 8.2.0.
SD-WAN Widgets
  • sdwan-widgets-v8.2.0-build.6.tar.gz

  • sdwan-widgets-v8.2.0-build.6.tar.gz.sha256.txt

Summary for complex table

File Type Versa Viptela
TAR sevone_solutions_sdwan_versa-v8.2.0-build.24.tgz sevone_solutions_sdwan_viptela-v8.2.0-build.57.tgz
CHECKSUM sevone_solutions_sdwan_versa-v8.2.0-build.24.tgz.sha256.txt sevone_solutions_sdwan_viptela-v8.2.0-build.57.tgz.sha256.txt
OVA sevone_solutions_sdwan_versa-v8.2.0-build.24.ova sevone_solutions_sdwan_viptela-v8.2.0-build.57.ova
QCOW2 sevone_solutions_sdwan_versa-v8.2.0-build.24.qcow2 sevone_solutions_sdwan_viptela-v8.2.0-build.57.qcow2
ISO sevone_solutions_sdwan_versa-v8.2.0-build.24.iso sevone_solutions_sdwan_viptela-v8.2.0-build.57.iso
VHD sevone_solutions_sdwan_versa-v8.2.0-build.24.vhd.gz-part-1 sevone_solutions_sdwan_viptela-v8.2.0-build.57.vhd.gz-part-1

Facts & Limitations

The following notes are some facts and limitations that you must be aware of.

Note: Controllers Aruba EdgeConnect, Cisco SD-WAN, Fortinet Plugin, Prisma (Palo Alto), and VeloCloud come integrated with SevOne NMS.
Important:

Palo Alto Rate-Limiting Behavior Palo Alto enforces a rate limit of 2 API calls per second per resource per user. Successful API responses typically complete within 1.5 - 3 seconds, but latency can increase response times to 15–20 seconds per call. Under higher site load, server-side rate limiting becomes inconsistent and can result in multiple 429 (multiple requests) errors.

Capacity Projection Lab testing shows an average processing time of 18 seconds for 6 devices. Within a 5-minute polling interval, the system can reliably support:

  • Upper bound: 120 devices (under optimal conditions)

  • Lower bound: 90 devices (when accounting for performance variances)

Important: Viptela Collector: vManage rate limits

The vManage overall rate limit is 450 requests per second. Currently, it has an API route related to device statistics which has a much lower rate limit of 43 requests per minute (or 0.72 requests per second). These rate limits are used as default rates in the Viptela collector configuration.

For the Viptela collector, each Agent has a vManage session.

Please refer to https://developer.cisco.com/docs/sdwan/#!browsing-returned-results-sorting-results-filtering-results-and-rate-limits/understanding-pagination for details.

Important: Viptela Collector: vManage data (Case change for names)

Collector handles the case change scenario for vManage data. Migration script removes the device / object group rules and adds new case-insensitive rules in the next run of deviceDescription / objectDescription agent.

Limitations:
  • Collector handles the case change only and not a complete name change.
  • In case of device name changes, collector does not change the actual device name in SevOne NMS. However, it keeps pushing data in the existing device.
  • In case of site / tenant name changes, collector does not update the device / object group name in SevOne NMS. However, it holds all the devices / objects available in the group.
  • In case of interface name changes, collector does not update the interface, interface queue, or tunnel name. However, it keeps pushing data for that object.
  • Collector does not support a scenario in which the device / interface name is same with a case difference in vManage. For example, device names, abc and ABC are not allowed.
Important: Viptela / Versa Collector

When upgrading the collector from a newly deployed SD-WAN 2.9 or SD-WAN 2.10 OVA to SD-WAN 8.2.0, please perform the steps mentioned in SD-WAN Viptela Collector Troubleshooting Guide or SD-WAN Versa Collector Troubleshooting Guide > section Upgrade Collector.

Important: Versa Collector

Tunnel data is coming from two different sources (sdwanB2BSlamLog and monStatsLog). Hence, the data gap might be visible in SevOne NMS.

Compatibility Matrix

Table 3. Compatibility Matrix
Platform / Component Versions supported (T – Tested & S – Supported)
SevOne NMS

8.2.0 (T & S)

8.1.0 (T & S)

REST API 2.1.47
Widget Version 8.2.0
SevOne Data Insight 8.2 (T & S)

CONTROLLERS

Table 4. CONTROLLERS
Controller Versions supported (T – Tested & S – Supported)
Aruba EdgeConnect
  • 9.6.0 (T & S)
  • 9.5.3 (S)
  • 9.4.1 (T & S)
  • 9.3.6 (T & S)
Cisco SD-WAN
  • 20.16.1 (S)
  • 20.15.4.2 (T & S)
  • 20.12.5 (T & S)
  • 20.3.5 (T & S)
Fortinet
  • v7.6.6 FortiManager (T & S)
  • v7.6.4 FortiManager (S)
  • v7.6.2 FortiManager (T & S)
  • v7.4.5 FortiManager (T & S)
  • v7.2.12 FortiManager (T & S)
  • v7.4.10 FortiManager (T & S)
Prisma (Palo Alto)
  • 6.5.1-b5 (T & S)
VeloCloud
  • VMware SASE 6.4.1.1 (T & S)
  • VMware SASE 6.4.1.0 (T & S)
  • VMware SASE 6.4.0.2 (T & S)
  • VMware SASE 5.4.0.1 (T & S)
  • VMware SASE 5.4.0.0 (S)
Table 5. Collector Controllers
Controller Type Versions supported (T – Tested & S – Supported)
Versa n/a
  • 22.1.4 (T & S)
  • 22.1.2 (S)
  • 21.2.3 (T & S)
  • 21.1.4 (T & S)
Viptela vManage
  • 20.18.1 (T &S)
  • 20.15.4.2(S)
  • 20.12.5 (S)
  • 20.16.1 (S)
  • 20.13.1 (S)
  • 20.12.4.1 (S)
  • 20.11.1.1 (T & S)
  • 20.9.4 (S)
  • 20.9.1 (S)
  • 20.6.4 (T & S)
  • 20.6.2.1 (S)
  • 20.5.1.2 (S)
  • 20.5.1 (S)
  • 20.4.1.1 (S)
  • 20.3.6 (S)
  • 20.3.5 (T & S)
  • 20.3.4.1 (S)
  • 20.3.4 (S)
  • 20.3.3.1 (S)
  • 20.3.1 (S)
  • 20.1.1 (S)
  • 19.2.2 (S)
vEdge
  • 20.3.5 (T & S)
  • 20.9.7 (T & S)
  • 20.9.8 ( T & S)
  • 20.9.1 (T & S)
cEdge
  • 17.18.01a (T & S)
  • 17.12.0.4 ( T & S)
  • 17.9.1 (T & S)
Note: Other requirements
Minimum resource needed on NMS for Versa and Viptela controllers:
  • CPU: 4 or more
  • RAM: 8GB or more
  • HDD: 20GB or more
Note: For additional details on hardware requirements such as, CPUs, RAM, flow limits, number of rack units, etc., for various hardware components, please contact your SevOne Technical Account Manager.
Note: SevOne Data Insight
  • Please refer to Release Notes SevOne Data Insight for details.

SevOne NMS

  • An administrator-level account in SevOne NMS.
  • User name and password for the administrator-level account.
  • IP address of the PAS.
  • 20k (vPAS_20K) appliance (minimum requirement).

New Features / Enhancements

Resolved Issues

Important: It is strongly recommended to run the external security scans such as Nessus, Snyk, or similar on the latest available patch for this release to verify whether the vulnerability has been addressed. If upgrading the production environment is not currently possible, these scans can still be performed in a lab or test environment.
Table 6. Resolved Issues
Component/s Key Release Notes
SDWAN Cisco Catalyst

S1NPM-77627

SevOne NMS version 6.7 is no longer supported; therefore, this ticket has been cancelled.

CVE

S1NPM-118383

Addressed CVE-2025-53547.

CVE

S1NPM-119020

Addressed CVE-2025-61726 / CVE-2025-61731.

CVE

S1NPM-119026

Addressed CVE-2025-59681.

SDWAN VeloCloud

S1NPM-119203

The Advance Health Agent was updated to validate the startTime field in the device advance health response.If the startTime value is null, the agent uses the current time and continues processing the remaining devices without error.SD-WAN objects display correctly for all devices as expected.

CVE

S1NPM-119650

Addressed CVE-2026-0994.

CVE

S1NPM-119917

Addressed CVE-2025-68458 / CVE-2025-68157.

CVE

S1NPM-120015

Addressed CVE-2025-65637.

CVE

S1NPM-120018

Addressed CVE-2025-15467.

CVE

S1NPM-120321

Addressed CVE-2026-24051.

10 issues

Known Issues

This section lists issues that SevOne is aware of in SD-WAN 8.2.0 release. Most of these issues were discovered during quality assurance testing and are published here to provide you with information that may be relevant when you plan your update. This list does not include feature requests or low impact issues that do not affect functionality. If you have questions, comments, or concerns, please contact us.

Warning: FYI
  • The default interval for the updation of the augmenter cache is 24 hours. If a policy is changed or added on vManage, it is necessary to update the cache forcefully to augment the flows correctly. Please run the PolicyParserAgent to update the cache forcefully.
    Note: Applicable to Viptela Collector only.
    • 
      kubectl exec <COLLECTOR_POD_ID> -- ./collector-viptela -run PolicyParserAgent
       
    • To find the <COLLECTOR_POD_ID>, execute the following command.
      
      kubectl get pods
       
  • Data gaps might be seen on the graphs in SevOne NMS for indicators of the objects of type SD-WAN Device Health as they are being polled at different timestamps. For example, SevOne NMS shows the data for the following indicators related to SD-WAN Device Health object.
    • memory_utilization
    • disk_utilization
    • cpu_utilization

    When querying data for these indicators from vManage, if the data is missing for any of the indicators, then the data gap might be visible in SevOne NMS.

  • If you are using SevOne NMS version < 5.7.2.23 (without the NMS-75375 hotfix), you may experience an impact on the performance of the collector. At a same time, collectors will not support tunnels > 10k.
  • Widgets
    • When the alternate name is enabled in SevOne Data Insight, Network Topology Widget 2.8.x / 2.9 does not show any tunnels for SD-WAN 2.6 collectors.
Table 7. Known Issues

Summary for complex table

Component/s Key Known Issues
SDWAN Cisco Catalyst S1NPM-77627 Viptela / Versa Collectors: When installing / upgrading the collector via GUI, you can proceed to theUpgrade SOA stage in the following scenarios:
  • Without selecting or updating the configuration file (in the Config stage).
  • Even if there are errors in the configuration file (in the Config stage).
SDWAN Solution, SDWAN Versa, SDWAN Cisco Catalyst S1NPM-100519 Platform: Depending on the scale of the environment,jaeger may quickly consume its allotted memory and in turn, restart. The maximum allotted memory can be adjusted when Jaeger is enabled.
SDWAN Solution, SDWAN Versa S1NPM-100816 Versa Collector: Tunnel objects will be pinned to their respective object groups either after 24 hours or according to the discovery schedule in SevOne NMS.
SDWAN Viptela S1NPM-101063 Viptela Collector: When updating the Installer Agent, theBFD_SESSIONS cache key gets updated based on received BFDSession data. TheTunnelStatAgent parses the BFD Session data and updates the availability and transition indicators accordingly.

If BFD Session data is not found for a specific object, the following occurs:

  • Not found bfd session for key warning string is logged in the collector logs.
  • The ApprouteStatStatistic response displays a down state for the specific objectName.
  • Empty values appear for availability and transition indicators on NMS.
  • Gaps may appear on the NMS graph for these indicators, which is expected behavior.
SDWAN Cisco Catalyst S1NPM-109664 Viptela Collector: When theNEXT_HOP_IP field is not present in a flow, the following fields will be set toUnknown.
  • Wan Path Source (4323)
  • Wan Path Source Alternate Name (4354)
  • Wan Path Destination (4323)
  • Wan Path Destination Alternate Name (4355)
  • Tunnel (4353)
  • Tunnel Alternate Name (4356)
SDWAN Solution S1NPM-112181

Platform: Interface statistics are not generated for the sub-interfaces; an expected behavior from Cisco. sdwan::device-interface objects for interfaces are created to provide interface statistics datapoints.

Since the mapping is performed for interface objects available in SevOne NMS, the ifIndex is not renamed to interface name for the sub-interfaces in Flow Interface Manager.

SDWAN VeloCloud S1NPM-112408 VeloCloud Collector: When upgrading VeloCloud from 7.0.0 or above to version 7.1.0, theVeloCloudSDWAN-DI-OOTB-Reports.tar file is still present in the/config/collectors/sdwan/velocloud/spk directory. This is an expected behavior.
SDWAN Viptela S1NPM-112547 / S1NPM-112715

Viptela Collector: After successful upgrade from version 7.1.0 to 7.1.x, the Viptela Summary Report in GUI displays a SevOne Data Insight migration error as shown below.Viptela Summary Report

Workaround: Please click on Try to load anyway to proceed with loading the report without any conflicts.

SDWAN Solution S1NPM-113717
Platform: The MetadataAgent fails to complete metadata updates for devices/objects because its runtime exceeds the default 1hour timeout limit. As a result, the metadata is not accurately reflected in the device/object with the following error.
2024-06-24T16:49:37Z ERR agent run canceled error="context deadline exceeded" agent=MetadataAgent
Workaround:
  1. Locate and change the timeout for MetadataAgent from 1h to greater than or equal to 2h (but, less than 12h) in the config file, /opt/SevOne/chartconfs/<config-file>, as shown below.
    
    collectorConfig:
    
    agent:
    
    override:
    
    MetadataAgent:
    
    timeout: 2h
     
  2. Run the below command in the collector to apply the changes.
    sevone-cli solutions reload
  3. Manually execute the below command in separate screen session, if needed , or wait for its next automatic cycle and then check the logs.
    sevone-cli solutions run_agent --deployment_name solutions-sdwan-viptela --agent_name MetadataAgent --log_level info > met...
SDWAN Cisco Catalyst S1NPM-117472

Device and object metadata may appear incomplete in SevOne NMS, with the Viptela / Versa Metadata Agent reporting the following message: 2024-06-24T16:49:37Z ERR agent run canceled error="context deadline exceeded".

SDWAN Solution S1NPM-119023

DeepDiff version 6.6.1 is bundled with Ansible 9.2.0. Ansible 9.2.0 is used by Versa and Viptela.

DeepDiff 6.6.1 contains a vulnerability that may allow denial-of-service (DoS) and remote code execution through Delta class pollution (CVE-2025-58367).

This issue affects DeepDiff versions 5.0.0 and later, but earlier than 8.6.1.

SDWAN Solution S1NPM-120406

Viptela / Versa: During new installation or upgrade, deployment may fail during the step that creates htpasswd credentials for registry keys. When this occurs, the deployment stops and does not proceed as expected to subsequent steps.

SDWAN Solution S1NPM-120423

Viptela / Versa: During a fresh installation of 8.2.0, using Graphical User Interface, configuration parameters entered in the Configuration Settings stage are not persisted. After clicking Saveor Next, the values are reset or not retained, preventing the installation from proceeding as expected.

SDWAN Solution S1NPM-120887

Upgrading the tar library from v6.x to 7.x in the widget-server (as a vulnerability fix) may cause SD-WAN widget packages to fail uploading in SevOne Data Insight, resulting in missing SD-WAN categories and widgets in the Select a Widget panel during the Create flow.

SDWAN VeloCloud S1NPM-120612

In some SevOne NMS environments, a subset of devices may display the status Never Activated, Offline, or Connected.

This behavior is not expected. When a device remains in the Never Activated state, the QoE agent starts but does not complete the load operation (Load done is not logged). As a result, SD-WAN objects are not discovered or updated.

SDWAN Viptela S1NPM-121521

Log files are unavailable in the current path because the log rotation path has changed.

For workaround, refer to Resolve log rotation failures for Viptela Collector logs in SD-WAN Viptela Collector Troubleshooting Guide.

16 issues