Skip to main content

Version: v25.04.30

hiCLOUDS SDWAN Platform Pre-Release Notes

Release Date: 1st Jun 2025

Deployment Locations

New Firmware Version: 24.10.1-b6 for CE/PE


Firmware-Version-Update

CE/PE Firmware 24.10.1-b6: To update to the latest firmware version, please contact technical support to receive the update package.


New Features

  • Bulk firmware upgrade for CE and PE devices [569]
    Firmware upgrades can now be performed simultaneously on multiple CE and PE devices with a single click. This streamlines maintenance for large networks. This feature will significantly simplify large-scale deployments, save administrator time, and improve update consistency across the network.

    Documentation for Bulk firmware upgrade for CE/PE

  • Real-time firmware upgrade status in the platform [861]
    The management UI will now display the immediate status of the firmware upgrade, indicating whether the upgrade is in progress, successful, or failed. This will provide clear visibility into the upgrade process, increase administrator confidence, and enable immediate action if issues arise.

    Documentation for CE Firmware config

    Documentation for PE Firmware config

  • Persistent Syslog support in firmware [880]
    The volatile in-memory logging was migrated to persistent file-based logging, which was erased when the device was powered off. It is now permanently saved in file form.

    Documentation for Persistent Syslog support in firmware

  • Daily Rsyslog file rotation [890]
    Automatic log file rotation has been implemented on a daily basis. This will improve log management, make troubleshooting easier, and prevent the creation of excessively large log files.

    Documentation for Daily Rsyslog file rotation

  • Auto-Extend Unused Disk Space into Log Partition [892]
    Created a method to utilize unused storage by creating a dedicated log section, which helps retain logs for longer periods of time and prevents log loss due to space limitations.

    Documentation for Auto-Extend Unused Disk Space into Log Partition

  • Separate Syslog file for forwarding traffic logs [896]
    Connection-level logging for IP tuples (src/dst IPs and ports) has been added to a separate syslog file. This will help with traffic flow analysis, security auditing, and troubleshooting.

    Documentation for Separate Syslog file for forwarding traffic logs


Improvements

  • CE Firmware Upgraded to OpenWrt 23.05.3 [64]
    CE (Customer Edge) firmware has been upgraded from OpenWrt 22.03.5 to 23.05.3. This upgrade provides enhanced kernel support, improved security patches, and updated packages.

  • CE firmware upgraded to OpenWrt 24.10.1 [853]
    The base firmware has been upgraded from OpenWrt 23.05.3 to 24.10.1, offering enhanced hardware compatibility, improved stability, and better performance.

  • CI/CD: Preserve Docker Tags in SD-WAN Cloud [860]
    Fixed an issue where Docker tags were inadvertently overwritten during a CI/CD run. Version checking has been implemented to ensure consistent deployment artifacts.


Bug Fixes

  • Index 0 Out of Bound" in Get Spoke API [840]
    Fixed an exception that occurred when retrieving spoke device data without a default LAN subnet. This API improves the robustness of the API, prevents crashes, and ensures reliable data retrieval for spoke devices.

    Documentation for Spoke

  • Global Settings URL field is missing validation [855]
    Proper frontend validation has been added to avoid malicious or invalid URLs that can break platform functionality. This prevents entries that could potentially break platform functionality or introduce security vulnerabilities.

    Documentation for Global setting

  • Revision ID Reset on Firmware Upgrade [859]
    Fixed behavior where the revision ID was unexpectedly reset after a firmware upgrade. The system now correctly maintains this ID. The revision ID is now persistently maintained through a keep-alive mechanism, which ensures proper configuration tracking and management, which is no longer maintained by configuration.

    Documentation for Firmware Upgrade

  • Save Button Not Enabled When Subnet Removed in CGW [862]
    Fixed a UI inconsistency where the Save button was not activated when editing a subnet in a Cloud Gateway (CGW) configuration.

    Documentation for CGW

  • SOCKS Proxy Not Working on OpenWrt PE [863]
    Fixed a bug where SOCKS proxy would silently fail on PE devices running OpenWrt. Now works on all supported PE variants. This resolves a critical connectivity issue, ensuring SOCKS proxy services work reliably on all supported PE variants.

    Documentation for Socks Proxy

  • Search Fails on Capitalized Backbone PE Names [864]
    Improved search functionality to be case-insensitive, enabling device searches regardless of the capitalization of the name.

    Documentation for Backbone PE

  • LDAP Filter Input Validation Broken [877]
    Server-side and client-side validation has been added for LDAP filter entries to prevent misconfigurations. This improves the reliability of LDAP integrations by ensuring that filter inputs are always valid.

    Documentation for LDAP

  • Missing "Save Config" button in VPN Authentication tab [878]
    Ensured that the Save button is rendered correctly when 'Defaults' is selected in VPN server authentication, resolving a critical UI flaw. This ensures that administrators can properly save VPN authentication settings, preventing configuration loss.

    Documentation for VPN Authentication

  • PBR Fails with 0.0.0.0/0 Prefix [898]
    Incorrect error logs have been removed for policy-based routing rules using the 0 prefix (0.0.0.0/0), which is a common configuration in routing scenarios.

    Documentation for PBR

  • PBR Rules with Src/Dst Ports Not Working [903]
    Fixed an issue where port-based PBR rules were ignored where they were not associated with an IP address. The rules now operate independently of the port only. The rules now operate independently of the IP address, allowing for more effective policy-based routing configuration.

    Documentation for PBR

  • CGW Ignored Domain Whitelist/Blacklist Traffic [909]
    Patched a firmware issue where DNS-based domain whitelisting/blacklisting was not applied properly in Cloud Gateway. This ensures that domain-based traffic filtering works as intended in v24.10.1 and onward, enhancing network security.

    Documentation for CGW


Need Help or Have Questions?

For further assistance, please contact our support team via any of the following channels:

We value your input to shape a strong final release. Thank you for your participation in our pre-release program!