Full Cisco Trademarks with Software License

THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.

THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.

The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.

NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE.

IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.

All printed copies and duplicate soft copies of this document are considered uncontrolled. See the current online version for the latest version.

Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at www.cisco.com/go/offices.

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)

About Cisco ASR 1000 Series Aggregation Services Routers

The Cisco ASR 1000 Series Routers carry a modular yet integrated design, so network operators can increase their network capacity and services without a hardware upgrade. The routers are engineered for reliability and performance, with industry-leading advancements in silicon and security to help your business succeed in a digital world that's always on. The Cisco ASR 1000 Series is supported by the Cisco IOS XE Software, a modular operating system with modular packaging, feature velocity, and powerful resiliency. The series is well suited for enterprises experiencing explosive network traffic and network service providers needing to deliver high-performance services.


Note


For more information on the features and specifications of Cisco ASR 1000 Series Routers, refer to the Cisco ASR 1000 Series Routers datasheet.

For information on the End-of-Life and End-of-Sale Announcements for Cisco ASR 1000 Series routers, refer to the ASR 1000 Series End-of-Life and End-of-Sale Notices.



Note


Cisco IOS XE Bengaluru 17.6.1a is the first release for Cisco ASR 1000 Series Aggregation Services Routers in the Cisco IOS XE Bengaluru 17.6.x release series.



Note


Starting from IOS XE 17.5, the following consolidated platforms (or with dual IOSd ) will move to monolith packaging and therefore it will not be possible to upgrade/downgrade using separate packages.

  • ASR1001-HX

  • ASR1001-X

  • ASR1002-X

  • ASR1002-HX


Instead use the command install add file bootflash:<file name> activate commit command to upgrade using a single image that combines all the separate packages therefore improving the boot time

Starting from IOS XE 17.6, the ISSU on Cisco ASR 1000 Series Aggregation Services Routers will migrate to an install workflow that provides step-by-step upgrade/downgrade commands.

The ISSU load version commands will be deprecated and these commands include:

  • abortversion,

  • acceptversion,

  • checkversion

  • commitversion

  • config-sync

  • image-version

  • loadversion

  • runversion

Additionally, dual IOSd ISSU commands and Bundle mode ISSU workflows will also be disabled.


Note


The In-Service Software Upgrade (ISSU) in ASR 1000 is being migrated to an install workflow that provides a step-by-step upgrade/downgrade. Starting from IOS-XE 17.6.1a, the following items will be disabled:

  • The ISSU load version command set including issu loadversion , issu runversion , issu acceptversion and issu commitversion

  • Dual IOSd ISSU commands

  • Bundle mode ISSU workflow



Note


Starting with Cisco IOS XE 17.3.x, with the introduction of Smart Licensing Using Policy, even if you configure a hostname for a product instance or device, only the Unique Device Identifier (UDI) is displayed. This change in the display can be observed in all licensing utilities and user interfaces where the hostname was displayed in earlier releases. It does not affect any licensing functionality. There is no workaround for this limitation.

The licensing utilities and user interfaces that are affected by this limitation include only the following:

  • Cisco Smart Software Manager (CSSM),

  • Cisco Smart License Utility (CSLU), and

  • Smart Software Manager On-Prem (SSM On-Prem).


Product Field Notice

Cisco publishes Field Notices to notify customers and partners about significant issues in Cisco products that typically require an upgrade, workaround or other user action. For more information, see https://www.cisco.com/c/en/us/support/web/field-notice-overview.html.

We recommend that you review the field notices to determine whether your software or hardware platforms are affected. You can access the field notices from https://www.cisco.com/c/en/us/support/web/tsd-products-field-notice-summary.html#%7Etab-product-categories.

New and Changed Software Features in Cisco IOS XE 17.6.8a

There are no new software features in this release.

New and Changed Software Features in Cisco IOS XE 17.6.6a

There are no new features in this release. This release provides a fix for CSCwh87343: Cisco IOS XE Software Web UI Privilege Escalation Vulnerability. For more information, see the Security Advisory: cisco-sa-iosxe-webui-privesc-j22SaA4z.

New and Changed Software Features in Cisco IOS XE 17.6.5a

There are no new features in this release. This release provides a fix for CSCwh87343: Cisco IOS XE Software Web UI Privilege Escalation Vulnerability. For more information, see the Security Advisory: cisco-sa-iosxe-webui-privesc-j22SaA4z.

New and Changed Software Features in Cisco IOS XE 17.6.5

There are no new software features in this release.

New and Changed Software Features in Cisco IOS XE 17.6.4

There are no new software features in this release.

New and Changed Software Features in Cisco IOS XE 17.6.3a

There are no new software features in this release.

New and Changed Software Features in Cisco IOS XE 17.6.2

There are no new software features in this release.

New and Changed Software Features in Cisco IOS XE 17.6.1a

Table 1. New Software Features in Cisco 1000 Series ASR Release Cisco IOS XE 17.6.1a

Feature

Description

Asymmetric Lease for DHCPv6 Relay Prefix Delegation:

This feature allows you to manage or change the lease renewal. It provides options to force renewal of lease and also detects when the lease is nearing the expiry date.

BGP Serviceability Enhancements for EVPN and MVPN

This feature includes the following enhancements

  • MAC address format for Type-2 EVPN routes: This enhancement provides three different Mac address formats suitable for various components such as L2RIB, CEF and EVPN.

  • EVPN Type-2 and Type-5 Routes Checking: This enhancement provides an updated output for the show ip bgp l2vpn evpn command. The updated output removes redundant keywords for Type-2 and Type-5 routes, and filters and retrieves matching routes based on both MAC and IP address.

  • MVPN/EVPN Routes Check Simplification: With this enhancement, users can avoid manual re-typing of key fields and directly copy details from the show ip bgp l2vpn evpn and show ip bgp ipv4 mvpn summary outputs.

Best Practices for Increased Scaling of IS-IS Neighbors

This enhancement introduces commands that let you configure increase scaling of neighbors in a hub and spoke deployment using the following criterions

  • Reducing flooding over parallel peer to peer links

  • Staggered synchronization of adjacencies after router reload

  • Configuring CLNS queue size and monitoring CLNS and IS-IS queues

BMP Per-Peer Header Timestamp:

  • By default, the BMP messages with per-peer header contain timestamps. The system time is used as a timestamp in these messages. To notify users about this enhancement, the show ip bgp bmp server summary command output includes the message - "BGP Message Timestamp will be sent to BMP Servers".

  • CFM operation and action model: This feature introduces a NETCONF/YANG model to perform the following functions:

    • Display Ethernet CFM maintenance-points data for local MEP, local MIP, remote MEP, or database.

    • Activate or deactivate CFM latching loopback and start or stop OAM remote loopback.

    • This model helps you to gain more visibility into the timing of the service operations and manage network devices from a centralised orchestration application such as Cisco DNAC.

      For more information, see Programmability Configuration Guide.

IEEE802.1ad Support on Port-channel and Subinterfaces:

This feature supports configuring IEEE802.1ad on port-channel, port-channel subinterfaces and port-channel member links with configurable ethertypes, in addition to configuration on physical interfaces.

L2VPN Traffic SteeringUsing SR-TE Preferred Path

This feature allows you to configure an SR policy as the preferred path for a VPWS or VPLS pseudowire. VPWS or VPLS pseudowires between same PEs can be routed over different SR policies based on the requirements.

Pyang version 2.x

The updated pyang plugin version 2.x fixes existing issues such as XPATH validation and upstream pyang issues. Additionally, this version reports all errors in the YANG models to the users and enforces a strict model validation.

Redistribution of leaked routes into BGP:

  • Allows you to leak (or replicate) routes between the global VRF and service VPNs, and redistribute the leaked routes into the destination protocol BGP. The redistribution of the leaked routes occurs after replicating the routes into the corresponding VRF. Route leaking allows you to share common services that multiple VPNs need to access. The source protocols that support route leaking and redistribution of routes into the destination protocol BGP are as follows:

    • Connected

    • Static

    • BGP

    • OSPF

    • EIGRP

Secure Factory Reset:

The Secure Factory Reset feature introduces the factory-reset secure all command that you can use to erase the contents of the bootflash memory, and securely reset the device using 3-pass overwrite method.

Zone-Based Firewall Reclassification:

The Zone-Based Firewall (ZBFW) Reclassification feature is an enhancement to the Zone-Based Firewall feature. With this enhancement, any changes you make to the policy configuration on an existing firewall session is immediately enforced.

Voice: Class of Restriction YANG Configuration Model:

YANG models were developed for the following CLIs as part of the Class of Restriction configuration:

  • dial-peer voice <tag> pots/voip corlist

  • dial-peer voice vad

  • dial-peer cor custom name <string>

  • dial-peer cor list <string> member <string>

  • voice num-exp <string1> <string2>

  • voice register pool <string> [no] cor {incoming | outgoing} cor-list-name {cor-list-number starting-number [- ending-number] | default}

Table 2. New Software Features in Cisco 1000 Series ASR Release Cisco IOS XE 17.6.2

Feature

Description

Snapshots for PAK Licenses

The library that manages product activation key (PAK) licenses is being deprecated from the software image. To continue supporting and honouring any existing PAK licenses you may have, the system automatically takes a snapshot of the PAK license and triggers a Device-Led Conversion process, to convert the PAK license to a Smart License. For the system to take the snapshot, the software version running on your device must be one of the required releases.

For information about the releases in which the system can take a snapshot, and the options that are available with respect to the device and the license, see Snapshots for PAK Licenses.


Note


From Cisco IOS XE Bengaluru 17.6.x, configuring a weak crypto algorithm generates a warning message. However, you can ignore this warning because the working of crypto algorithms is not impacted. For more information on weak crypto algorithms, see Supported Standards.


Cisco Bug Search Tool

Cisco Bug Search Tool (BST) is a gateway to the Cisco bug-tracking system, which maintains a comprehensive list of defects and vulnerabilities in Cisco products and software. The BST provides you with detailed defect information about your products and software.

Resolved and Open Bugs for Cisco IOS XE Bengaluru 17.6.x

Resolved Bugs in Cisco IOS XE 17.6.8a

There are no resolved bugs for this release.

Open Bugs in Cisco IOS XE 17.6.8a

There are no open bugs in this release.

Resolved Bugs in Cisco IOS XE Bengaluru 17.6.7

All resolved bugs for this release are available in the Cisco Bug Search Tool.

Bug ID

Description

CSCwh73350

Device keeps crashing when processing a firewall feature.

CSCwh99399

FTMD crash observed in the device while running the PWK suite.

CSCvo01546

NHRP reply processing may dequeue an unrelated request.

CSCwh49644

CSDL compliance failure: use of 3DES by IPSec is denied.

CSCwi01046

PoE module is not providing enough power to bring up the ports after an unexpected reload.

CSCwh01425

ITU channel configuration seems not working on the device.

CSCwh20577

Crashed by TRACK Client thread at access to an invalid memory location.

CSCwh70449

PMTUD incorrectly converging without attempting to learn a higher MTU.

CSCwi59202

MFG Manhattan C-NIM-2T with SwitzerCC can't boot up in the operating system.

CSCwf34171

configure replace command fails due to the license udi PID XXX SN:XXXX line on devices.

CSCwh36801

Crash in IP input process during tunnel encapsulation.

CSCwf99947

Crash when modifying the tunnel after running show crypto commands.

CSCwh26209

Device crashed with no microcode due to possible dataplane memory corruption in the NAT client.

CSCwh30377

Device's data plane crash in DNS processing due to incorrect UDP length.

CSCwf89154

EZMAN posted stats to APIs: ingress and egress byte counters suddenly jump for sub-interfaces.

CSCwi28781

EPBR will generate an error when the policy is added and deleted multiple times.

Open Bugs in Cisco IOS XE 17.6.7

There are no open bugs for this release.

Open Bugs in Cisco IOS XE Bengaluru 17.6.6a

Caveat ID Number

Description

CSCwe37016

The output rate on port channel does not match with the total physical interface output rate.

CSCwh14083

High CPU due to MPLS MIB poll.

CSCwd16559

ISG FFR: ARP request to reroute nexthop IP is not triggered if ARP entry not in ARP table.

CSCwf99647

SRTP cipher failure for RTCP packets when AEAD_AES_256_GCM Cipher is used for call.

CSCwh21376

Unable to disable the call-home feature on devices.

CSCwb51779

Cisco IOS XE software privilege escalation vulnerability.

CSCwe93070

Tracebacks seen when configuring VRF with 32 characters or more.

CSCwf80400

IOS XE router may experience unexpected reset while executing show utd engine standard statistics.

CSCwd46688

Unable to apply the service policy on tunnel interface.

CSCwf55243

Device is crashing while adding a trustpoint to the router.

CSCwe29301

AOM objects (FMAN_OBJ_ACL_REF) might be missing intermittently after MMA flapping.

CSCwe90119

Device-tracking database entry stuck on UNKNOWN state with temporal mac address.

CSCwh15021

QFP crash when configuring S2S VPN (IKEv2/IPSEC) with Azure vWAN/HUB.

CSCwf55145

SFP transceiver DOM not working after some time, however interface forwards the traffic as expected.

CSCvu85539

Unable to delete wrong interface name.

CSCwd97212

UNIX-EXT-SIGNAL: Segmentation fault(11), Process = IOSXE-RP punt service process.

CSCwe14885

VPN is established although the peer is using a revoked certificate for authentication.

CSCwc67429

CTS PI changes for adding new binding source priority for LISP sourced local host bindings.

CSCwh45169

Unexpected reboot while dispalying information from cleared SSS session.

CSCwb99084

OMP routes carrying prepended AS_PATH incorrectly imported into BGP at remote site.

CSCwh49644

CSDL Compliance failure : Use of 3DES by IPSec is denied.

CSCwe91898

Environmental syslog is not appearing when power cord is disconnected from the redundant PS.

CSCwb89958

Unified Policy HSL not sending properly NBAR application information.

CSCvz68895

The device crashed after adding trustpoint

CSCvz32960

%IOSXE-3-PLATFORM: R0/0: /usr/sbin/pkg_to_tree: Failed to parse the key record 0. (28).

CSCwf95535

Intf/System xml files are not generated on device.

CSCwf99947

Crash when modifying tunnel after running show crypto commands.

CSCwd16419

Device unexpected reload generates PUBD core.

CSCwd97077

Device leaking memory in MallocLite because of telemetry subscription to collect FNF cache.

CSCwf78735

Device uses the NIM-1T/4T card for interconnection, and NAT+ GRE over ipsec cannot be applied.

CSCvy94747

GRACEFUL-RELOAD: Wrong state: 1 to recieve chasfs event.

CSCwh12093

SOS/ROC Feature on NIM.

CSCwh30377

Device data plane crash in Umbrella/OpenDNS processing due to incorrect UDP length.

CSCwf34171

configure replace command fails due to the license udi PID XXX SN:XXXX line on IOS-XE devices.

CSCwh45579

Unexpected reload on device UCode core @l2_dst_output_goto_output_feature_ext_path.

CSCvz82148

%CRYPTO_SL_TP_LEVELS-6-VAR_NEW_VALUE message is observed in each write config with same crypto value.

CSCwf80191

Flowspec on device won't revoke.

CSCwh00963

Unable to migrate from ADSL to VDSL without reboot on device.

CSCwf41084

Extranet multicast code improvements for better handling of data structure.

CSCwc87565

Unexpected reload due to a watchdog on the kernel.

CSCwf00276

Packets with L2TP headers cause device to crash.

CSCwd05362

Performance issue on device.

CSCwe85301

Crypto PKI-CRL-IO_0 process crash when PKI trustpoint is being deleted.

CSCwh42119

UCode crash when ZBFW is configured on inside interfaces.

CSCwf71557

IPv4 connectivity over PPP not restored after reload.

CSCwh01738

Unexpected reload when using rsh/rcmd.

CSCwf59929

CTS CORE process crash after configuring role based ACL.

CSCwh35397

Intermittent one way audio on RTP to SRTP calls with SSRC and seq num changes.

CSCwh20577

Crashed by TRACK Client thread at access invalid memory location.

CSCwe21703

DMI for RESTCONF/NETCONF enters degraded state due to discriminator configured.

CSCvz20285

Image info not updated in packages.conf when upgrading in autonomous mode.

CSCwf60120

Static NAT entry gets deleted from running config; but remains in startup config.

CSCwf26494

BDI + NTP configuration puts DMI process in degraded mode.

CSCwh25168

CPLD upgrade failed error message logged during ROMmon upgrade.

CSCvz38859

GD:Cu/Fiber SFP port Te0/0/2 down, PHY UP but MAC down (intermittent and after multiple iterations).

CSCwf80191

Flowspec on device won't revoke.

CSCwd38626

Repeating SYS-2-PAK_SUBBLOCK_BADSIZE: 4 -Process= &lt;interrupt level&gt;.

CSCwb55514

Unexpected reboot of the ESP seen after enabling platform qos port-channel-aggregate.

CSCwh26209

Router crashed with no ucode due to possible dataplane memory corruption in NAT client.

CSCwh45579

Unexpected reload on device UCode core @l2_dst_output_goto_output_feature_ext_path.

CSCwa52627

Incorrect Tx/Rx optical power values reported for QSFP transceivers.

CSCwe25815

Crash due to DTL push/pop on wait loop.

CSCwd02329

Router crash observed after add delay protetion - macsec_macsec_next_pn_ret_msg_message_handler.

CSCwf51206

EVPN: BUM traffic is not flooded to bridge domain interface.

CSCwf47789

dot3StatsDuplexStatus gives unknown for tengig and gig interfaces.

CSCvz68277

%IOSXE_EPA-3-SPA_PORT_NUM_FAILURE: Failure in getting SPA port number.

CSCwf25735

Device QoS more than four remark with set-cos not work.

CSCwf48967

Failure to upgrade FPGA version to standby RP module.

CSCwf97285

Router switched to Software TCAM with enough HW TCAM space.

CSCwf99947

Crash when modifying tunnel after running show crypto commands.

CSCwf00276

Packets with L2TP headers cause device to crash.

CSCwh42119

UCode crash when ZBFW is configured on inside interfaces.

CSCwd34941

NAT configuration with no-alias option is not preserved after reload.

CSCwe24491

Static NAT with HSRP stops working after removing/adding standby.

CSCwd94495

SSM On-Prem responds with message completed to poll_id requests without ACK data.

Resolved Bugs in Cisco IOS XE Bengaluru 17.6.6

Caveat ID Number

Description

CSCwe09745

Memory leak in PUBD when continuously trying to connect to remote peer.

CSCwd63063

Standby BGP session receives incorrect routes from Active.

CSCwe19084

NAT: Traffic is not translated to the same global address though PAP is configured.

CSCwd90168

Unexpected reload after running show voice dsp command while an ISDN call disconnects.

CSCwe60059

Crash when using dial-peer groups with STCAPP.

CSCwe24210

SNMP MIB does not show correct firmware version for device LTE module.

CSCwe09805

OID for SNMP monitoring of DSP resources are not working as expected.

CSCwb81159

L2RIB thread crash when updating the MAC-IP.

CSCwe36122

ISIS crash when performing TI-LFA calculation.

CSCwf03193

Device crash with crashinfo files were generated with Segmentation fault, Process IPSec key engine.

CSCwf59173

Segmentation fault at IPv6 BGP backup route notification.

CSCwe10905

vBond tracker.

CSCwd88554

Filesystem Leak on Standby Switch of device SVL Setup.

CSCwe20008

[Device LTE] SNMP MIB OID changing its last index.

CSCwf00769

L2RIB Thread crash after removing EVPN member from bridge domain.

CSCwf39552

Segmentation fault by process mDNS on device.

CSCwf83301

Device displays incorrect values for Call Quality statistics (RTT/MOS).

CSCwe72462

Username/Password under voice register pool gets deleted post CME reload.

CSCwe25006

An unexpected removal of the underlay S,G entry resulting ~20s disruption in the multicast flow SDA.

CSCwe21042

NBAR DP traceback - "Failed to process non-graph batch message: wrong batch id" is logged.

CSCwf47796

NHRP cache entries flood matching a /32 default route.

CSCwe32862

Router IOS-XE crash while executing AES crypto functions.

CSCwf09758

Watchdog crash while importing a large CRL file into switch.

CSCwf67564

Device observes Memory Leak at process SSS Manager.

CSCvy87339

Telemetry subscription fails to connect to grpc receiver when multiple XPATH changes are made to it.

CSCwe41946

DTMF is failing through IOS MTP during call on-hold.

CSCvq81894

Check Nexthop reachability before installing route for a prefix.

CSCwe52796

Intermittent one way audio issue after hold and resume. SRTP to RTP.

CSCvz12193

SNMP Walk: Authentication failure, with MD5 SNMPv3 user.

CSCwd09685

Memory leak found @nfra/green/cep/src/cep.c.

CSCwe64213

[Autorp]: LSPVif removal on OIF for RP discovery group 224.0.1.40 with timing related trigger.

CSCwf47563

Device is crashing after importing the trustpoint with rsakeypair.

CSCwe12194

Auto-Update Cycle incorrectly deletes certificates.

CSCwe33793

Memory allocation failure with extended antireplay enabled.

CSCwd59423

Unexpected Reload on device caused by WNCD process after removing a VLAN from a VLAN-GROUP.

CSCwc03176

Device crashes when applying a service-policy to a newly created tunnel.

CSCwa96399

Configuring entity-information xpath filter causes syslogs to print, does not return data.

CSCwh04884

VC Down due to control-word negotiation.

CSCwc24044

IOS XE device may experience an unexpected reset with high volume of multicast.

CSCwb47153

Keyman process crash.

CSCwb59052

Observe traceback message when BVM client do Inter-xTR roaming.

CSCwd73783

Observed qfp-ucode-wlc crash.

CSCwf14135

SIPREC recording fails in transfer scenario when certian options are enabled in configuration.

CSCwf56463

IOS process crash during VRRP hash table lookup.

CSCwf44649

LISP failed to recreate the more specific away table entries after less specific entries toggled.

CSCwe23150

CUBE memory leak sdp_copy_all_attrs sdp_parse_attribute sdp_add_new_attr.

CSCwf48808

FlexVPN: stale client routes stuck in RIB on FlexServer.

CSCwf39490

MCID (Malicious Call Identification) gets broken due to Custom prefix setting under STCAPP FAC.

CSCwa92418

hide cisco-smart-*.yang from device by adding tailf:hidden full​ annotations.

CSCwd99921

IOS XE software crash while validating certification trust.

CSCvy14316

MPLS VPN traffic dropped due FDB OOM with cause FIAError under scale flow number (<1M).

CSCwe69783

Device can lose its config during a triggered resync process if lines are in an off-hook state.

CSCwc56033

Not triggering any alarms when RPM of a fan is 0.

CSCwf08019

TACACS+ authentication stops working after changing AES encryption key on the WLC.

CSCwe36743

Segmentation Fault - Crash - SSH - When Changing AAA Group Configs.

CSCwe41234

Device VMWI race condition causes no ringing for analog phones.

CSCwf55830

No Dial Tone on analog phones due to DSP going into Power Denial state.

CSCwc97579

Spoke-spoke cache refresh not working correctly in case of multiple cache entries for same next hop.

CSCwf41082

MallocLite emory Leak observed in HTTP CORE allocator.

CSCwh11858

Switch running IOS-XE crashes when removing FQDN ACL.

CSCwc89823

Router Crashes Due to CPUHOG When Walking ciscoFlashMIB @snmp_platform_get_flash_file_info.

CSCwf29859

Logging in get-config processing affecting the template push fail.

CSCwd28734

Device memory leak in pubd causes switch reload.

CSCwf27815

DSP resource can not be release after end the call.

CSCuq20562

ISDN Memory Leak when PRI link flaps, crashes router.

CSCwf01986

Radius attribute 31 not being sent on device for CTS Pac provisioning.

CSCwf03292

I/O middle pool leaking when VOIP trace is enabled.

CSCwe66318

NAT entries expire on standby router.

CSCwh05407

Gateway disconnecting incoming calls when FPI Correlator is not released after disconnect on PRI Leg.

CSCwe39011

GARP on port up/up status from router is not received by remote peer device.

CSCwf14589

IOS-XE switch may experience a segmentation fault with L2VPN EVPN when clearing duplicate MAC.

CSCwe70237

CUBE reloads due to a segmentation fault in CCSIP_SPI_CONTROL process.

CSCwd12330

Invalid TCP checksum in SYN flag packets passing through router.

CSCwf24164

NetFlow stops working when flow monitor reaches cache limit in device.

CSCwd49177

ISG: L2-connected subscriber: IPv6 prefix delegation is not reachable when packet are switched.

CSCwf08698

Device crashes unexpectedly due to a fault in the 'TLSCLIENT_PROCESS'.

CSCwe22838

ARP is not completing on interface having CISCO-OPLINK SFP.

CSCwd81240

CPU utilization from the Linux kernel is at 100% due to btelnet.

CSCwa20942

Seeing traceback in device after test_add_delete_modify_multiple_geo_filer_rules .

CSCwe80684

QFP ucode crash when clearing MACs under BD in EVPN scenario.

CSCwe53849

Observed crash in CPP, UCode & FMAN while upgrading with crypto module present.

CSCwe22353

IpFormatErr drops on device when bridge-domain/EVC MAC learning limit is exhausted.

CSCwc03478

vTCP does not support L2 correctly.

CSCwd81813

startup-config not parsed correctly after upgrading.

CSCwd93401

AppNav-XE: Policy-map edit on cluster with multiple service context fails to program TCAM.

CSCwf45769

Ingress and Egress Bytes counters can suddenly increase and are not accurate for Sub-Interfaces.

CSCwe18124

MACsec remains marked as SECURED, but randomly the traffic stops working.

CSCwd76648

Port-channel DPI Load-Balancing not utilizing all the member-links.

CSCvr90635

Output of show dmvpn detail is not matching the output of show nhrp group.

CSCwe34808

FMAN FP leak due to the punt-policer command.

Open Bugs in Cisco IOS XE Bengaluru 17.6.6

Caveat ID Number

Description

CSCwe37016

The output rate on port channel does not match with the total physical interface output rate.

CSCwh14083

High CPU due to MPLS MIB poll.

CSCwd16559

ISG FFR: ARP request to reroute nexthop IP is not triggered if ARP entry not in ARP table.

CSCwf99647

SRTP cipher failure for RTCP packets when AEAD_AES_256_GCM Cipher is used for call.

CSCwh21376

Unable to disable the call-home feature on devices.

CSCwb51779

Cisco IOS XE software privilege escalation vulnerability.

CSCwe93070

Tracebacks seen when configuring VRF with 32 characters or more.

CSCwf80400

IOS XE router may experience unexpected reset while executing show utd engine standard statistics.

CSCwd46688

Unable to apply the service policy on tunnel interface.

CSCwf55243

Device is crashing while adding a trustpoint to the router.

CSCwe29301

AOM objects (FMAN_OBJ_ACL_REF) might be missing intermittently after MMA flapping.

CSCwe90119

Device-tracking database entry stuck on UNKNOWN state with temporal mac address.

CSCwh15021

QFP crash when configuring S2S VPN (IKEv2/IPSEC) with Azure vWAN/HUB.

CSCwf55145

SFP transceiver DOM not working after some time, however interface forwards the traffic as expected.

CSCvu85539

Unable to delete wrong interface name.

CSCwd97212

UNIX-EXT-SIGNAL: Segmentation fault(11), Process = IOSXE-RP punt service process.

CSCwe14885

VPN is established although the peer is using a revoked certificate for authentication.

CSCwc67429

CTS PI changes for adding new binding source priority for LISP sourced local host bindings.

CSCwh45169

Unexpected reboot while dispalying information from cleared SSS session.

CSCwb99084

OMP routes carrying prepended AS_PATH incorrectly imported into BGP at remote site.

CSCwh49644

CSDL Compliance failure : Use of 3DES by IPSec is denied.

CSCwe91898

Environmental syslog is not appearing when power cord is disconnected from the redundant PS.

CSCwb89958

Unified Policy HSL not sending properly NBAR application information.

CSCvz68895

The device crashed after adding trustpoint

CSCvz32960

%IOSXE-3-PLATFORM: R0/0: /usr/sbin/pkg_to_tree: Failed to parse the key record 0. (28).

CSCwf95535

Intf/System xml files are not generated on device.

CSCwf99947

Crash when modifying tunnel after running show crypto commands.

CSCwd16419

Device unexpected reload generates PUBD core.

CSCwd97077

Device leaking memory in MallocLite because of telemetry subscription to collect FNF cache.

CSCwf78735

Device uses the NIM-1T/4T card for interconnection, and NAT+ GRE over ipsec cannot be applied.

CSCvy94747

GRACEFUL-RELOAD: Wrong state: 1 to recieve chasfs event.

CSCwh12093

SOS/ROC Feature on NIM.

CSCwh30377

Device data plane crash in Umbrella/OpenDNS processing due to incorrect UDP length.

CSCwf34171

configure replace command fails due to the license udi PID XXX SN:XXXX line on IOS-XE devices.

CSCwh45579

Unexpected reload on device UCode core @l2_dst_output_goto_output_feature_ext_path.

CSCvz82148

%CRYPTO_SL_TP_LEVELS-6-VAR_NEW_VALUE message is observed in each write config with same crypto value.

CSCwf80191

Flowspec on device won't revoke.

CSCwh00963

Unable to migrate from ADSL to VDSL without reboot on device.

CSCwf41084

Extranet multicast code improvements for better handling of data structure.

CSCwc87565

Unexpected reload due to a watchdog on the kernel.

CSCwf00276

Packets with L2TP headers cause device to crash.

CSCwd05362

Performance issue on device.

CSCwe85301

Crypto PKI-CRL-IO_0 process crash when PKI trustpoint is being deleted.

CSCwh42119

UCode crash when ZBFW is configured on inside interfaces.

CSCwf71557

IPv4 connectivity over PPP not restored after reload.

CSCwh01738

Unexpected reload when using rsh/rcmd.

CSCwf59929

CTS CORE process crash after configuring role based ACL.

CSCwh35397

Intermittent one way audio on RTP to SRTP calls with SSRC and seq num changes.

CSCwh20577

Crashed by TRACK Client thread at access invalid memory location.

CSCwe21703

DMI for RESTCONF/NETCONF enters degraded state due to discriminator configured.

CSCvz20285

Image info not updated in packages.conf when upgrading in autonomous mode.

CSCwf60120

Static NAT entry gets deleted from running config; but remains in startup config.

CSCwf26494

BDI + NTP configuration puts DMI process in degraded mode.

CSCwh25168

CPLD upgrade failed error message logged during ROMmon upgrade.

CSCvz38859

GD:Cu/Fiber SFP port Te0/0/2 down, PHY UP but MAC down (intermittent and after multiple iterations).

CSCwf80191

Flowspec on device won't revoke.

CSCwd38626

Repeating SYS-2-PAK_SUBBLOCK_BADSIZE: 4 -Process= &lt;interrupt level&gt;.

CSCwb55514

Unexpected reboot of the ESP seen after enabling platform qos port-channel-aggregate.

CSCwh26209

Router crashed with no ucode due to possible dataplane memory corruption in NAT client.

CSCwh45579

Unexpected reload on device UCode core @l2_dst_output_goto_output_feature_ext_path.

CSCwa52627

Incorrect Tx/Rx optical power values reported for QSFP transceivers.

CSCwe25815

Crash due to DTL push/pop on wait loop.

CSCwd02329

Router crash observed after add delay protetion - macsec_macsec_next_pn_ret_msg_message_handler.

CSCwf51206

EVPN: BUM traffic is not flooded to bridge domain interface.

CSCwf47789

dot3StatsDuplexStatus gives unknown for tengig and gig interfaces.

CSCvz68277

%IOSXE_EPA-3-SPA_PORT_NUM_FAILURE: Failure in getting SPA port number.

CSCwf25735

Device QoS more than four remark with set-cos not work.

CSCwf48967

Failure to upgrade FPGA version to standby RP module.

CSCwf97285

Router switched to Software TCAM with enough HW TCAM space.

CSCwf99947

Crash when modifying tunnel after running show crypto commands.

CSCwf00276

Packets with L2TP headers cause device to crash.

CSCwh42119

UCode crash when ZBFW is configured on inside interfaces.

CSCwd34941

NAT configuration with no-alias option is not preserved after reload.

CSCwe24491

Static NAT with HSRP stops working after removing/adding standby.

CSCwd94495

SSM On-Prem responds with message completed to poll_id requests without ACK data.

Open Bugs in Cisco IOS XE 17.6.5a

Caveat ID Number

Description

CSCwd90168

Unexpected reload after running show voice dsp command while an ISDN call disconnects.

CSCwc03478

VTCP does not support L2 correctly.

CSCwa52627

Incorrect Tx/Rx optical power values reported for QSFP transceivers.

CSCwd89338

Clear ISG existing lite-session upon reception of DHCP packet for same client.

CSCwd71458

Outgoing number of bytes decrease in router interface.

CSCvr90635

Output of show dmvpn detail is not matching the output of show nhrp group .

CSCwd34941

NAT configuration with no-alias option is not preserved after reload.

CSCvq81894

Check nexthop reachability before installing route for a prefix.

CSCwb99084

OMP routes carrying prepended AS_PATH incorrectly imported into BGP at remote site.

CSCwb89958

Unified Policy HSL not sending properly NBAR application information.

CSCwd59722

Unexpected reboot due to IOSXE-WATCHDOG: Process = Crypto IKMP.

CSCwd97077

Device leaking memory in MallocLite because of show platform software flow .

CSCwd81240

CPU utilization from the Linux kernel is at 100% due to btelnet.

CSCwc56033

Not triggering any alarms when RPM of a fan is 0.

CSCwa96399

Configuring entity-information xpath filter causes syslogs to print, does not return data.

CSCwd93401

AppNav-XE: Policy-map edit on cluster with multiple service context fails to program TCAM.

CSCwd81813

startup-config not parsed correctly after upgrade.

CSCwd82460

QFP ucode crash due to invalid RLB descriptor.

CSCwd88715

ucode crash during CVLA routines trying to merge a free block.

CSCwb55514

Crash seen after enabling platform qos port-channel-aggregate .

CSCwd76648

Port-channel DPI Load-Balancing not utilizing all the member-links.

CSCwd49177

ISG: L2-connected subscriber: IPv6 prefix delegation is not reachable when packet are switched.

Resolved Bugs in Cisco IOS XE 17.6.5

Bug ID

Description

CSCvz93612

%HW_FLOWDB-3-HW_FLOWDB_DBLDEL_FEATOBJ: FlowDB featobj cannot be deleted twice.

CSCvy60839

CSDL Compliance: Add CLI to disable CSDL compliance.

CSCwc82140

QFP crash when ZBFW configuration features log dropped-packets configuration.

CSCwc99823

fman crash seen in SGACL@ fman_sgacl_calloc.

CSCwc78021

Standby WLC crash @ fman_acl_remove_default_ace.

CSCvz92994

Lack of MAC address in inform event message.

CSCwc89328

Device might reboot when device supporting explicit IV joins network.

CSCwb52324

Device unexpected reload due to QFP ucode crash.

CSCwb61073

BQS Failure - QoS policy is missing in hardware for some Virtual-Access tunnels after session flaps.

CSCwd61255

Data plane crash on device when making per-tunnel QoS configuration changes with scale.

CSCwd03869

CEF DPI load-balancing causes out of order packets.

CSCwb04815

NHRP process taking more CPU because of FlexVPN event trace.

CSCwc22314

RTSP Traffic not being rewritten by NAT.

CSCwc76044

Interface stats are not getting updated for port-channel.

CSCwc26669

TLB miss for lock address during FNF cache lookup.

CSCwd30578

Wired guest client stuck at IP_LEARN with DHCP packets not forwarded out of the foreign to anchor.

CSCwd71584

DSPware 58.5.2 Release targeting v176_throttle.

CSCwd12748

Ping fails on 10G/100G interface when autoneg is configured on it, in controller mode.

CSCwc00557

Unexpected reload when running show platform hardware qfp active feature qos queue output all .

CSCwd56131

LTE modem doesn't show GSM bands.

CSCwd38943

GETVPN: KS reject registration from a public IP.

CSCwc49154

ISG DHCPD Timer crash due to subscriber session double free.

CSCwb73395

Need CLI option to disable ALG.

CSCwd06372

Unconditional excessive logging in eogre tunnel error handling case.

CSCwc54463

LAN Module is down when high CPU noticed.

CSCwc72923

ERROR info: Router configuration failed:interface Serial0/1/0:23 isdn switch-type primary-ntt.

CSCwc84967

Intermittent double DTMF due to changing timestamp on a DTMF event.

CSCwd85580

Unexpected reload after set ospfv3 authentication null command.

CSCwb08057

ISG: Number of lite sessions conversion in progress counter not decrementing on failed account-logon.

CSCwd47123

ISG uses identifier mac-address 0000.0000.0000 when DHCP LQ does not reply.

CSCwb32635

File is incomplete when running admin-tech.

CSCwd72312

GETVPN: Traffic drops seen on GM after rekey installing policies on image.

CSCvx00230

IOS-XE device may show input/output rate values even if the interface is in admin down state.

CSCwd79089

Device controller crash when sending full line rate of traffic with >5 Intel AX210 stations.

Open Bugs in Cisco IOS XE 17.6.5

Bug ID

Description

CSCwd90168

Unexpected reload after running show voice dsp command while an ISDN call disconnects.

CSCwc03478

VTCP does not support L2 correctly.

CSCwa52627

Incorrect Tx/Rx optical power values reported for QSFP transceivers.

CSCwd89338

Clear ISG existing lite-session upon reception of DHCP packet for same client.

CSCwd71458

Outgoing number of bytes decrease in router interface.

CSCvr90635

Output of show dmvpn detail is not matching the output of show nhrp group .

CSCwd34941

NAT configuration with no-alias option is not preserved after reload.

CSCvq81894

Check nexthop reachability before installing route for a prefix.

CSCwb99084

OMP routes carrying prepended AS_PATH incorrectly imported into BGP at remote site.

CSCwb89958

Unified Policy HSL not sending properly NBAR application information.

CSCwd59722

Unexpected reboot due to IOSXE-WATCHDOG: Process = Crypto IKMP.

CSCwd97077

Device leaking memory in MallocLite because of show platform software flow .

CSCwd81240

CPU utilization from the Linux kernel is at 100% due to btelnet.

CSCwc56033

Not triggering any alarms when RPM of a fan is 0.

CSCwa96399

Configuring entity-information xpath filter causes syslogs to print, does not return data.

CSCwd93401

AppNav-XE: Policy-map edit on cluster with multiple service context fails to program TCAM.

CSCwd81813

startup-config not parsed correctly after upgrade.

CSCwd82460

QFP ucode crash due to invalid RLB descriptor.

CSCwd88715

ucode crash during CVLA routines trying to merge a free block.

CSCwb55514

Crash seen after enabling platform qos port-channel-aggregate .

CSCwd76648

Port-channel DPI Load-Balancing not utilizing all the member-links.

CSCwd49177

ISG: L2-connected subscriber: IPv6 prefix delegation is not reachable when packet are switched.

Resolved Bugs in Cisco IOS XE 17.6.4

Bug ID

Description

CSCwb03893

When MACSEC dot1q-in-clear 1 is enabled on interfaces there is traffic drop.

CSCwa52627

Incorrect Tx/Rx optical power values reported for QSFP transceivers.

CSCwb44275

Simulated flows with PPPoE with NAT DIA result in crash consistently.

CSCwb26560

Linecard crashed on doing issu-mdr-force issu.

CSCwa68540

FTP data traffic broken when UTD IPS enabled in both service VPN.

CSCvx00230

Device may show input/output rate values even if the interface is in admin down state.

CSCwb95559

Packet sanity failed for resolution reply on spoke due to missing SMEF capability.

CSCvz93712

VFR is enabled by feature NAT but there is no NAT configured on the interface.

CSCwa84919

"Revocation-check crl none" does not failover to NONE DNAC-CA.

CSCvz63684

Alpha: EWC HA pair experiencing IOS tracebacks, followed by KEYMAN crash.

CSCwb25137

[XE NAT] Source address translation for multicast traffic fails with route-map.

CSCwb02142

Traceback: fman_fp_image core after clearing packet-trace conditions.

CSCwb32059

Cellular interface tracker down but NAT route persists in the service VPN routing table.

CSCvz98547

Device should not show warning message during reload.

CSCwc06967

IOS PKI client uses incorrect search filter for CRL retrieval using LDAPv3.

CSCwc37320

RP switchover causes linecard NFS mount failure resulting in memory leak.

CSCwb05743

Crash seen with umbrella config during soak run.

CSCvz83016

BFD tunnel uptime not showing correct values post upgrade.

CSCwb43605

OMPd crash during RIB-out attribute aspath/community processing.

CSCwc13013

IPSec key engine process holding memory continuously and not freeing up.

CSCwb90470

Device crashed with last reload reason critical process cxpd fault.

CSCwb73511

Device is not able to bring up SIG tunnels after reboot.

CSCwb91729

Fix mishandling of policy sequence programming failures and notify with syslog/notification.

CSCwa67886

UDP based DNS resolution doesn't work with IS-IS EMCP.

CSCwb85046

Device reloads when group-range is configured under an interface Group-Async.

CSCwc39881

Device generated from hardware cEdge contains "/" in Common Name.

CSCvz23982

IOS sending UP Event for the sub interface which is in down state.

CSCvx93283

Service Chain is not created when tracking is disabled.

CSCvx18302

[SIT] Speed Test to Internet failing on device.

CSCvz99832

Device per class BFD - echo response pkts.

CSCwb08636

IPSEC-3-HMAC_ERROR: IPSec SA receives HMAC error seen for TLOCExt setup after upgrade.

CSCvx74917

DNS Packets are not redirected to configured custom DNS after umbrella template edit.

CSCwa72273

ZBFW dropping return packets from tunnel post upgrade.

CSCwa64955

Device loses control connections after installing new enterprise hardware.

CSCwa92137

Device is changing ICMP ID in ICMP echo replies intermittently.

CSCwa49721

Device with firewall configured incorrectly dropping return packets when routing between VRFs.

CSCwa81471

AOM pending objects with loopbacks binded to tloc-extended interfaces.

CSCwb49857

Memory leaks on keyman process when key is not found.

CSCwb76866

CSDL failure: Use of MD5 by IPSEC key engine is denied.

CSCwb16723

Traceroute not working on device with NAT.

CSCwb55683

Large number of IPSec tunnel flapping occurs when underlay is restored.

CSCwa80826

IOS-XE: Devices running crypto ipsec policy installation fails.

CSCwb83376

Device endpoint-tracker cannot be configured on a 100G interface.

CSCwc13304

Per-tunnel QoS counters and shapers not working for some bfd tunnel with stale 'nh_overlay' objects.

CSCwa67398

NAT translations do not work for FTP traffic.

CSCwb78173

CSDL failure: IPSec QM Use of DES by encrypt proc is denied.

CSCwb71658

[SIT] Traceback seen on device after enabling ipsec_pwk and reboot.

CSCwb76170

IPsec SIG auto tunnels are not coming up.

CSCwb41907

CPP uCode crash due to ipc congestion from dp to cp.

CSCwb74917

Device incorrectly drops ip fragments due to reassembly timeout.

CSCwc25854

ucode crash due to SIGABRT from bnxt_start_xmit.

CSCvy54048

CPP unexpected reboot while freeing CVLA chunk.

CSCwa30857

Internet speed test with ;oopback binding mode doesn't work with implicit ACL drop for return traffic.

CSCwb14020

Serial interface stuck in "line protocol is down" state after it went down and it is recovered.

CSCwa98545

Checks of route leaks creates memory corruption.

CSCwb46649

NAT translation don’t show (or use) correct timeout value for an established TCP session.

CSCwa08847

ZBFW policy stops working after modifying the zone pair.

CSCwc33311

Device crash @ imgr_n2_ipsec_sa_ctx_register.

CSCwa26599

FN980 new signed Telit modem firmware FN980M_38.02.X92 upgrade failed

CSCwb12647

Device crash for stuck threads in cpp on packet processing.

CSCwc04688

Device crash observed after enabling NWPI trace with IPv6 traffic.

CSCwb78290

CISCO-SDWAN-BFD-MIB request gives results intermittently.

CSCwb76988

IKEv2 fragmentation causes wrong message ID used for EAP authentication.

CSCvw50622

NHRP network resolution not working with link-local ipv6 address.

CSCwb59736

BFD tunnel is zero.

CSCwa57873

Incorrect reload reason - last reload reason: local soft for NETCONF initiated request.

CSCvz37340

The [service timestamps log datetime msec localtime] command cannot be pushed via CLI add on template.

CSCwb99793

CRL verification failure result 400 bad request with digicert.

CSCwa25256

Installing new enterprise wan edge cert does not remove old cert causing device to use old cert.

CSCwb51595

Missing IOS config (voice translation rule) on upgrade.

CSCwb40575

After device upgrade, umbrella DNS config set to NONE in show umbrella config.

CSCwb18315

Umbrella DNS security policy doesn't work with cloud on ramp with SIG tunnels.

CSCwb58468

Sig Autotunnels:tunnel 409 response received.

CSCwc04289

Inconsistency between path MTU discovery result and tunnel MTU.

CSCwb74339

OTV ISIS authentication commands missing after reload.

Open Bugs in Cisco IOS XE 17.6.4

Bug ID

Description

CSCwc18977

Crash with "IPE_CPE_U14_CSR32_IPE_CPE_ERR_CPE_MISC_LEAF_INT__INT_CPE_MALGN_ADDR_ERR " error.

CSCwc03478

vtcp does not support L2 correctly.

CSCwb62474

Device may crash when doing speedtest with WAN flapping.

CSCwc23077

Firewall drop seen stating “FirewallL4” seen on device.

CSCwb74821

Yang-management process confd is not running, controller mode.

CSCwc37465

Static NAT configuration in CLI with the no-alias keyword cannot be retrieved via NETCONF/YANG.

CSCvz92994

Lack of MAC address in Inform Event message.

CSCwc52538

Device flows are not distributed and load-balanced evenly and consistently.

CSCwb61073

BQS Failure - QoS policy is missing in hardware for some Virtual-Access tunnels after session flaps.

CSCwc55260

Memory leak due to FTMd process.

CSCwb55514

Crash seen after enabling "platform qos port-channel-aggregate".

CSCwb99084

OMP routes carrying prepended AS_PATH incorrectly imported into BGP at remote site.

CSCwb89958

Unified policy HSL not sending properly NBAR application information.

CSCwb90375

Adding modem to AUX port results in having to toggle modem in out or reload the router.

CSCwc59598

Device statistics collection causing service-side BFD to flap on every collection interval.

CSCwc50477

Device crashed in ipv4_nat_create_out2in_session_entry.

CSCwb04815

NHRP process taking more CPU with ip nhrp redirect configured.

CSCwc22314

RTSP Traffic not being rewritten by NAT.

CSCwb83236

Traceback QFP core after pushing data policy with IPv6 interface.

CSCwc67465

Router can not be upgraded.

CSCwc26669

TLB miss for lock address during FNF cache lookup.

CSCwc25291

NIM-LTE-EA No Data - Requires subslot reload to recover.

CSCwc63563

Unable to set specific speed and duplex values on SFP ports on routing platforms.

CSCvz89354

Router running crashes due to CPUHOG when walking cisco flash MIB.

CSCwb73395

Need CLI option to disable ALG.

CSCwc43973

DLC is not completing after upgrading to smart licensing from CSL.

CSCvz28950

DMVPN phase 2 connectivity issue between two spokes.

CSCwb27486

New key for NBAR app and NBAR category without OGREF optimized.

CSCwc27208

BFD sessions not coming UP because of ANTI-REPLAY-FAILURES.

CSCwb08057

ISG: Number of lite sessions conversion in progress counter not decrementing on failed account-logon.

CSCwb68897

"Total output drops" counter in "show interface" on Port-channel doesn't work properly.

CSCwc30050

UTD: Exception in utd_logger.py due to missing extra-data in AMP alert.

CSCwa52627

Incorrect Tx/Rx optical power values reported for QSFP transceivers.

CSCwc20171

Fragmented packets crashes while allocating memory.

CSCwc17032

cpp_cp_svr crash when port-channel configured.

CSCvx00230

Device may show input/output rate values even if the interface is in admin down state.

CSCwc52538

Device flows are not distributed and load-balanced evenly and consistently.

CSCwc25291

NIM-LTE-EA No Data - Requires subslot reload to recover.

CSCwc55260

Memory leak due to FTMd process.

CSCwc63563

Unable to set specific speed and duplex values on SFP ports on IOS-XE routing platforms.

CSCwb99084

OMP routes carrying prepended AS_PATH incorrectly imported into BGP at remote site.

CSCwc30050

UTD: Exception in utd_logger.py due to missing extra-data in AMP alert.

CSCwb89958

Unified Policy HSL not sending properly NBAR application information.

CSCwb90375

Adding modem to AUX port results in having to toggle modem in out or reload the router.

CSCwb62474

Device may crash when doing speedtest with WAN flapping.

CSCwc50477

Device crashed in ipv4_nat_create_out2in_session_entry.

CSCwc43973

DLC is not completing after upgrading to smart licensing from CSL.

CSCwc23077

Firewall drop seen stating “FirewallL4” seen on device.

CSCwc22314

RTSP traffic not being rewritten by NAT.

CSCwb74821

Yang-management process confd is not running, controller mode.

CSCwc67465

Router can not be upgraded.

CSCwb83236

Traceback QFP core after pushing data policy with IPv6 interface.

CSCwc59598

vManage statistics collection causing service-side BFD to flap on every collection interval.

CSCvz92994

Lack of MAC address in Inform Event message.

CSCwc27208

BFD sessions not coming UP because of ANTI-REPLAY-FAILURES.

CSCwd36511

Ping fail to VRRP virtual IP address.

Resolved Bugs in Cisco IOS XE 17.6.3a

Bug ID

Description

CSCvz98446

Device crashed when changing Debug Level.

CSCwa13553

Device QFP core due to NAT scaling issue.

CSCvx40516

17.5 ZBFW + NAT: Traffic flow In2Out scenario failed.

CSCvy73165

10G interfaces supports multirate:Mismatch in autoneg/speed in SH run and SH SDWAN run.

CSCwa26509

Shut/no shut of endpoint-tracker attached tunnel, doesn't create probe again.

CSCwa10915

PFRv3: Elephant flow will trigger performance monitor exporting more than 50% byte loss.

CSCvw67366

Punt keepalive crashed due to bqs related interrupt.

CSCvz73202

TCAM parity error - QFP crash with a scale configuration.

CSCvz71436

Call placing issue from SCCP phones.

CSCvy69846

Guestshell:.py files stored under /home/guestshell are lost after reboot on 1ng device.

CSCvz86591

VRF-aware static NAT with route-map and reversible not working.

CSCvz99404

SdwanImplicitAclDrop seen on non-SDWAN interface after upgrade.

CSCwa01804

Router ucode crash with PPE DTL transfer error during IP reassembly.

CSCvz67279

SELINUX-5-Mismatch Log on device.

CSCvz62032

Attach gateways failed in cloud express.

CSCvz59621

MKA Session not coming up on EVC.

CSCvz87460

VID&gt;V07|16.9.7 MD5 signature does not match failure while upgrading.

CSCwa19074

Infinite output from command show sdwan tunnel sla

CSCwa80474

IKEv2 Deprecated Ciphers denied by Crypto Engine CDSL - PSB Security Compliance - MD5, SHA1.

CSCwa76260

IKEv2 Deprecated Ciphers denied by Crypto Engine CDSL - PSB Security Compliance - DES, 3DES, DH1/2/5.

CSCwa11150

E1 configurations (under Serial interface) lost after reload.

CSCwa30988

CoS preservation not working for the services EVPL and EPL tunnel.

CSCvz65545

ISIS reports encode error when NSF cisco if configured for GRE tunnel number greater than 65535.

CSCvz41647

Partial multicast drops are seen after a failover event in a site with two devices.

CSCvz76277

Hostname not allowed beginning with numbers.

CSCvz34668

Static mapping for the hub lost on one of the spokes.

CSCvz84437

8500L // Unexpected reload due IPV6 UDP fragment header in VxLAN.

CSCvx28426

Router may crash due to Crypto IKMP process.

CSCwa18177

Flapping bidirectional/unidirectional packet capture option with IPv4 filter for long time failed.

Open Bugs in Cisco IOS XE 17.6.3a

Bug ID

Description

CSCvz93712

VFR is enabled by feature NAT but there is no NAT configured on the interface.

CSCwa39336

Cannot transfer files.

CSCwb02142

Traceback: fman_fp_image core after clearing packet-trace conditions.

CSCwb23871

2048 RSA keys are lost after reload.

CSCvz98547

Device platforms should not show warning message during reload.

CSCwb20089

Device ESP crashes after enable platform debug for Cloud onRamp for SaaS.

CSCwb00533

Device traffic is getting dropped/blackholed due to OCE_ADJ_DROP reason.

CSCvz05814

[Chrysler]: Cwand issue observed ..potential crash.

CSCwb25913

(Rework): After configuring match input-interface on class-map, router goes into a reboot loop.

CSCwa72273

ZBFW dropping return packets from Zscalar tunnel post cedge upgrade.

CSCvz91913

Bay 2 startup config of 40Gbps not applied on reload.

CSCwa68471

Traceback: CPP ucode core generated after HSRP priority change.

CSCwa74499

ZBFW seeing the SIP ALG incorrectly dropping traffic and resetting connection.

CSCwa49721

SDWan HUB with firewall configured incorrectly dropping return packets when routing between VRFs.

CSCwa51582

IP device-tracking not functional with voice VLAN configured.

CSCwa81471

AOM pending objects with loopbacks binded to tloc-extended interfaces.

CSCwb21195

Device sees Anti-Replay drops when sequence number is beyond 32 bit.

CSCwa97171

PRP frames not transparent transmitted over L2TPv3 or EoMPLS tunnel.

CSCwb08186

E1 R2 - dnis-digits cli not working.

CSCwa98714

FMFP-3-OBJ_DWNLD_TO_DP_FAILED and tracebacks are seen following traffic drop.

CSCwa67101

Netflow exporter statistics not increasing on MFR interface with frame-relay fragmentation.

CSCwa08378

Day0 ZTP ignores crypto configuration before licensing.

CSCvz51752

SGACL policy doesn't get sync with standby post active RP crash & standby comes up.

CSCwa84448

Intersite cloudsec enabled packets with &lt;60 byte across device getting dropped when PTP is enabled.

CSCwa11349

Incorrect topology on TLOC extension causing high QFP.

CSCwb20222

Upgrade device from 17.3.4a to 17.6.2 is failed.

CSCvy54048

CPP unexpected reboot while freeing CVLA chunk.

CSCwa98545

Checks of route leaks creates memory corruption.

CSCvz08674

Device rebooted 2 time with CPP 0 failure stuck thread.

CSCwa76875

After configuring match input-interface on class-map, router goes into a reboot loop.

CSCwa08847

ZBFW policy stops working after modifying the zone pair.

CSCwa26599

FN980 new signed Telit modem firmware FN980M_38.02.X92 upgrade failed.

CSCwa29964

SCEP fails if AAAA DNS repy is received and source interface has no IPv6 address.

CSCwa52627

Incorrect Tx/Rx optical power values reported for QSFP transceivers.

CSCwb32635

Vdaemon file is incomplete when running admin-tech.

CSCwa67851

Router traceback and reload when different encapsulation used on xconnect interfaces.

CSCvz95158

IPSec Led doesn't lit even though module is correctly installed.

CSCwb18315

Umbrella DNS security policy doesn't work with Cloud onRamp with SIG tunnels.

CSCvx00230

IOS-XE device may show input/output rate values even if the interface is in admin down state.

Resolved Bugs in Cisco IOS XE 17.6.2

Bug ID

Description

CSCvz30670

Qos issue on IPv6 Virtual access (tunnel ipsec) interface ASR1k

CSCti88451

Syslog message for SIP Trunk unregistration / registration

CSCvh31741

IOS Device may unexpectedly reboot when displaying BGP neighbors from AF being deleted

CSCvt49729

IPv6 PD lost after RP failover under the sh subscr sess output

CSCvt95787

Unhide "bandwidth" interface command on cedge cli

CSCvw13682

L3 connected lite session not coming up , stuck in data-plane(qfp)

CSCvx61611

Disruption of IPC communication between the FMAN-FP and FED processes due to lack of ACKs from FED.

CSCvx99833

[EVPN L2TRM] Default SMET route should accept only group/source length zero & wildcard value

CSCvy03887

SCP process leading to crash

CSCvy06671

Wrong source ip address is shown in https access log

CSCvy18995

[EVPN BGP] IMET route without PMSI tunnel attribute is accepted by Leaf VTEP

CSCvy23400

MC-LAG feature cannot preserve administratively shut down sub-interfaces

CSCvy27721

IOS-XE Router may experience unexpected reboot with X25 RBP

CSCvy29677

Invalid Free Block Memory Corruption Caused by DHCP is Leading to IOSd Crash

CSCvy31008

OSPF process may not install an external prefix (with fwaddr) in RIB

CSCvy39259

Memory Corruption in standby node of B2B HA setup when running Mifid Media Proxy Recording Calls

CSCvy44951

ESP Unexpected Reboot on Broadband Intelligent Services Gateway During Session Clean-up

CSCvy46402

CUBE-979 Wrong crypto suite selection for re-invite during SRTP-SRTP dialpeer based recording case.

CSCvy54607

Iosd crash at ospf-1 router process while applying config from bootflash

CSCvy56660

mlacp backbone interface defined in netconf as Container instead of list entry

CSCvy58348

Bulk-Sync Failure (PRC) On applying a non-existent Policy map to interface via template

CSCvy67482

SRTP failure leading to no audio in TDM-SIP call with 183 wSDP present

CSCvy67650

Controller does not send TCP SYN or ACK for web redirect when banner size is greater than 200 char

CSCvy68568

show telemetry internal diagnostics decode error

CSCvy69555

unable to fetch eigrp prefix, nexthop, omptag, and route origin

CSCvy69663

Running certain commands from old web interface may cause device to crash

CSCvy72193

ISG IPv6 session lose connection w/ "no ipv6 nd ra suppres" due to final RA sent for other session

CSCvy72210

CIsco IOS XE crash after executing 'show flowspec ipv4' command

CSCvy78311

CUBE FPI leak on DO-DO flow in ANAT m-line switch case with CUBE pref IPv6

CSCvy78544

17.7:ASR1K:Traceback @be_isis_process_no_router on unconfiguring ISIS with Entropy Label feature.

CSCvy78992

BGP Router process may crash after configuring maximum-paths eibgp

CSCvy83154

MAG is not detecting the path UP after several reboots

CSCvy84153

Crash is observed in the controller when the AP location name is greater than 32 character

CSCvy85559

LISP DDT: Buffered Map Request leads to NMR delivery failure

CSCvy86265

Memory leak in ospf on withdrawing SRMS prefix sid

CSCvy86580

[EVPN BGP] Crash seen @bgp_evpn_print_pmsi ,bgp_show_one_pmsi ,bgp_show_network_detail

CSCvy87819

Extra isis config lines getting added to interface BDI Config

CSCvy90726

BGP Memory Leak after upgrading to 17.3.x due to Duplicate Attribute Entries

CSCvy91369

IOS-XE : IPSLA ICMP-Jitter over L3VPN results incorrect jitter value.

CSCvy92696

Cosmetic: `Logging host` configuration inconsistent between sdwan and IOS configuration

CSCvy93771

Webauth hosts fails to get login page due to increment of aaa_reply_pending_count, WA bkpressure

CSCvy93946

Removal of SHA-1 HMAC Impacting ability to SSH

CSCvy99942

Netconf: Logging to syslog stops working in certain scenarios

CSCvz00900

No Ringback to External Callers When Call Reaches Desk Phone JIRA CMESRST-328

CSCvz01295

Edge Device performance issue

CSCvz01883

DHCP Lease not renewed properly after expiry

CSCvz03677

router crashes when changing BGP AS Number

CSCvz04388

RSP3:pubd process crashed during ISSU from 17.6.1 to 17.3_throttle

CSCvz06288

PI Infra changes for CSCvy74957 CPU generated FNF traffic does not adhere to standard RFC 4594

CSCvz08303

Controller reloads unexpectedly in dbm process when DBAL batch stops executing

CSCvz09498

'show isis teapp' with scale doesn't display the entire list

CSCvz12010

CUBE switches over to fax passthrough when "a=silenceSupp:off - - - -" received in 200 OK.

CSCvz12596

Memory leak in emulated database of OSPF and VRF.

CSCvz14745

Memory leak seen when using DNS with IP SLA

CSCvz21844

When Polling MIB 1.3.6.1.4.1.9.9.764 CUBE status shows wrong information

CSCvz24067

On-Prem ZTP: control connections are formed. But after sometime, vManage reset the configuration.

CSCvz24880

CUBE responds with new transaction refresher (UA) within the refresh message for fax passthru call

CSCvz26193

IOS-XE switch may experience unexpected reboot while executing MAB commands

CSCvz27413

CUBE takes lot of time to send 486 to the other call-leg when media stats-disconnect is enabled

CSCvz28986

SNMP poll of DHCP Stats not available on IOS-XE 17.03.03

CSCvz30670

Qos issue on IPv6 Virtual access (tunnel ipsec) interface ASR1k

CSCvz33145

SDA - on Anywhere Border RPF for external RP incorrectly pointing to LISP after BGP route is back

CSCvz33428

STATIC IP configured on SVI is lost when changing from DHCP if SVI flaps at the same time

CSCvz35288

Ti-LFA backup path is not availabe for some protected Adj-SIDs in mutil-area OSPF

CSCvz37619

DSPware 58.5.1 Release targeting v176_throttle to 17.6.2

CSCvz41766

VG450 Crashes Repeatedly in IOSd due to HTSP

CSCvz45020

%SIP-1-LICENSING: SIP service is Up. License report acknowledged.

CSCvz45256

Inbound fax T38 switchover on MGCP GW sending an m line of audio instead of image

CSCvz51558

udp-jitter incorrect RTT calculation when using BDI interfaces

CSCvz60451

Memory leak is observed in C9800-CL due to native telemetry

CSCvz66346

ASR920: New Bridge-Domain are not added dynamically to POCH when TEFP-encap from-bd is configured

CSCvx08118

ASR1001-X: Bug to further address CSCvt08179 : QFP crash due to hardware interrupt

CSCvy24936

vBond connections continuously flapping on edge devices.

CSCvy37285

SSH to Loopback not working

CSCvy44723

control connection to the edege device doesnt come up with v6 and reverse proxy

CSCvy54606

CVLA need to reserve at least 50M memory for low-end DRAM platform

CSCvy74799

Ucode crash observed at tw_bad_timer_bucket () at ../../../infra/tw_timer.c:918

CSCvy85281

Crash triggered by "crypto gdoi ks rekey replace-now"

CSCvy89362

QOS-3-INVALID_BQS_QUEUE_INFO: Drop policy given an invalid scheduling queue/wred 0/0 -Traceback

CSCvy89461

Crash when getting cdspCardStatusEntry OID

CSCvy89785

OSPFv3 adjacency won't come up after "ospfv3 authentication ipsec" is applied on Tunnel interface

CSCvy91411

SD-WAN policy is not correctly programmed in cEdge

CSCvy94954

LA LED turns green when just inserted SFP-10G-LR on ISR4k without cable connecting

CSCvy95586

SCCP gateway auto configuration download results in an incomplete configuration.

CSCvy97578

Need Active/Active ZBFW support for Inter-vrf TCP traffic

CSCvy97761

IPV6 route is breaking control connection.

CSCvy98784

AppQoE DP stats for active connections shows huge bogus value

CSCvy99344

cEdge: Multicast UnconfiguredIpv4Fia drop when multicast interworks with service chain/NAT DIA

CSCvz03053

OMP continues to redistribute BGP route with down bit set (SoO)

CSCvz03342

Multicast boundary command on tunnel interface DMVPN network is sending ttl=1 packet

CSCvz04121

"show sdwan tunnel statistics bfd" and "clear sdwan tunnel statistics" issues

CSCvz06952

vSmart crash on ompd process

CSCvz07134

Router does not boot on recent 16.X releases with large service policy applied on the interface.

CSCvz09078

FireWall Policy Drops are seen when the OG/ACE's are reconfigured multiple times

CSCvz09330

Bootstrap aaa config issues due to default aaa config

CSCvz18867

IP NAT source static does not work for TCP traffic from OUT to IN

CSCvz23024

17.6.1_auto:SNMP failure on bfdSessionsListSystemIp

CSCvz24267

Static NAT entry is injecting a route to Null0

CSCvz25619

FNF: Reload due to a memory allocation failure in cEdge

CSCvz26211

flow monitor statistics missing when reloading with configuration

CSCvz30465

MT: Template push with thousand eye feature failed for ISR4461 after PnP workflow

CSCvz34290

no ip nbar resources flow max-session does not restore default platform session limits

CSCvz40788

SDWAN tunnels are not coming up in Multilink Frame relay sub-interface

CSCvz47421

VLAN IP config missing on bootup due to missing startup configs

CSCvz47982

Flow-Control Goes down when configurating manual speed and remove the auto negotiation

CSCvz53819

ZBFW : ARStandby drops seen on New Active during RG switchover

CSCvz55789

Data-policy direction-all with empty action is causing to ignore app-route-policy

CSCvz56966

Zscaler SIG tunnels not coming up after reboot due to HTTP/RESP/CODE 400

CSCvz60101

Failure to start (on RP2) iox app-hosting application

CSCvz62602

Extranet local switch crash when mdata is enabled.

CSCvz70734

cEdge crash with sdwan overlay multicast: "CPU Usage due to Memory Pressure exceeds threshold"

CSCvz73780

memory leak with fman_cc process when SM-X-G4M2X module installed

Open Bugs in Cisco IOS XE 17.6.2

Bug ID

Description

CSCuv05226

ASR920 : VRF is not deleted after replacing default config

CSCvv82322

ASR1001-X and ASR9K: Link issue when using macsec

CSCvw67366

ASR1002-X: Punt keepalive crashed due to bqs related interrupt

CSCvw70446

17.4 ZBFW:Crash pointing to fw_base_flow_create () seen on ASR1K

CSCvz11362

ASR fails to install rekey causing traffic drop

CSCvz31901

ASR1K: Cisco makefile changes to build the PHY API SW 4.67.05

CSCvz33747

High CPU caused by "IOSD ipc" task on ASR 1002-HX.

CSCvz54262

ASR1001X crash at CFT after scaling up to 4M flows when internet link up from 2Gbps to 10Gbps

CSCvz55696

ASR1K - IOSXE BGP Graceful Restart inducing extensive packets loss after nexthop node is offline

CSCvz62601

ASR1000-MIP100 / IOS XE 17.3.2 / high CPU on LC process mcpcc-lc-ms and link flaps

CSCvz67279

SELINUX-5-Mismatch Log on ASR1002HX and 8500 Platforms

CSCvz74322

"Shutdown" command visible in running config after reload of ASR 1002-HX

CSCvz87460

ASR 1000-RP2|VID>V07|16.9.7 MD5 signature does not match failure while upgrading to 17.3(1r) rommon

CSCvu62879

Crash@bgp_perform_general_scan

CSCvy20617

CUBE license status goes to ""NOT IN USE" after SLR Authorization

CSCvy22343

Crash after reapplying BGP/ attempt to initialize an initialized wavl tree

CSCvy57681

Unexpected reboot of IOS-XE Router in BQS QM @ cpp_qm_proc_rt_commit

CSCvy97741

qfp_ucode_c8kv crash at making a blind transfer from an outside SIP service

CSCvy98400

CUBE responds with new transaction refresher (UA) within the refresh message

CSCvz05377

ACL not getting updated once pushed from ISE

CSCvz07465

Too big Call-ID length in the SIP REGISTER

CSCvz19341

SUBSCRIBE-NOTIFY Passthrough does not work as expected in CUBE registration proxy scenario

CSCvz20285

SDWAN image info not updated in packages.conf when upgrading in autonomous mode

CSCvz21812

QoS policy update with "random-detect dscp" configuration get rejected on device side

CSCvz23470

Function: DNA-C/SWIM - NCSW10249: Distribution failed using protocol: HTTPS with FQDN

CSCvz26532

No audio on Courtesy Call Back from CCE when using SRTP

CSCvz26852

During netconf push vManage adding '\" for every pipe "|" symbol

CSCvz26901

When survivability script with header-passing enabled is invoked, the translation rule fails

CSCvz30202

CUBE does not send REGISTER to registrar server after reloading it.

CSCvz35474

Traceback: IOS core generated after failure of process CCSIP_SPI_CONTROL

CSCvz43262

CUBE DTMF Interworking breaks during consulted call transfer

CSCvz48118

Radius probe account pushes unsupported Service-type [6] attribute

CSCvz55553

BGP routes refreshing in the routing table after adding "bgp advertise-best-exterenal"

CSCvz55696

ASR1K - IOSXE BGP Graceful Restart inducing extensive packets loss after nexthop node is offline

CSCvz55812

MLP cpp crash cause both FP cpp to lock and stuck in disconnecting

CSCvz57415

128.0.0.0/2 is installed into CEF as unusable on a PETR after EID-Prefix is removed.

CSCvz57887

CUBE is not sending audio for SIPREC call recording

CSCvz60420

Peer voice hunt group does not track hops

CSCvz62589

Crash when configuring NAT log flow-export v9 (HSL)

CSCvz64802

WLC reloaded due to a memory corruption in wncd

CSCvz72871

Multicast traffic received over DMVPN tunnel are dropped on RP and not forwarded downstream.

CSCvz74646

CME fails to send notifications to all phones for shared line use during parallel calls

CSCvz76277

Hostname not allowed beginning with numbers

CSCvz76649

APs disjoin the WLC when a clients connects to a Secure LDAP SSID

CSCvz77313

Catalyst Switch reload due to SFF8472

CSCvz81906

Crash while running 'show running-config' command due to "ipv6 dhcp test relay reply add"

CSCvz84537

Webauth external stuck in authenticating without taking ip address

CSCvz86218

IOS 17.x / SCP copy command fails for large files > 2GB size due to "invalid argument"

CSCvz86580

Unable to remove the BGP neighbor statement through vManage template.

CSCvz89713

CEF should not notify LISP based on helpered UDP broadcast packets from remote hosts

CSCvv82985

dhcpv6_relay:dhcp-client on branch not receive ipv6 address

CSCvx28426

Router may crash due to Crypto IKMP process

CSCvy63924

Telemetry: IOS-XE Controller crashes after using 'show telemetry ietf subscription all' command.

CSCvy69846

Guestshell:.py files stored under /home/guestshell are lost after reboot on 1ng device

CSCvy72970

Active ftp not working with UTD+HTX for security and Unified policy.

CSCvz28950

DMVPN phase 2 connectivity issue between two spokes

CSCvz37340

The [service timestamps log datetime msec localtime] command cannot be pushed via CLI Addon template

CSCvz40459

Ucode crash due to NAT proxy timeout

CSCvz54262

ASR1001X crash at CFT after scaling up to 4M flows when internet link up from 2Gbps to 10Gbps

CSCvz58895

IOS-XE unable to export elliptic curve key

CSCvz65545

ISIS reports encode error when NSF cisco if configured for GRE tunnel number greater than 65535

CSCvz67279

SELINUX-5-Mismatch Log on ASR1002HX and 8500 Platforms

CSCvz76277

Hostname not allowed beginning with numbers

CSCvz77008

SDWAN Router Crashed "Critical process qfp_ucode_csx fault on fp_0_0 (rc=139)"

CSCvz80197

FTMD message error

CSCvz87460

ASR 1000-RP2|VID>V07|16.9.7 MD5 signature does not match failure while upgrading to 17.3(1r) rommon

Resolved Bugs in Cisco IOS XE 17.6.1a

Bug ID

Description

CSCvo41609

GETVPN: Clearing members on Key Server causing rekey processing failure on GMs

CSCvr91128

NAT HA - stale tcp sessions in standby router

CSCvw21378

ASR1001-X built-in Tengig interfaces' counters increasing continuously and port stay up/up w/o SFP

CSCvw91361

Crash when issuing "show crypto isakmp peers config"

CSCvw98579

BQS crash seen in 17.3 while bringing up 30k PPPOE sessions

CSCvx22349

After reload or switchover, redundant ESP goes offline->online (transient issue)

CSCvx23159

FW-4-ALERT_ON: (target:class)-():getting aggressive seen when no half open feature configed

CSCvx25217

cannot remove NAT configuration from the template in a single operation if NAT translation is active

CSCvx26065

1006-X: Box rebooted due to ucode crash, with 2M CFLOW and 8K BFD sessions

CSCvx32090

Port channel configuration triggers traceback

CSCvx32670

Wrong reload reason reflected after a power outage.

CSCvx32807

False positive alarm: IOSXE_RP_ALARM-6-INFO: ASSERT CRITICAL Fan Tray Bay 1 Fan Tray Module Missing

CSCvx44834

ASR1K - ACE entry added after object-group is missing in hardware causing packets drops

CSCvx45788

cannot apply ciscosdwan.cfg due to vpg-log-server-acl ACL on VirtualPortGroup0 for logging

CSCvx53399

fman_fp_image crashed with ZBFW config change

CSCvx57615

ZBFW blocking ACK packets for applications using cloudexpress SaaS set to use a Gateway with synsent

CSCvx64449

%CRYPTO-4-RECVD_PKT_MAC_ERR: decrypt: mac verify failed due to ip rtp header-compression iphc-format

CSCvx64640

Data plane VPLS traffic generating Control Word on all Label Switched Headers

CSCvx68767

PWK - Overlay tunnel goes down with overnight traffic (No Crash)

CSCvx69830

ASR1k: BQS crash seen at cpp_qm_event_proc_defer_cb

CSCvx72682

[DMM/SLM test issue] CFM crash when using physical port, DMM/SLM doesn't work on EVC

CSCvx75330

fman_rp memory leak in acl_config_bind_v4_acl_message function.

CSCvx77024

IPv6 DMVPN - NBMA address not getting preserved

CSCvx77203

[17.5] Router crashed when sending traffic through non-SDWAN interface with DIA NAT + debug enabled

CSCvx77674

A router may crash when processing an NHRP packet

CSCvx78215

An IOS XE device might crash at DoubleExceptionVector

CSCvx82406

Memory leaks in IOS_PRIV_OPER_DB

CSCvx83301

"insufficient resources" NHRP-ERROR while receiving small rate of NHRP Resolution Requests/second

CSCvx88061

Extended PAT not allowing more than 1k translations

CSCvx88246

Packets dropped due to firewall + data policy interop issue

CSCvx89710

SCEP: CA server fails to rollover CA certificate with error: "Storage not accessible"

CSCvx94323

NHRP messages tagged with incorrect MPLS labels - unable to establish shortcut

CSCvx97718

vtcp frees rx buffer when packet with expected next sequence arrives with no payload; phones reset

CSCvy00963

On vManage 20.4.1, traceroute on cEdge leads to outage at the site

CSCvy01097

Router may crash under ZBF configuration (cpp_cp_svr)

CSCvy03584

cEdge fails to capture sdwan-related outputs to admin-tech

CSCvy09343

CFM inject packet is not marked as high priority

CSCvy10159

Software MTP should support encrypted TLS connection

CSCvy13261

ASR1001-X is not tagging BGP prefixes with OMP tags

CSCvy13735

BFD tunnels stuck in down state after port-hop

CSCvy17941

High memory utilization observed due to NAT/ALG

CSCvy18691

ASR1002HX-IPSECHW octeon ucode crashes when provisioned via SD-WAN

CSCvy20588

CSDL failure when it should be allowing RSA keys with 1024 length.

CSCvy30209

IOS-XE cpp ucode crash with fragmented packets

CSCvy32673

GD/1hx-Interface doesn't come up when reboot/upgrade device with autoneg enabled on 10G SFP+ Port

CSCvy33007

"Best of Worst" Fallback mode causes reachability issue when routes flap

CSCvy33818

On MTT vManage system IP persists after invalidating and deleting the edge devices.

CSCvy34102

CPP ucode crash with route-map and overload at ipv4_nat_rmap_walk_find.

CSCvy35853

ASR1k- egress byte counter on MIP100 10GE interface is inaccurate

CSCvy50292

Standby router crashes ZBFW on VASI interfaces with FTP or SIP TCP traffic

CSCvy52761

adding multilink frame relay sub-interface to SDWAN fails; "Aborted: application error"

CSCvy54314

Data-policy local-tloc with app-route is dropping packets when SLA is not met

CSCvy64468

ASR1002-HX crashed after removing then applying the ZBF configuration.

CSCvy67720

[FNF] Need to force DTL read after PLU lookup in fnf_build_do_ipv4_fast

CSCvy93830

BFD tunnel uptime not showing correct values post upgrade to 17.6.01

Open Bugs in Cisco IOS XE 17.6.1a

Bug ID

Description

CSCvx44834

ASR1K - ACE entry added after object-group is missing in hardware causing packets drops

CSCvx95405

Cellular interface lte Network Selection Mode switches to auto following a reload

CSCvy33818

On MTT vManage system IP persists after invalidating and deleting the edge devices.

CSCvy57681

Crash in BQS QM @ cpp_qm_proc_rt_commit

CSCvy72970

Active ftp not working with UTD+HTX for security and Unified policy.

CSCvy78501

17.6: AAR not working properly as configured SLA classes are not shown under app-route stats

CSCvy86497

BFD session flap/down while control connection with vManage is going down

CSCvy87507

Router unexpectedly routes traffic with broadcast dst MAC

CSCvy90763

PYON: Adjusting new text segment to address L2i rejections issues with SDWAN profiles

CSCvz06095

ReassTimeout drops with NAT in Port-Channel.

CSCvz08674

cedge rebooted 2 time with CPP 0 failure Stuck Thread

CSCvz08945

low-bandwidth-link doesn't reduce number of BFD packets

CSCvz09078

FireWall Policy Drops are seen when the OG/ACE's are reconfigured multiple times

CSCvz11362

ASR fails to install rekey causing traffic drop

CSCvz24199

cEdge: Transport interface IP is unexpectedly NATed to pool address in DIA scenarion

CSCvz25403

NetApp: Issues with traffic does not get forwarded via TLOC extended interface

CSCvz28795

SSL VPN fails to establish if 'match url' is configured under crypto ssl profile

CSCvz28950

DMVPN phase 2 connectivity issue between two spokes

CSCvz31630

Crash ASR 1k crash under "VTEMPLATE Background Mgr" process

CSCvz33108

After uploading the serial file list to the vmanage, the edges lost Control Con. and BFD sessions

CSCvz34290

no ip nbar resources flow max-session does not restore default platform session limits

CSCvz35990

OSPFv3 IPSec encryption failure when IPv4 address-family not configured in VRF

ROMmon Release Requirements

For more information on ROMmon support for Route Processors (RPs), Embedded Services Processors (ESPs), Modular Interface Processors (MIPs), and Shared Port Adapter Interface Processors (SIPs) on Cisco ASR 1000 Series Aggregation Services Routers, see https://www.cisco.com/c/en/us/td/docs/routers/asr1000/rommon/asr1000-rommon-upg-guide.html


Note


After upgrading the ROMmon to version 17.3(1r), you cannot revert it to a version earlier than 17.3(1r) for the following platforms:

  • ASR 1001-X

  • ASR 1001-HX

  • ASR 1002-HX

This restriction is only applicable for these platforms. If you have upgraded to ROMmon version 17.3(1r) on any other platform, reverting to an earlier version of ROMmon is permitted and does not cause any technical issues


Related Documentation

Communications, Services, and Additional Information

  • To receive timely, relevant information from Cisco, sign up at Cisco Profile Manager.

  • To get the business impact you’re looking for with the technologies that matter, visit Cisco Services.

  • To submit a service request, visit Cisco Support.

  • To discover and browse secure, validated enterprise-class apps, products, solutions and services, visit Cisco DevNet.

  • To obtain general networking, training, and certification titles, visit Cisco Press.

  • To find warranty information for a specific product or product family, access Cisco Warranty Finder.

Cisco Bug Search Tool

Cisco Bug Search Tool (BST) is a web-based tool that acts as a gateway to the Cisco bug tracking system that maintains a comprehensive list of defects and vulnerabilities in Cisco products and software. BST provides you with detailed defect information about your products and software.

Documentation Feedback

To provide feedback about Cisco technical documentation, use the feedback form available in the right pane of every online document.

Troubleshooting

For the most up-to-date, detailed troubleshooting information, see the Cisco TAC website at https://www.cisco.com/en/US/support/index.html.

Go to Products by Category and choose your product from the list, or enter the name of your product. Look under Troubleshoot and Alerts to find information for the issue that you are experiencing.