Release Notes for Cisco Catalyst 8500 Series Edge Platforms, Cisco IOS XE Dublin 17.12.x

First Published: 2023-08-22

Full Cisco Trademarks with Software License

THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.

THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.

The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.

NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE.

IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.

All printed copies and duplicate soft copies of this document are considered uncontrolled. See the current online version for the latest version.

Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at www.cisco.com/go/offices.

About Cisco Catalyst 8500 Series Edge Platforms

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)

Note: Cisco IOS XE Dublin 17.12.1a is the first release for Cisco Catalyst 8500 Series Edge Platforms in the Cisco IOS XE Dublin 17.12.x release series.

The Cisco Catalyst 8500 Series Edge Platforms are high-performance cloud edge platforms designed for accelerated services, multi-layer security, cloud-native agility, and edge intelligence to accelerate your journey to cloud.

The Cisco Catalyst 8500 Series Edge Platforms includes the following models:

For more information on the features and specifications of Cisco 8500 Series Catalyst Edge Platform, see the Cisco 8500 Series Catalyst Edge Platform datasheet.

Sections in this documentation apply to all models unless a reference to a specific model is explicitly made.

Feature Navigator

You can use Cisco Feature Navigator (CFN) to find information about the features, platform, and software image support on Cisco Catalyst 8500 Series Edge Platforms. To access Cisco Feature Navigator, go to http://www.cisco.com/go/cfn. An account on cisco.com is not required.

New and Changed Software Features

Table 1: Software Features

FeatureDescription
Segment Routing over IPv6 DataplaneSegment Routing (SR) can currently be applied on Multiprotocol Label Switching (MPLS) dataplane. From Cisco IOS XE 17.12.1a, SR is supported over the IPv6 dataplane for the following protocols:-
  • Interior Gateway Protocol (IS-IS only)
  • Border Gateway Protocol (BGP)
In addition, the following functionalities are available for Segment Routing over IPv6 dataplane:
  • Segment Routing Traffic Engineering Policies
  • Static Routes
  • Performance Management
  • Operations, Administration and Maintenance (OAM)
TrustSec and Software-Defined Access Scale MeasurementWith this feature, the scale numbers for TrustSec and Software-Defined Access (SDA) are measured for the following:
  • Security Group Tag (SGT) or Destination Group Tag (DGT) Policies
  • Unidirectional IPv4 SGT Exchange Protocol (SXP) connections
  • Bidirectional IPv4 SXP connections
  • IPv4 SGT Bindings
  • IPv6 SGT Bindings
  • Security Group Access Control Entries (SG ACEs)
IPv6 Unicast Support with DLEPThe IPv6 Unicast Support feature introduces support for IPv6 dataplane to RAR Dynamic Link Exchange Protocol.
Managing the SD-Routing Devices Using Cisco SD-WAN ManagerThis feature allows you to perform management operations for SD-Routing devices using Cisco Catalyst SD-WAN Manager. You can use a single network manage system (Cisco Catalyst SD-WAN Manager) to monitor all the SD-Routing devices and therefore help in simplifying solution deployments.

Resolved and Open Bugs for Cisco IOS XE 17.12.x

Features with Enhancements

FeatureDescription
Quantum-Safe Encryption Using Post-Quantum Preshared KeysThis enhancement introduces support for Quantum-Safe Encryption using Post-Quantum Preshared Keys for the following platforms:
  • Cisco 1000 Series Integrated Services Routers
  • Cisco Catalyst 8500 Series Edge Platforms
Support for Automatic Log DeletionThis feature allows you to delete the entries from the logging buffer. You can configure the local syslog retention period after which the entries are purged from the device automatically. To enable this feature, use the logging purge-log buffer days command.

Resolved Bugs for Cisco IOS XE 17.12.1a

Bug IDHeadline
CSCwe82666Not all HSL entries get pushed to device if more than 1 HSL entries are configured
CSCwe31226Issues/discrepancies around CPU alarms generated and sent to device
CSCwe43341TLS control-connections down, traffic from device dropped
CSCwe18124MACsec remains marked as secured, but the traffic randomly stops working
CSCwe18276Route-map not getting effected when its applied in OMP for BGP routes
CSCwf83850With Pure IPv6, minimal bootstrap unable to onboard non-fabric - IPv6 config missing in WAN int G1
CSCwb74821Unexpected behavior due to unstable power source
CSCwe79007Unexpected reload when doing ips test with UTD ips engine
CSCwe81182(EPC, packet-trace) for IPsec running COFF (Crypto Offload)
CSCwe38296Procyon packets drop due to MACsec post-encryption padding behavior
CSCwe93905NAT ALG is changing the Call-ID within SIP message header causing calls to fail
CSCwe85195AAR: BoW feature ignoring color preference from Tiered Transport preference configuration
CSCwe14885VPN is established although the peer is using a revoked certificate for authentication
CSCwd53710Crash seen when name_lookup takes > 30 sec
CSCwe66318NAT entries expire on standby router
CSCwd35047Failed to ping gateway while configuring SharedLOM with console, te1 interface. until router reload
CSCwd84599Dataplane memory utilization issue - 97% QFP DRAM memory utilization
CSCwd59722Unexpected reboot due to IOSXE-WATCHDOG: Process = Crypto IKMP
CSCwe70374Platform punt-policer is not configurable
CSCwf05405Traceback seen after BDI interface is configured
CSCwe73408For some error condition platform_properties may double free
CSCwd42523Same label is assigned to different VRFs
CSCwe37123Device uses excessive memory when configuring ACLs with large object groups
CSCwe12194Auto-Update cycle incorrectly deletes certificates
CSCwd90056C8500-12X4QC : P2MP WAN MACsec does not allow traffic to pass on the link
CSCwe09298C8500L sees the increase of input errors without any other specifc errors increasing under show interface
CSCvz82148%CRYPTO_SL_TP_LEVELS-6-VAR_NEW_VALUE message is observed in each write config with same crypto value
CSCwe85421BFD session down with interface flap
CSCwe95606Double GR_Additional log enablement defect
CSCwe31471Segmentation fault in device when per-tunnel QoS config withdraw
CSCwe89404No way audio when using secure hardware conference with secure endpoints
CSCwd39257IOS-XE cpp crash when entering no ip nat create flow-entries
CSCwe63222Certificate output is not getting changed on renew when Cloud Certificate Authorization is Automated
CSCwe70642AAR overlay actions are applied to DIA traffic
CSCwa96399Configuring entity-information xpath filter causes syslogs to print, does not return data
CSCwe06518C8500-12X : ~23% degradation in IPSEC IPv6 profile for 1400B
CSCwe31281Autotunnel Ipsec tracker:Tracker does not come up at all on device
CSCwe39157During soak run, On C8500L-8S4X, Memif channel's were missing and causing SC-SN state down
CSCwd93401AppNav-XE: Policy-map edit on cluster with multiple service context fails to program TCAM
CSCwf65696Non-fabric- Load the minimal bootstrap configs again if device rebooted without saving the configs
CSCwd76648Port-channel DPI Load-Balancing not utilizing all the member-links
CSCwe39011GARP on port up/up status from device is not received by remote peer device
CSCwb39206Enable VFR CLI
CSCwe85022Device is showing 4 additional NR bands support - 1, 3, 7, and 28

Open Bugs for Cisco IOS XE 17.12.1a

Bug IDHeadline
CSCwh00332B2B NAT: when configration ip nat inside/outside on VASI intereface,ack/seq number abnormal
CSCwf70854Changes to speed on the interface via CLI/GUI dont go through unless first done via shell access.
CSCwh06834Using special characters in the password while generating TP generates an invalid TP
CSCwf87292Punt keep alive failure crash on controller managed device apparently due to data packets
CSCwf94294Misprograming during vpn-list change under data policy.
CSCwf55145SFP transceiver DOM not working after some time, however interface forwards the traffic as expected
CSCwf94052BFD going down for newly onboarded device
CSCwh01095Rapid memory leak on ngiolite process
CSCwf80927Speed tests to internet from C8500 device triggered will fail sometimes
CSCwf84522C8500L Unexpected rebooted while classifying packet with CTF (Common Flow Table)
CSCwh00320Show commands in sync after removing GigabitEthernet3
CSCwf44703NAT64 prefix is not originated into OMP
CSCwf99947Crash when modifying tunnel after running show crypto commands
CSCwf77252SIP calls not working on device with ZBFW enabled
CSCwf62757C8500L Interface data report interval issue for physical interface
CSCwf96416Couldn't access any show commands at all.
CSCwf67564Device observes memory leak at process SSS Manager
CSCwf34171Configure replace command fails due to the license udi PID XXX SN:XXXX line on IOS-XE devices
CSCwh00963Unable to migrate from ADSL to VDSL without reboot on device
CSCwf69062SDRA-SSLVPN : The SSLVPN session closes with re-authentication error after some interval of time
CSCwf79264In device traffic forwarded to wrong VPN hence, traffic gets wrong zonepair matched and gets dropped.
CSCwf71557IPv4 connectivity over PPP not restored after reload
CSCwf45486OMP to BGP redistribution leads to incorrect AS_Path Installation on chosen next-hop
CSCwh01313Unexpected reboot due QFP UCode due to IPsec functions
CSCwf95527BFD entries removed
CSCwe26895Router has LocalSoftADR crash, writes flat core, and reloads
CSCwh01318Multiple crashes observed on device platform due to memory exhaustion
CSCwf71116Static route keep advertising via OMP even though there is no route.
CSCwf60120Static NAT entry gets deleted from running config; but remains in startup config

ROMmon Release Requirements

Use the following tables to determine the ROMmon version required for your Catalyst 8500 model:

Table 2: Minimum and Recommended ROMmon Releases

DRAMModelMinimum RommonRecommended Rommon
C8500-12X4QC & C8500-12X16GB (default)17.2(1r)17.11(1r)
32GB17.2(1r)17.11(1r)
64GB17.3(2r)17.11(1r)
C8500-20X6CAll variants17.10(1r)17.10(1r)
C8500L-8S4X-17.8(2r) - available from Cisco IOS XE 17.9.1a release17.10(1r)- available from Cisco IOS XE 17.10.1a release
---

Note: In case of C8500L-8S4X platform, the ROMmon image is bundled with the Cisco IOS XE software image which ensures that when the device is booted up, the ROMmon image is also automatically upgraded to the recommended version.

Table 3: ROMmon Release per Platform

ModelROMmon Release
C8500-12X4QC & C8500-12X17.2(1r)
17.3(1r)
17.11(1r)
C8500-20X6C17.10(1r)
C8500L-8S4X17.8(2r)
17.10(1r)

Related Documentation

Table 4: What's New in the ROMMon Release

ROMmon ReleaseFixes
ROMmon Release for C8500-12X4QC, C8500-12X17.3(1r): Supports 64GB DRAM for C8500-12X4QC & C8500-12X
17.10 (1r): Added support for new platform C8500-20X6C
17.11(1r): Fixed a issue in data wipe feature
ROMmon Release for C8500L-8S4X17.10(1r):
  • CSCwa41877 - Fixes for Intel 2021.2 IPU
  • CSCwb67177 - Fixes for Intel 2022.1 IPU
  • CSCwb60723 - Fixes for CPU temperature
  • CSCwb60863 - Fixes for TAM_LIB_ERR_WRITE_FAILURE error

Related Documentation Links:

Communications, Services, and Additional Information

Cisco Bug Search Tool

Cisco Bug Search Tool (BST) is a web-based tool that acts as a gateway to the Cisco bug tracking system that maintains a comprehensive list of defects and vulnerabilities in Cisco products and software. BST provides you with detailed defect information about your products and software.

Documentation Feedback

To provide feedback about Cisco technical documentation, use the feedback form available in the right pane of every online document.

Troubleshooting

For the most up-to-date, detailed troubleshooting information, see the Cisco TAC website at https://www.cisco.com/en/US/support/index.html.

Go to Products by Category and choose your product from the list, or enter the name of your product. Look under Troubleshoot and Alerts to find information for the issue that you are experiencing.


File Info : application/pdf, 10 Pages, 190.86KB

PDF preview unavailable. Download the PDF instead.

cat8500-17-12-rel-notes

References

DITA Open Toolkit XEP 4.30.961; modified using iText 2.1.7 by 1T3XT

Related Documents

Preview Cisco Catalyst 8500 Series Edge Platforms Ordering Guide
A comprehensive guide for ordering Cisco Catalyst 8500 Series Edge Platforms, detailing hardware configurations, Cisco DNA subscription options, software selection, and support services.
Preview Cisco Catalyst 8500 Series Edge Platforms Release Notes 17.18.1a
This document provides release notes for the Cisco Catalyst 8500 Series Edge Platforms, version 17.18.1a. It details new software features, resolved and open issues, compatibility information, and ROMmon upgrade procedures.
Preview Cisco Catalyst 8500 Series Edge Platforms Data Sheet
Comprehensive data sheet detailing the Cisco Catalyst 8500 Series Edge Platforms, including their high-performance cloud edge capabilities, SD-WAN integration, multi-layer security features, and specific models like C8500-20X6C, C8500-12X4QC, C8500-12X, and C8500L-8S4X. Covers platform details, software, specifications, ordering information, and services.
Preview Managing SD-Routing Devices with Cisco SD-WAN Manager Guide
A comprehensive guide detailing how to manage and monitor SD-Routing devices using Cisco SD-WAN Manager, covering onboarding, configuration, and troubleshooting for enterprise networks.
Preview Cisco Catalyst 8000 Edge Platforms: SD-WAN and SASE Solutions
Explore the Cisco Catalyst 8000 Series Edge Platforms, designed for SD-WAN and SASE, offering high performance, advanced security, and flexible deployment options. Includes specifications, modules, and Cisco DNA licensing details.
Preview Cisco Catalyst SD-WAN Control Components Compatibility Matrix Release 20.12.x
This document provides a compatibility matrix for Cisco Catalyst SD-WAN Control Components, Release 20.12.x, detailing compatible software versions for various Cisco routing platforms and virtual platforms.
Preview Cisco TrustSec Integration Guide for SD-WAN
This guide details the integration of Cisco TrustSec with Cisco SD-WAN, focusing on Security Group Tag (SGT) propagation using inline tagging and SXP. It covers configuration, supported hardware, and best practices for network segmentation and security.
Preview Cisco Catalyst 9300 Switches Software Configuration Guide: Cisco IOS XE Dublin 17.12.x
Learn how to configure Cisco Catalyst 9300 Switches with Cisco IOS XE Dublin 17.12.x. This guide covers initial setup, Web UI configuration, network settings, and best practices for enterprise network deployment.