Asr1000 Rel Notes Xe 17 9
Asr1000 Rel Notes Xe 17 9
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
1
About Cisco ASR 1000 Series Aggregation Services Routers
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and
other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/
legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use
of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)
Note For more information on the features and specifications of Cisco ASR 1000 Series Routers, refer to the Cisco
ASR 1000 Series Routers datasheet.
For information on the End-of-Life and End-of-Sale Announcements for Cisco ASR 1000 Series routers, refer
to the ASR 1000 Series End-of-Life and End-of-Sale Notices.
Note Cisco IOS XE Cupertino 17.9.1a is the first release for Cisco ASR 1000 Series Aggregation Services Routers
in the Cisco IOS XE Cupertino 17.9.x release series.
Note Starting from IOS XE 17.5, the following consolidated platforms (or with dual IOSd) will move to monolith
packaging and will not enable upgrade/downgrade using separate packages:
• ASR 1001-X
• ASR 1001-HX
• ASR1002-X
• ASR 1002-HX
Instead, use the install add file bootflash:<file name> activate commit command to upgrade using a single
image that combines all the separate packages improves the boot time.
Starting from IOS XE 17.6, the ISSU on Cisco ASR 1000 Series Aggregation Services Routers will migrate
to an install workflow that provides step-by-step upgrade/downgrade commands.
The ISSU load version commands will be deprecated and these commands include:
• abortversion
• acceptversion
• checkversion
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
2
Product Field Notice
• commitversion
• config-sync
• image-version
• loadversion
• runversion.
Additionally, dual IOSd ISSU commands and Bundle mode ISSU workflows will also be disabled.
Note The In-Service Software Upgrade (ISSU) in ASR 1000 is being migrated to an install workflow that provides
a step-by-step upgrade/downgrade. Starting from IOS-XE 17.6.1, the following items will be disabled:
• The ISSU load version command set including issu loadversion, issu runversion, issu acceptversion,
and issu commitversion.
• Dual IOSd ISSU commands.
• Bundle mode ISSU workflow.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
3
New and Changed Software Features in Cisco IOS XE 17.9.4
Support for broadband features and functionalities From Cisco IOS XE 17.9.3 release, the following
with DNA Network Advantage Tier 3 License functionalities and features are supported on
ESP100-X & ESP200-X platforms:
• Layer 2 Tunnel Protocol Network Server (LNS)
• Layer 2 Access Concentrator (LAC)
• Broadband Network Gateway (BNG)
• Intelligent Services Gateway (ISG)
• Intelligent Wireless Access Gateway (iWAG).
• PPP and IP sessions
Asymmetric Lease This feature allows you to manage or change the lease renewal in a shorter period of
for DHCPv4 time than the actual lease that is granted by the DHCP server. You can enable this
using the ip dhcp relay short lease command on the server or relay agent.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
4
New and Changed Software Features for Cisco IOS XE 17.9.1a
Feature Description
Displaying link and The show isis node command is updated to display information about link and prefix
prefix cache, and cache, and the show isis lspgen tlv neighbor command is introduced to display
ISIS LSP TLV information about ISIS LSP TLV neighbors.
neighbor
Increase ACE Scale This feature provides an increase in the ACE scale limit per ACL and OGACL as the
Limit Per OGACL current implementation of CACE has a total limit of only 64K entries. The scale for
this feature is 1D and the scale information for OGACL is 3000 ACE entries per
OGACL, 2400 OGs and 100 networks per OG.
Logging Destination The ip nat settings log-destination command is introduced in Carrier Grade Network
IP Address and Port Address Translation (CGN) mode to include the destination IP address and the
Details destination port details in the add and delete HSL records.
Support for BGP This enhancement introduces support for configuring BGP additional paths when
additional paths with label-unicast unique mode is configured.
label-unicast unique
mode
Support for PFP Previously, a separate PDP policy was created for every default IGP/RIB learned path.
with RIB Path This implementation would eventually increase the number of policies and would not
scale. From Cisco IOS XE 17.9.1, RIB path is supported for PFP. This feature enables
you to configure forwarding class in a per flow policy using the RIB path option.
Instead of configuring a per destination policy, the RIB option uses the IGP shortest
path to the policy destination.
Support for This feature introduces support for configuration of unicast-to-multicast destination
Unicast-to-Multicast reflection to facilitate unicast-to-multicast destination translation and
Destination unicast-to-multicast destination splitting. It also provides the capability for users to
Reflection translate externally received unicast destination addresses to multicast addresses.
CUBE: End-to-end With the Cisco Voice Portal (CVP) application, a caller may request an
Secure Calling for automatedcallback, rather than wait in a queue for an extended period. When an agent
Courtesy Call Back becomes available, CVP sends a request to place a call to the original caller. When the
and Unified Contact call is answered, the agent is connected. With this update, outbound calls over a secure
Center Survivability SIP PSTN trunk are possible.
CUBE: Load This enhancement to the DNS session target feature, provides effective call distribution
Balancing for DNS and load balancing of calls based on the preference, priority and availability of hosts
SRV Host provided in DNS SRV Resource Records. This feature further simplifies configuration
by allowing effective call distribution with a single dial-peer.
CUBE: Options Previously, CUBE (Local Gateway) had to be configured with separate dial-peers to
Ping for DNS SRV monitor the availability of individual proxies used in services such as Webex Calling.
Hosts To simplify this configuration, all targets resolved from a DNS SRV record may now
be monitored using a common Options Ping policy defined for a single dial-peer. If a
remote server becomes unresponsive, CUBE will busy out that destination, allowing
calls to be sent to alternative destinations.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
5
New and Changed Software Features for Cisco IOS XE 17.9.1a
Feature Description
Transfer of Call Cisco IOS gateways can use FTP and now SFTP servers to transfer call accounting
Detail Records files.
Using SFTP
Programmability Feature
Pubd Restartability The pubd process is restartable on all platforms in this release. Prior to this release,
pubd was restartable only on certain platforms. On other platforms, to restart the pubd
process, the whole device had to be restarted.
New mechanism to A new mechanism to send data privacy related information was introduced. This
send data privacy information is no longer included in a RUM report.
related information
If data privacy is disabled (no license smart privacy{all|hostname|version} command
in global configuration mode), data privacy related information is sent in a separate
sync message or offline file.
Depending on the topology you have implemented, the product instance initiates the
sending of this information in a separate message, or CSLU and SSM On-Prem initiates
the retrieval of this information from the product instance, or this information is saved
in an offline file.
For more information, see license smart (global config).
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
6
Resolved and Open Bugs for Cisco IOS XE 17.9.x
Feature Description
RUM Report For all topologies where the product instance initiates communication, the minimum
Throttling reporting frequency is throttled to one day. This means the product instance does not
send more than one RUM report a day.
The affected topologies are: Connected Directly to CSSM, Connected to CSSM Through
CSLU (product instance-initiated communication), CSLU Disconnected from CSSM
(product instance-initiated communication), and SSM On-Prem Deployment (product
instance-initiated communication).
This resolves the problem of too many RUM reports being generated and sent for
certain licenses. It also resolves the memory-related issues and system slow-down that
was caused by an excessive generation of RUM reports.
You can override the reporting frequency throttling, by entering the license smart
sync command in privileged EXEC mode. This triggers an on-demand synchronization
with CSSM or CSLU, or SSM On-Prem, to send and receive any pending data.
RUM report throttling also applies to the Cisco IOS XE Amsterdam 17.3.6 and later
releases of the 17.3.x train, and Cisco IOS XE Bengaluru 17.6.4 and later releases of
the 17.6.x train. From Cisco IOS XE Cupertino 17.9.1, RUM report throttling is
applicable to all subsequent releases.
Virtual Routing and On a product instance where VRF is supported, you can configure the license smart
Forwarding (VRF) vrf vrf_string command and use a VRF to send licensing data to CSSM, or CSLU, or
Support SSM On-Prem.
Note When using a VRF, the supported transport types are smart and cslu
only.)
For more information, see license smart (global config)
CSCwj88872 IPsec tunnel fails to establish due to error IPSec policy invalidated proposal
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
7
Resolved Bugs for Cisco IOS XE 17.9.6
Bug ID Description
CSCwj84949 Unencrypted Traffic Due to Non-Functional IPsec Tunnel in FLEXVPN Hub & Spoke
Setup
CSCwj40589 Endpoint tracker using DNS does not log "DOWN" message when DNS server
reachability is lost
CSCwk33173 EzPM application-performance profile cause memory leak and crash with long-lived
idle TCP flows
CSCwj24511 Tunnel QoS - WRED incorrect IP precedence classification with MPLS EXP
CSCwb47658 Repeated and endless messages "Network change event - activated 4G Carrier
Aggregation."
CSCwj73113 MGCP GW doesn't respond with 250 OK for a DLCX leading to DLCX loop from
CUCM side
CSCwj03621 Ping with smaller packet size is failing on macsec enabled port.
CSCwi25737 Router should discard IKE Notification messages with incorrect DOI.
CSCwj36915 Router: macsec not working under LACP port-channel member port.
CSCwj02110 EPA-2x40GE: Process mcpcc-lc-ms crash seen due to mka session SAK rekey/PN
expiry.
CSCwk53680 Inbound calls through VG400 results in phantom calls (64.3.0, 60.1.4, 62.3.3).
CSCwj48421 FlexVPN Client : IPsec tunnels are down due to issue with SADB detach and delete.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
8
Open Bugs for Cisco IOS XE 17.9.6
Bug ID Description
CSCwj79987 SD-WAN Router does not establish BFD sessions after upgrade to 17.9.3a or 17.9.4a.
CSCwk89256 vManage/IOS-XE 17.9.3 speed mismatch in IOS-XE configuration after device template
push for ISR.
CSCwi15930 Router failing to upgrade from 17.6.3a to 17.6.5 due to CDB issue.
CSCwi51234 Unable to activate properly Foundation Suite license on ASR running 17.9.4a.
CSCwk49806 Router running IOS 17.06.05 rebooted unexpectedly due to process NHRP crash.
CSCwj13395 Router Data plane crashed when starting a new NWPI trace from this device with NAT
DIA/ZBFW.
CSCwk75459 MGCP GW fails to respond with 250 OK when there's a delay from dataplane in
gathering statistics.
CSCwk56504 In NAT64 scenario, IPv4 packets that needs translation might be dropped b device.
CSCwf73123 BFD timers reverting back to default value after negotiating correctly.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
9
Open Bugs for Cisco IOS XE 17.9.6
Bug ID Description
CSCwb25507 CWMP : Add vendor specific parameter for NBAR protocol pack version.
CSCwh50510 Router Crash with Segmentation fault(11), Process = NHRP when processing NHRP
traffic.
CSCwk31715 After deleting a NAT configuration, the IP address still shows up in routing table.
CSCwm27005 "CCA Detected Logic Error, code = 14" Traceback seen constantly.
CSCwf25735 QoS more than four remark with set-cos not work .
CSCwc42837 Router crash when creating VRF when subscriber event tracing is enabled.
CSCwk30527 IKEv2 session is down after reload if identity local address is assigned to interface on
Switch.
CSCwh45169 Unexpected Reboot while Dispalying Information from Cleared SSS Session.
CSCwk44078 GETVPN / Migrating to new KEK RSA key doesn't trigger GM re-registration.
CSCwm27647 BFD sessions are down and not recovering for one color after Hub replacement.
CSCwm32269 Cisco DNA Center - SBEN Onboarding fails - EAP-TLS Failed to fetch IP address.
CSCwk22942 Unable to build two IPSec SAs w/same source/destination where one peer is PAT'd
through the other.
CSCwk57979 emd fault on cc_0_0 (rc=134) due to ensor has exceeded it's maximum number of read
errors.
CSCwh41497 DDNS update retransmission timer fails to work with a traceback error.
CSCwc86434 Static NAT DIA inside static routes being advertised over OMP to remote sites.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
10
Resolved Bugs for Cisco IOS XE 17.9.5a
Bug ID Description
CSCwi16111 ipv6 tcp adjust-mss not working after delete and reconfigure
CSCwk81360 Cisco IOS-XE Router can reboot unexpectedly while configuring NAT Static
Translation
CSCwi63042 Packet drops observe between LISP EID over GRE Tunnel
CSCwj54638 ASR1001-HX: EVC Q-in-Q configuration may filter out certain vlans
CSCwh22451 Packets appeared out of order when using Embedded Packet Capture (EPC).
CSCwf89154 EZMAN posted stats to APIs: Ingress and Egress Bytes counters suddenly jump for
sub-interfaces.
CSCwh85803 The MACsec session is in a secured state but stuck without sending any traffic.
CSCwi28781 EPBR will generate an error when the policy is added and deleted multiple times.
CSCwh25168 A CPLD upgrade failed error message is logged during ROMmon upgrade.
CSCwf51206 In EVPN, BUM traffic is not flooded to the bridge domain interface.
CSCwh93257 The device creates a crooked NAT entry if two or more IP phones from the NAT
outside register to the same server.
CSCwh59064 Depletion in the process memory pool/IOSd after enabling virtualization on the IOS-XE
platform.
CSCwf99947 Crash when modifying tunnel after running show crypto commands.
CSCwh59411 Device's fifty-gig port returns a link-flap err-disabled status when the peer device
reloads or bounces.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
11
Resolved Bugs for Cisco IOS XE 17.9.5a
Bug ID Description
CSCwf23291 write or do write saves configuration, but RSA keys/SSH are lost after reload.
CSCwc79115 Policy commit failure notification and alarm from management software.
CSCwh06834 Using special characters in the password while generating a token generates an invalid
token.
CSCwh68508 Unexpected reboot after establishing control plane of EVPN MPLS and receiving
packets.
CSCwf82676 CPU usage mismatch in show sdwan system status vs show process CPU platform.
CSCwf03193 Device crash with crash info files generated with segmentation fault, process IPSEC
key engine.
CSCwh08434 OMP route is being advertised although the route is not available.
CSCwf26875 Interface from Port-channel going to suspended status after applying platform QoS
port-channel-aggregate.
CSCwf24164 NetFlow stops working when flow monitor reaches cache limit in the device.
CSCwf65540 Running more than 4 tests on network agent causes tracebacks on device running
software in a docker container.
CSCwe14885 VPN is established although the peer is using a revoked certificate for authentication.
CSCwe91898 Environmental syslog is not appearing when the power cord is disconnected from the
redundant power supply.
CSCwh30377 Device data plane crash in DNS security processing due to incorrect UDP length.
CSCwf34171 configure replace command fails due to the license udi PID XXX SN:XXXX line on
IOS-XE devices.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
12
Open Bugs for Cisco IOS XE 17.9.5a
Bug ID Description
CSCwe64779 Router software forced reset during high IPC congestion with IPSec.
CSCwh00963 Unable to migrate from ADSL to VDSL without reboot on the device.
CSCwe85301 Crypto process crash when PKI trust point is being deleted.
CSCwh20734 Crypto process crash when PKI trust point is requested and deleted.
CSCwc97579 Spoke-spoke cache refresh not working correctly in case of multiple cache entries for
the same next hop.
CSCwf11394 Debug log should mention port-hop and reason prior to DISTLOC.
CSCwf04866 Keyman process crash seen while re-generating SSH key in the device.
CSCwh00332 B2B NAT: When configuring IP NAT inside/outside on the interface, ACK/SEQ
number abnormal.
CSCwi51234 Unable to properly activate the Foundation Suite License on the device.
CSCwb55514 Unexpected reboot of the ESP observed after enabling platform qos
port-channel-aggregate.
CSCwf25735 QoS with more than four remarks using set-cos does not work.
CSCwi34743 Device's Tx queue depth is twice the q-limit, resulting in output discards.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
13
Open Bugs for Cisco IOS XE 17.9.5a
Bug ID Description
CSCwe24491 Static NAT with HSRP stops working after removing/adding standby.
CSCwi53951 Packets with unicast MAC get dropped on a Port Channel Layer 2 sub-interface after
a device reboot.
CSCwh80441 Cosmetic issue causing distress to customers - Modem WCDMA 900 is displayed as
Unknown.
CSCwh50510 Device crash with segmentation fault (11), Process = NHRP when processing NHRP
traffic.
CSCwi51326 CPP CP SVR crash after decoding all packets to text (using L2 copy) on FIA trace.
CSCwi10735 Zone-Based Firewall drops transit packets due to 'Invalid ACK number'.
CSCwh18120 IKEv2 - Diagnose feature is taking 11% CPU during session set up.
CSCwh41497 DDNS update retransmission timer fails to work, resulting in a traceback error.
CSCwi25737 Router should discard IKE Notification messages with incorrect DOI.
CSCwh22414 Warning and critical CPU utilization thresholds not recomputed when using
data-plane-heavy mode.
CSCwi01046 PoE module is not providing enough power to activate the ports after an unexpected
reload.
CSCwi16111 IPv6 TCP adjust-mss not working after delete and reconfigure.
CSCwi63042 Packet drops observed between LISP EID over GRE Tunnel.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
14
Resolved Bugs - Cisco IOS XE 17.9.4a
Bug ID Description
CSCwb25507 CWMP: Add vendor specific parameter for NBAR protocol pack version.
CSCwh91136 Traffic not encrypted and dropped over IPSEC SVTI tunnel.
Bug ID Description
CSCwe85301 Crypto PKI-CRL-IO_0 process crash when PKI trustpoint is being deleted.
CSCwf41492 NHRP BFD flaps randomly with dynamic tunnel (NHRP phase 3) in DMVPN.
CSCwe14885 VPN is established although the peer is using a revoked certificate for authentication.
CSCwc86434 Static NAT DIA inside static routes being advertised over OMP to remote sites.
CSCwf34171 configure replace command fails due to the license udi PID XXX SN:XXXX line
on IOS-XE devices.
CSCwf24164 Netflow stops working when flow monitor reaches cache limit in 8500L
CSCwe95072 Unexpected reload due to memory corruption when modifying and access list.
CSCwf03193 Device crash with crashinfo files were generated with segmentation fault, rocess IPSEC
key engine.
CSCwf25735 Device QoS more than four remark with set-cos not work.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
15
Resolved Bugs for Cisco IOS XE 17.9.4
Bug ID Description
CSCwf11394 IOS XE - device debug log should mention port-hop and reason prior to DISTLOC.
CSCwd61988 Output packet bytes calculation biase when we enable QoS on port channel.
CSCwf60120 Static NAT entry gets deleted from running config; but remains in startup config.
CSCwe93905 NAT ALG is changing the call-ID within SIP message header causing calls to fail.
CSCwe24210 SNMP MIB does not show correct firmware version for device LTE module.
CSCwe18124 MACsec remains marked as SECURED, but the traffic stops working randomly.
CSCwd87195 NAT configuration with redundancy, mapping id and match-in-vrf options with no-alias
support.
CSCwd34941 NAT configuration with no-alias option is not preserved after reload.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
16
Resolved Bugs for Cisco IOS XE 17.9.4
Bug ID Description
CSCwd49309 Crash seen on device with traffic pointing to segfault in coff handler.
CSCwe37123 Device uses excessive memory when configuring ACLs with large object groups.
CSCwe39011 GARP on port up/up status from device is not received by remote peer device.
CSCwf39490 MCID (Malicious Call Identification) gets broken due to custom prefix setting under
STCAPP FAC.
CSCwe19084 NAT: Traffic is not translated to the same global address though PAP is configured.
CSCwe69783 Device can lose its configuration during a triggered resync process if lines are in an
off-hook state.
CSCwe89404 No way audio when using secure hardware conference with secure endpoints.
CSCwa96399 Configuring entity-information xpath filter causes syslogs to print, does not return
data.
CSCwc89823 Router crashes due to CPUHOG when walking Cisco Flash MIB
@snmp_platform_get_flash_file_info.
CSCwf37888 Device Packet Duplication: Duplicate packets are counted on Primary Tunnel Interface
Statistics.
CSCwd35047 Failed to ping gateway while configuring SharedLOM with console , te1 interface
until router reload.
CSCwd49177 ISG: L2-connected subscriber. IPv6 prefix delegation is not reachable when packet
are switched.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
17
Open Bugs for Cisco IOS XE 17.9.4
Bug ID Description
CSCwe80684 QFP Ucode crash when clearing MACs under BD in EVPN scenario.
CSCwe12090 No error log generated when EVC/bridge-domain reaches maximum MAC learning
limit on device.
CSCwd93401 AppNav-XE: Policy-map edit on cluster with multiple service context fails to program
TCAM.
CSCwf45769 Ingress and Egress bytes counters can suddenly increase and are not accurate for
sub-interfaces.
CSCwe85301 Crypto PKI-CRL-IO_0 process crash when PKI trustpoint is being deleted.
CSCwf41492 NHRP BFD flaps randomly with dynamic tunnel (NHRP phase 3) in DMVPN.
CSCwe14885 VPN is established although the peer is using a revoked certificate for authentication.
CSCwc86434 Static NAT DIA inside static routes being advertised over OMP to remote sites.
CSCwf34171 configure replace command fails due to the license udi PID XXX SN:XXXX line
on IOS-XE devices.
CSCwf24164 Netflow stops working when flow monitor reaches cache limit in 8500L
CSCwe95072 Unexpected reload due to memory corruption when modifying and access list.
CSCwf03193 Device crash with crashinfo files were generated with segmentation fault, rocess IPSEC
key engine.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
18
Resolved Bugs for Cisco IOS XE 17.9.3a
Bug ID Description
CSCwf25735 Device QoS more than four remark with set-cos not work.
CSCwf11394 IOS XE - device debug log should mention port-hop and reason prior to DISTLOC.
CSCwd61988 Output packet bytes calculation biase when we enable QoS on port channel.
CSCwf60120 Static NAT entry gets deleted from running config; but remains in startup config.
CSCwd45402 MSR Unicast-To-Multicast not working if DST and SRC are the same in Service
Reflect configuration.
CSCwd90168 Unexpected reload after running show voice dsp command while an ISDN call
disconnects.
CSCwd16559 ISG FFR: ARP request to reroute nexthop IP is not triggered if ARP entry not in ARP
table.
CSCwd79089 Device-L controller crash when sending full line rate of traffic with >5 Intel AX210
stations,
CSCwd16664 GetVPN long SA - GM re-registration after encrypting 2^32-1 of packets in one IPSEC
SA.
CSCwd81357 QoS classification not working for DSCP or ACL + MPLS EXP.
CSCwd89338 Clear ISG existing lite-session upon reception of DHCP packet for same client.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
19
Open Bugs for Cisco IOS XE 17.9.3a
Bug ID Description
CSCwd25107 Interface VLAN placed in "shutdown" state when configured with ip address pool.
CSCwd61255 Data plane crash on device when making per-tunnel QoS configuration changes with
scale
CSCwc65697 vCube crashing and restarting during call flow with new image.
CSCwd84599 Dataplane memory utilization issue - 97% QFP DRAM memory utilization.
CSCwe03614 CWMP : MAC address of ATM interface is not included in inform message.
CSCvy14316 MPLS VPN traffic dropped due FDB OOM with cause FIAError under scale flow
number (<1M).
CSCwd85580 Device unexpected reload after set ospfv3 authentication null command.
CSCwd33202 DHCP behavior issue when BDI interface is enabled on WAN and SVI interface.
CSCwd47123 ISG uses identifier mac-address 0000.0000.0000 when DHCP LQ does not reply.
CSCwd72312 GETVPN: Traffic drops seen on GM after rekey installing policies on image.
CSCwe53849 Observed crash in CPP, UCode & FMAN while upgrading to with crypto module
present.
CSCwe19084 NAT: Traffic is not translated to the same global address though PAP is configured.
CSCwe09805 OID for SNMP monitoring of DSP resources are not working as expected.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
20
Resolved Bugs for Cisco IOS XE 17.9.2a
Bug ID Description
CSCwe14885 VPN is established although the peer is using a revoked certificate for authentication.
CSCwe24491 Static NAT with HSRP stops working after removing/adding standby.
CSCwc28468 Device always fails to push any template to device if device is running in FIPS mode.
CSCwc06327 PFP policy in SRTE, RIB resolution in FC bring down ipsec tunnel interface- stuck
at linestate down.
CSCwd34941 NAT configuration with no-alias option is not preserved after reload.
CSCwe37184 Device seeing out of service on switch modules when using with new DC power supply.
CSCwc21739 NAT not requesting further for low ports after initial allocation when CLI knob
reserved-ports set.
CSCwc39012 Crash saving tracelogs after Too many open files error.
CSCwc37320 RP switchover causes linecard NFS mount failure resulting in memory leak.
CSCwc82140 QFP crash when ZBFW configuration features log dropped-packets configuration.
CSCwc96444 Device is not programming correct next-hop for unicast prefix with multicast config
present.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
21
Resolved Bugs for Cisco IOS XE 17.9.2a
Bug ID Description
CSCwd06118 IKEv2 Cert-based IPSEC not working between IOS-XE and AWS.
CSCwc43794 Device VRF+NAT Outside Source Static - Drop packets during FTP (Active-mode)
execution.
CSCwc20170 Device reloads unexpectedly due to critical FTMD fault when VRF configuration is
pushed.
CSCwb89958 Unified Policy HSL not sending properly NBAR application information.
CSCwc52538 Flows are not distributed and load-balanced evenly and consistently.
CSCwc45950 ZBFW self zone policy drops ssh session on Mgmt-intf 512 ports.
CSCwc79145 Throughput degrades when Local TLOC specified in Data Policy goes down.
CSCwb65396 CLI template push fails with error: 'Error: on line 48: line-mode single-wire line 0'.
CSCvz89354 Router running crashes due to CPUHOG when walking cisco flash MIB.
CSCwb48953 Device speed test failing with Device Error: Speed test in progress.
CSCwd11365 Needs cert update - Azure CGW creation fails due to NVA provisioning failure.
CSCwb08057 ISG: Number of lite sessions conversion in progress counter not decrementing on failed
account-logon.
CSCwc29629 Crashes when Virtual-Access tries to bring-up/bring-down OSPFv3 ipsec crypto session
authentication.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
22
Open Bugs for Cisco IOS XE 17.9.2a
Bug ID Description
CSCwc77177 BFD and control packets are dropped when ACL is applied on gigi to which loopback
is bind.
CSCwc68132 SIG tunnel tracker packets are dropped by firewall with self zone policy.
CSCwd56015 UTD skipped when interface UTD config is used to enable/disable UTD.
CSCwd56336 BFD sessions are not coming up after flapping the interface due to low ftm rate.
CSCwd44006 Control Connection on device doesn't come-up with reverse proxy using Enterprise
Certificate.
CSCwd17579 Router crashing with reason CPU usage due to Memory Pressure exceeds threshold
(Reboot).
CSCwd17381 NAT/DIA traffic is skipping UTD in forward direction after SSNAT path from
service-side.
CSCwd12955 NAT translation is not correctly sent to hub router from branch when SSNAT and
UTD are configured.
CSCwd15560 With 2 sequences, should not skip if the match is different and action is same.
CSCwd36621 CERM may kick in due to IPSec sessions initiated for on-demand tunnels.
CSCwd37410 0365 and MS Teams applications access issues when using DIA with app-list match
in data-policy.
CSCwc28468 Device always fails to push any template if it is running in FIPS mode.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
23
Resolved Bugs for Cisco IOS XE 17.9.1a
Bug ID Description
CSCwd29334 Upgrade failures due to inability to establish netconf connection from device to
upgrade-confirm.
CSCwd45508 Device does not form BFD across Serial link when upgrading.
CSCwa96399 Configuring entity-information xpath filter causes syslogs to print, does not return
data.
CSCwd34941 NAT configuration with no-alias option is not preserved after reload.
CSCwd18028 After delete CSP, new CCM bring up on existing CSP is stuck in Initializing CCM on
MT cluster.
CSCwa52627 Incorrect Tx/Rx optical power values reported for QSFP transceivers.
CSCwb44275 Simulated flows with PPPoE with NAT DIA result in crash consistently.
CSCwa68540 FTP data traffic broken when UTD IPS enabled in both service VPN.
CSCvx00230 Device may show input/output rate values even if the interface is in admin down state.
CSCwb33968 Device failed to display active flows when flow count is high on the device.
CSCwb11389 NAT translation stops suddenly (ip nat inside doesn't work).
CSCwb39098 Router crashed after new IPv6 address assigned when router use specific configuration.
CSCwa67886 UDP based DNS resolution doesn't work with IS-IS EMCP on IOX-XE/
CSCvz84588 Destination prefix packets getting dropped because forwarding plane is not
programming the next hop.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
24
Resolved Bugs for Cisco IOS XE 17.9.1a
Bug ID Description
CSCwb27486 New key for NBAR app and NBAR category without OGREF optimized.
CSCwa49721 Hub with firewall configured incorrectly dropping return packets when routing between
VRFs.
CSCwb21645 NAT traffic gets dropped when default route changes from OMP to NAT DIA route.
CSCwb51238 Router reload unexpectedly two times when enter netflow show command.
CSCwa48512 CoR intercepted DNS reply packets dropped with drop code 52 (FirewallL4Insp) if
UTD enabled also.
CSCwa78348 Traceback: IOS-XE reload after Segmentation fault on Process = SSS Manager.
CSCvz81664 Enabling or disabling OMP overlay AS prevents connected routes from being advertised
in OMP.
CSCwa08847 ZBFW policy stops working after modifying the zone pair.
CSCvw50622 NHRP network resolution not working with link-local IPv6 address.
CSCwa57873 Incorrect reload reason - last reload reason: LocalSoft for Netconf Initiated request.
CSCwb18315 Umbrella DNS security policy doesn't work with Cloud on Ramp with SIG tunnels.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
25
Open Bugs for Cisco IOS XE 17.9.1a
CSCwb68897 "Total output drops" counter in "show interface" on Port-channel doesn't work properly.
CSCvz89354 Router crashes due to CPUHOG when walking Cisco Flash MIB.
CSCwc19171 High CPU on SIP (mip100) due to mcpcc-lc-ms caused by link up/down interrupts.
CSCwc26669 TLB miss for lock address during FNF cache lookup.
CSCwc39012 Crash saving tracelogs after "Too many open files" error.
CSCwb89958 Unified Policy HSL not sending properly NBAR application information.
CSCwc52538 Device flows are not distributed and load-balanced evenly and consistently.
CSCwc20170 Device reloads unexpectedly due to critical FTMD fault when VRF configuration is
pushed.
CSCwb88621 Device unable to establish control connection with vBond due to out of order DTLS
packets.
CSCwc37465 Static NAT configuration in CLI with the no-alias keyword cannot be retrieved via
NETCONF/YANG.
CSCwc59598 Statistics collection causing service-side BFD to flap on every collection interval.
CSCwc59650 Show device app-fwd cflowd flows vpn X format tabled does not show all flows for
vpn X.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
26
ROMmon Release Requirements
Bug ID Description
CSCwc63563 Unable to set specific speed and duplex values on SFP ports on IOS-XE routing
platforms.
CSCwc43973 DLC is not completing after upgrading to Smart licensing from CSL.
CSCwc53885 IOS-XE "no ip nat" config is allowed to be committed and removes NAT routes among
other NAT config.
CSCwb08057 ISG: Number of lite sessions conversion in progress counter not decrementing on failed
account-logon.
CSCwc63337 Destination not reachable if configured as a next for a static route resolvable via non
/32 OMP.
CSCwc29629 Crashes when Virtual-Access tries to bring-up/bring-down OSPFv3 ipsec crypto session
authentication.
CSCwc68132 SIG tunnel tracker packets are dropped by firewall with self zone policy.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
27
Related Documentation
Note After upgrading the ROMmon to version 17.3(1r), you cannot revert it to a version earlier than 17.3(1r) for
the following platforms:
• ASR 1001-X
• ASR 1001-HX
• ASR 1002-HX
This restriction is only applicable for these platforms. If you have upgraded to ROMmon version 17.3(1r) on
any other platform, reverting to an earlier version of ROMmon is permitted and does not cause any technical
issues.
Related Documentation
• Release Notes for Previous Versions of ASR 1000 Series Aggregation Services Routers
• Hardware Guides for Cisco ASR 1000 Series Aggregation Services Routers
• Configuration Guides for ASR 1000 Series Aggregation Services Routers
• Product Landing Page for ASR 1000 Series Aggregation Services Routers
• Datasheet for ASR 1000 Series Aggregation Services Routers
• Upgrading Field Programmable Hardware Devices for Cisco ASR 1000 Series Routers
• Cisco ASR 1000 Series Aggregation Services Routers ROMmon Upgrade Guide
• Field Notices
• Cisco Bulletins
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
28
Documentation Feedback
Documentation Feedback
To provide feedback about Cisco technical documentation, use the feedback form available in the right pane
of every online document.
Troubleshooting
For the most up-to-date, detailed troubleshooting information, see the Cisco TAC website at
https://www.cisco.com/en/US/support/index.html.
Go to Products by Category and choose your product from the list, or enter the name of your product. Look
under Troubleshoot and Alerts to find information for the issue that you are experiencing.
Release Notes for Cisco ASR 1000 Series, Cisco IOS XE Cupertino 17.9.x
29
© 2022–2023 Cisco Systems, Inc. All rights reserved.