PDF(549.6 KB) View with Adobe Reader on a variety of devices
Updated:November 1, 2017
Bias-Free Language
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This release notes document provides information about Cisco CSR 1000v Series Cloud Services Routers operating with Cisco IOS XE Denali 16.3. You can find CSR1000v release notes for other versions of Cisco IOS XE at Cisco CSR 1000v Release Notes.
Cisco CSR 1000v Series Cloud Services Routers Overview
Virtual Router
The Cisco CSR 1000v Cloud Services Router is a cloud-based virtual router deployed on a virtual machine (VM) instance on x86 server hardware. It supports a subset of Cisco IOS XE software features and technologies, providing Cisco IOS XE security and switching features on a virtualization platform.
When the Cisco CSR 1000v is deployed on a VM, the Cisco IOS XE software functions as if it were deployed on a traditional Cisco hardware platform. You can configure different features depending on the Cisco IOS XE software image.
Secure Connectivity
The Cisco CSR 1000v provides secure connectivity from an enterprise network (such as in a branch office or data center) to the public or private cloud.
A platform’s product landing page lists technology configuration guides for Cisco IOS XE technologies that the platform supports.
In each technology configuration guide, a Feature Information table indicates when a feature was introduced to the technology. For some features, the table also indicates when additional platforms have added support for the feature.
To determine whether a particular platform supports a technology, view the list of technology configuration guides posted on the platform’s product landing page.
System Requirements
The following sections describe the system requirements for the Cisco CSR 1000v Series Cloud Services Routers.
The Cisco CSR 1000v supports activation using Cisco Smart Licensing. To use Cisco Smart Licensing, you must first configure the Call Home feature and obtain Cisco Smart Call Home Services. For more information, see the Cisco CSR 1000v Cloud Services Router Software Configuration Guide.
Evaluation license availability depends on the software version:
Evaluation licenses valid for 60 days are available at the Cisco Software Licensing (CSL) portal: http:/www.cisco.com/go/license
The following evaluation licenses are available:
– AX technology package license with 50 Mbps maximum throughput
– APPX technology package license with 10 Gbps maximum throughput
If you need an evaluation license for the Security technology package, or for an AX technology package with higher throughput, contact your Cisco service representative.
Cisco CSR 1000v software licenses are divided into feature set licenses. Supported feature licenses depend on the release.
Legacy License Types
Three legacy technology packages— Standard, Advanced, and Premium —were replaced in Cisco IOS XE Release 3.13 with the IPBase, Security, and AX technology packages.
Current License Types
The following license types are supported in Cisco IOS XE Denali 16.3.1:
The Cisco CSR 1000v router provides both perpetual licenses and term subscription licenses that support the feature set packages for the following maximum throughput levels:
Beginning with Cisco IOS XE 3.11S, a memory upgrade license is available to add memory to the Cisco CSR 1000v. This license is available only for selected technology packages.
Additional Information about Licenses and Activation
Software Image Nomenclature for OVA, ISO, and QCOW2 Installation Files
The Cisco CSR 1000v installation file nomenclature indicates properties supported by the router in a given release.
The following are filename examples for the 16.3.1 release: csr1000v-universalk9.16.03.01.ova csr1000v-universalk9.16.03.01.iso csr1000v-universalk9.16.03.01.qcow2
Table 1 lists the attributes and the release properties indicated.
Table 1 OVA Installation Filename Attributes
Filename Attribute
Properties
Example: universalk9
Installed image package.
03.09.00a.S.153-2.S0a
Indicates that the software image is for the Cisco IOS XE 3.9.0aS release image (mapped to the Cisco IOS 15.3(2) release).
std or ext
Standard release or extended maintenance support release.
Every third release, an extended maintenance support release (16.3, 16.9, 16.12,...) is planned.
Features and Notes: Release Cisco IOS XE Denali 16.3.5
Notes
Recommended Release for Cisco IWAN
Cisco IOS XE Denali 16.3.5 is not recommended for Cisco IWAN due to the following bugs: CSCvf98783, CSCvg35332, and CSCvg05896. Instead, it is recommended to use Cisco IOS XE Denali 16.3.5c for Cisco IWAN, which provides a fix for these bugs. For more details on these bugs, please see Cisco Bug Search Tool.
Features and Notes: Release Cisco IOS XE Denali 16.3.1a
Notes
Amazon Web Services High Availability (AWS HA)
The method for monitoring AWS HA errors such as BFD peer down events has changed from using an EEM applet (in release Cisco IOS XE 3.16 or earlier) to using new Cisco IOS XE commands (for Cisco IOS XE Denali 16.3.1a or later) that include the redundancy command and sub-command cloud provider [ aws | azure ] node-id.
Use these commands to specify routing changes to the Route-table-id, Network-interface-id and CIDR in the event of an AWS HA error (for Cisco IOS XE Denali 16.3.1a or later).
The following verification commands are also available: show redundancy cloud provider [ aws | azure ] node-id and debug redundancy cloud [ all | trace | detail | error ].
Features and Notes: Release Cisco IOS XE Denali 16.3.1
Features
Hypervisor Support
The following hypervisors are either newly introduced or re-added for this release:- Citrix XenServer, Microsoft Hyper-V, Amazon Web Services and Microsoft Azure. (For Amazon Web Services, instance type C3 is no longer supported.)
Snort-Powered IPS/IDS support on CSR
The Snort IPS feature enables Intrusion Prevention System (IPS) or Intrusion Detection System (IDS) for branch offices on Cisco CSR 1000v. This feature uses the open source Snort solution to enable IPS and IDS. For more information, see the Security Configuration Guide: Unified Threat Defense.
VRF Support for IPS/IDS on CSR
For detailed information, see the following documentation:
DPDK (Dataplane Development Kit) is integrated into the dataplane of the CSR 1000v, using poll-mode drivers.
URL Filtering Support on CSR
Web Filtering enables the user to provide controlled access to Internet websites or Intranet sites by configuring the domain-based or URL-based policies and filters on the device. For more information, see the Security Configuration Guide: Unified Threat Defense.
MVPN PE-PE Ingress Replication
In Multicast VPN (MVPN) or Multipoint to Multipoint LDP (MLDP), multicast traffic received by an ingress provider edge (PE) router is replicated/copied and passes through the core to egress PE routers. State is maintained in the core and this may lead to some dynamic fluctuation of state in the service provider core routers. To improve upon this, when the new feature (PE to PE Ingress Replication (IR)) is used, multicast traffic received by an ingress PE router is replicated/copied and then tunneled over multiple unicast LSPs directly to egress PE routers. State is not maintained as the traffic passes through the core. For more information, see: BGP MVPN PE-PE Ingress Replication in the IP Multicast: MVPN Configuration Guide
Citrix XenServer Support
Support added for XenServer 6.5, 6.2 on Cisco CSR 1000v.
Microsoft Hyper-V Support
Support added for Windows Server 2012-R2 Hyper-V Mgr 6.3.9600.16384 on Cisco CSR 1000v.
BGP IPv6 Admin Distance
For detailed information, see the following documentation:
Effective with Cisco IOS XE Denali 16.3.1, the way PKI Trustpools are managed have changed. The PKI Trustpool Enhancements feature is used for authentication of HTTPS connections built from the router.Common features that leverage this feature include, but not exhaustive, Plug and Play (PnP), Cisco Web Security (CWS), Cisco Umbrella Branch. If you are upgrading to this release, please review the changes to the feature at the following Cisco document:
Memory Requirements when vCPUs Spread across Two Sockets (NUMA Nodes)
In this release, if the CSR 1000v is configured to have vCPUs spread across two sockets (NUMA Nodes), then you must use 5 GB memory (not 4 GB).
Web User Interface
The Web User Interface supports an embedded GUI-based device-management tool that provides the ability to provision the router, simplifies device deployment and manageability, and enhances user experience. The following features are supported on Web User Interface for Cisco IOS XE Denali 16.3:
Limitations and Restrictions in Cisco IOS XE Denali 16.3.1
REST API Management Container Images Compatible with Denali 16.3.1
When using the Cisco IOS XE REST API with the router, note the following limitation: If the router is operating with Cisco IOS XE Denali 16.3.1, use the latest REST API management container image. Attempting to use a REST API container image released prior to Cisco IOS XE Denali 16.x may cause the router to crash repeatedly.
Limitations and Restrictions in Cisco IOS XE Denali 16.3.11
Cisco CSR1000V Release 16.3.11 does not support the 6.4.3f-b4.2 image. If you upgrade your Cisco CSR1000V instance to release 16.3.11, the router moves to an offline state.
Caveats
See open and resolved caveats in the following sections:
Caveats, or “bugs,” describe unexpected behavior. Severity 1 caveats are the most serious. Severity 2 caveats are less serious. Severity 3 caveats are moderate caveats. This section includes severity 1, severity 2, and selected severity 3 caveats.
Terminology
The Dictionary of Internetworking Terms and Acronyms contains definitions of acronyms that are not defined in this document:
If you have an account on Cisco.com, you can also use the Bug Search Tool (BST) to find select caveats of any severity. To reach the Bug Search Tool, log into Cisco.com and go to https://tools.cisco.com/bugsearch/search.
If a defect that you have requested cannot be displayed, it may be because the defect number does not exist or the defect does not have a description available.
In the Product field, enter Cisco Cloud Services Router 1000v.
In the Releases field, enter one or more Cisco IOS XE releases of interest. The search results include caveats related to any of the releases entered in this field.
The tool provides autofill while you type in these fields to assist in entering valid values.
Releases beginning with 3.x have an equivalent release number beginning with 15.x, as shown in the following table. Include the 15.x equivalent to ensure that all relevant caveat results are displayed.
Releases for Cisco IOS XE Denali 16.x, such as Cisco IOS XE Denali 16.3.1 do not have equivalent 15.x releases; for example a search using release number 16.3.1 should find the caveats for Cisco IOS XE Denali 16.3.1.
Table 2 Release Number Equivalents for Cisco IOS XE 3S Releases
For...
...search using the following equivalent release numbers
3.14
3.14 and 15.5(1).
3.15
3.15 and 15.5(2)
3.16
3.16 and 15.5(3)
3.17
3.17 and 15.6(1)
Field Notices
We recommend that you view the field notices for the current release to determine whether your software or hardware platforms are affected. You can access the field notices from the following location:
This document is to be used in conjunction with the documents listed in the
“Related Documentation” section.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.