Release Notes for Cisco vEdge Device, Cisco SD-WAN Release 20.3.x


Note


To achieve simplification and consistency, the Cisco SD-WAN solution has been rebranded as Cisco Catalyst SD-WAN. In addition, from Cisco IOS XE SD-WAN Release 17.12.1a and Cisco Catalyst SD-WAN Release 20.12.1, the following component changes are applicable: Cisco vManage to Cisco Catalyst SD-WAN Manager, Cisco vAnalytics to Cisco Catalyst SD-WAN Analytics, Cisco vBond to Cisco Catalyst SD-WAN Validator, and Cisco vSmart to Cisco Catalyst SD-WAN Controller. See the latest Release Notes for a comprehensive list of all the component brand name changes. While we transition to the new names, some inconsistencies might be present in the documentation set because of a phased approach to the user interface updates of the software product.

These release notes accompany the Cisco SD-WAN Release 20.3.x, which provides Cisco Catalyst SD-WAN capabilities. They include release-specific information for Cisco Catalyst SD-WAN Controllers, Cisco Catalyst SD-WAN Validators, and Cisco SD-WAN Manager as applicable to Cisco vEdge devices.

For release information about Cisco IOS XE Catalyst SD-WAN devices, refer to Release Notes for Cisco IOS XE Catalyst SD-WAN Devices, Cisco IOS XE Release Amsterdam 17.3.x.

What's New for Cisco SD-WAN Release 20.3.x

This section applies to Cisco vEdge devices.

Cisco is constantly enhancing the SD-WAN solution with every release and we try and keep the content in line with the latest enhancements. The following table lists new and modified features we documented in the Configuration, Command Reference, and Hardware Installation guides. For information on additional features and fixes that were committed to the SD-WAN solution, see the Resolved and Open Bugs section in the Release Notes.

Table 1. Cisco SD-WAN Release 20.3.1 for vEdge Routers
Feature Description

User Documentation and Interactive Help in Cisco vManage

User Documentation

Starting from this release, we've restructured the listing page of our configuration guides to display category-wise book and chapter contents. This new page lets you switch between releases using the View Documents by Release drop-down list.

Interactive Help in Cisco vManage

This feature helps you navigate Cisco vManage and complete vManage procedures using guided workflows. The Interactive Help points to elements within the Cisco SD-WAN Manager interface and shows you where to click next and what to do to complete a selected workflow.

Cisco SD-WAN Getting Started

Cisco vManage Cluster Upgrade

This feature outlines the upgrade procedure for Cisco vManage servers in a cluster to Cisco vManage Release 20.3.1.

On-Site Bootstrap Process for Cisco vEdge 5000 using SHA2 Enterprise Certificates

By default, a Cisco vEdge 5000 device uses an SHA1 certificate for authentication with controllers in the overlay network. With this feature, you can authenticate the device using an OTP and a Public Key, and install an SHA2 enterprise certificate on the device. By authenticating the device using an OTP and a Public Key and installing an SHA2 enterprise certificate, you can bypass SHA1 certificate authentication and secure the device against SHA1 vulnerabilities.

Systems and Interfaces

Export vManage Audit Log as Syslog

The Cisco vManage NMS exports audit logs in syslog message format to a configured external syslog server. This feature allows you to consolidate and store network activity logs in a central location.

Configure Sessions in Cisco vManage

This feature lets you see all HTTP sessions open within Cisco vManage. It gives you details about the username, source IP address, domain of the user, and other information. A user with User Management Write access, or a netadmin user can trigger a log out of any suspicious user's session.

You can set client session timeouts, session lifetimes, server session timeouts, and enable the maximum number of user sessions in Cisco vManage.

Support for Multiple VRRP Groups on the Same LAN Interface or Sub-interface

This feature increases support from one VRRP group per interface to five VRRP groups per interface. Multiple VRRP groups are useful for providing redundancy and for load balancing.

Dynamic On-Demand Tunnels

This feature enables you to configure an Inactive state for tunnels between edge devices, reducing performance demands on devices and reducing network traffic.

Routing

Route Leaking Between Transport VPN and Service VPNs

This feature enables you to leak routes bidirectionally between the transport VPN and service VPNs. Route leaking allows service sharing and is beneficial in migration use cases because it allows bypassing hubs and provides migrated branches direct access to non-migrated branches.

Policies

Service insertion tracker support

This feature extends support for service chaining to Cisco IOS XE SD-WAN devices. On Cisco IOS XE SD-WAN devices and Cisco vEdge devices, it adds a tracking feature that logs the availability of a service.

Security

Self Zone Policy for Zone-Based Firewalls

This feature allows you to define firewall policies for incoming and outgoing traffic between a self zone of an edge router and another zone. When a self zone is configured with another zone, the traffic in this zone pair is filtered as per the applied firewall policy.

Extended DNS (EDNS) and Local Domain Bypass Support with Cisco Umbrella Integration

This feature enables cloud-based security service on Cisco vEdge devices by inspecting the DNS query. Once the DNS query is inspected, action is taken on it based on whether the query is for a local domain or an external domain.

Cloud OnRamp

New Configuration Workflow for Cloud onRamp for SaaS for Cisco vEdge devices

This feature updates the existing configuration workflow for Cloud onRamp for SaaS for Cisco vEdge devices.

Support Catalyst 48Y4C (Cloud OnRamp for Colocation)

This release supports the use of Cisco Catalyst 9500-48Y4C switches in the Cloud onRamp for Colocation cluster that enables 80G-200G of bidirectional throughput.

Flexible Topologies (Cloud OnRamp for Colocation)

This feature provides the ability to flexibly insert the NIC cards and interconnect the devices (CSP devices and Catalyst 9500 switches) within the Cloud onRamp for Colocation cluster. Any CSP ports can be connected to any port on the switches. The Stackwise Virtual Switch Link (SVL) ports can be connected to any port and similarly the uplink ports can be connected to any port on the switches.

TACACS Authentication (Cloud OnRamp for Colocation)

This feature allows you to configure the TACACS authentication for users accessing the Cisco CSP and Cisco Catalyst 9500 devices. Authenticating the users using TACACS validates and secures their access to the Cisco CSP and Cisco Catalyst 9500 devices.

Network Assurance –VNFs: Stop/Start/Restart (Cloud OnRamp for Colocation)

This feature provides the capability to stop, start, or restart VNFs on Cisco CSP devices from the Colocation Clusters tab. You can easily perform the operations on VNFs using Cisco vManage.

TAC Access

TAC Access to Cisco SD-WAN Manager

When working with the Cisco Technical Assistance Center (TAC) to address an issue in Cisco SD-WAN Manager, users may provide TAC with access to Cisco SD-WAN Manager or TAC teams may access Cisco SD-WAN Manager using the consent token mechanism. In the past, this access has relied on a user account called viptelatac. In this release, two separate user accounts have been added, one with read-only access and one with write access. The accounts use a challenge-response authentication method.

TCP Optimization

TCP Optimization Support for Cisco ISR1100 6G

Added TCP Optimization support for the Cisco ISR1100 6G platform.

Important Notes, Known Behavior, and Workaround

  • Cisco vManage Release 20.3.1 implements a hardened security posture to comply with FedRamp guidelines. As a result, your Cisco SD-WAN Analytics login credentials that are stored locally get erased on upgrading the software, and you cannot access the Cisco SD-WAN Analytics service directly through Cisco SD-WAN Manager. In this case, log in to Cisco SD-WAN Analytics using this URL: https://analytics.viptela.com. If you can’t find your Cisco SD-WAN Analytics login credentials, open a case with Cisco TAC support.

  • For Cisco Catalyst SD-WAN Control Components Releases 20.3.1, 20.3.2, and 20.3.2.1, you must run the messaging server on all the active instances of the Cisco SD-WAN Manager cluster when deploying the Cisco SD-WAN Manager cluster. See the High Availability Configuration Guide for vEdge Routers for more information.

  • Starting from Cisco SD-WAN Release 20.3.1 and later releases, the Cisco Cloud Infrastructure monitoring service is changed to a push based model, for cloud-hosted controllers provisioned by Cisco, for cloud subscription customers. As part of this model, Cisco SD-WAN Manager authenticates with the monitoring system to send the health status data. This model no longer requires the 'viptelatac' user to log in to Cisco SD-WAN Manager and collect the health status data. For this new model to work in Cisco SD-WAN Release 20.3.1 and later releases, you must provide consent in Cisco SD-WAN Manager settings and configure a One Time Password (OTP).

    For more information about Cisco CloudOps monitoring service, see Monitor the Cisco Catalyst SD-WAN Cloud-Hosted Controllers.

  • MD5 authentication protocol is deprecated for Cisco Catalyst SD-WAN Control Components Release 20.3.2 and later releases.

  • In Cisco vManage Release 20.3.1, when you create a CLI template through REST API, add this input parameter: "cliType":"device" to the REST API. If this input parameter is not added, the CLI template fails to attach to the device.

  • If your Cisco SD-WAN Manager is running Cisco vManage Release 20.6.1 and your Cisco vEdge devices are running Cisco SD-WAN Release 20.3.x, a defect CSCwc64459 prevents Cisco vManage from pushing the device templates as expected.

Cisco SD-WAN Manager Upgrade Paths

For information about Cisco SD-WAN Manager upgrade procedure, see Upgrade Cisco SD-WAN Manager Cluster.

Starting Cisco SD-WAN Manager Version Destination Version

19.2.x

20.1.x

20.3.x

18.x/19.2.x

Direct Upgrade

Direct Upgrade

Check disk space*

  • If the disk space is more than 2GB: Direct Upgrade

  • If the disk space is less than 2GB: Step upgrade through 20.1

  • If you are upgrading to 20.3.5, the available disk space should be at least 2.5 GB.

For cluster upgrade procedure**: request nms configuration-db upgrade

Note

 

We recommend the data base size in the disk is less than or equal to 5GB. Use the request nms configuration-db diagnostic command to check the data base size. This is applicable only for upgrades of devices running Cisco SD-WAN Manager Release 20.1.1 and later.

20.1.x

Not Supported

Direct Upgrade

Direct Upgrade

For cluster upgrade procedure**: request nms configuration-db upgrade

Note

 

We recommend the data base size in the disk is less than or equal to 5GB. Use the request nms configuration-db diagnostic command to check the data base size. This is applicable only for upgrades of devices running Cisco SD-WAN Manager Release 20.1.1 and later.

20.3.x

Not Supported

Not Supported

Direct Upgrade

20.4.x

Not Supported

Not Supported

Not Supported

*To check the free disk space using CLI,

  1. Use the vshell command to switch to vshell.

  2. In vshell, use the df -kh | grep boot command.

**Cluster upgrade must be performed using CLI

  • Use the following command to upgrade the configuration database. This must be done on only one node that runs configuration-db in the cluster:
    request nms configuration-db upgrade

    Note


    We recommend the data base size in the disk is less than or equal to 5GB. Use the request nms configuration-db diagnostic command to check the data base size. This is applicable only for upgrades of devices running Cisco SD-WAN Manager Release 20.1.1 and later.


  • Enter login credentials, if prompted. Login credentials are prompted if all Cisco SD-WAN Manager server establish control connection with each other. After a successful upgrade, all configuration-db services are UP across the cluster and the application-server is started.


Note


The autoscale issue is fixed in Cisco SD-WAN Release 20.3.x. If your device is running on Cisco SD-WAN Release 18.4.x and mapped to a transit VPC, you must skip the upgrade to Cisco SD-WAN Release 19.2.x and Cisco SD-WAN Release 20.1.x, and upgrade directly to Cisco SD-WAN Release 20.3.x.


Resolved and Open Bugs

About the Cisco Bug Search Tool

Use the Cisco Bug Search Tool to access open and resolved bugs for a release.

The tool allows you to search for a specific bug ID, or for all bugs specific to a product and a release.

You can filter the search results by last modified date, bug status (open, resolved), severity, rating, and support cases.

Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.8

Open Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.8

Identifier

Headline

CSCwh68093

IPV4 Subnet Mask drop-down options are floating and Cisco SD-WAN Manager is getting frozen in Firefox browser

Bugs for Cisco SD-WAN Release 20.3.8

Open Bugs for Cisco SD-WAN Release 20.3.8

Identifier

Headline

CSCwe21563

Cisco vEdge device cannot resolve Cisco SD-WAN Validator on the loopback interface

CSCwh61634

Cisco Webex Audio Not working via TLOC-EXT

CSCwf74787

Cisco vEdge device is crashing due to FP Core dying

CSCwf49735

The tracker is not working after upgrade to 20.3.5

Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.7.2

Resolved Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.7.2

Identifier

Headline

CSCwf34096

Cisco vEdge 5000 device inbuilt certificate expiring on 12th November 2023

Bugs for Cisco SD-WAN Release 20.3.7.2

Resolved Bugs for Cisco SD-WAN Release 20.3.7.2

Identifier

Headline

CSCwf34096

Cisco vEdge 5000 device inbuilt certificate expiring on 12th November 2023

Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.7.1

Resolved Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.7.1

Identifier

Headline

CSCwf28118

vEdge: Certificate issue on Cisco vEdge devices

Bugs for Cisco SD-WAN Release 20.3.7.1

Resolved Bugs for Cisco SD-WAN Release 20.3.7.1

Identifier

Headline

CSCwf28118

vEdge: Certificate issue on Cisco vEdge devices

Bugs for Cisco SD-WAN Release 20.3.7

Open Bugs for Cisco SD-WAN Release 20.3.7

Identifier

Headline

CSCwd86884

Cisco vEdge Devices 1000 - Silent Reboot - with ZBFW configured.

CSCwc67625

The OU field is deprecated from CA/B Forum Certificate Authorities.

CSCwe51195

Cisco SD-WAN vDaemon should not remove unvalidated certificates from /usr/share/viptela/vedge_certs

CSCwe21563

Cisco vEdge devices cannot resolve vBond on the loopback interface

CSCwe51222

On root-ca bundle install control connection should flap if existing certificate is not verified

Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.7

Resolved Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.7

Identifier

Headline

CSCwb52326

Admin-tech on Cisco SD-WAN Manager cluster nodes takes one hour due to elastic search

CSCwc72071

Control connections down due to controller certificate missing on all the controllers.

CSCwd46383

Cisco SD-WAN Software Denial of Service Vulnerability

Open Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.7

Identifier

Headline

CSCwe07891

Cisco SD-WAN Manager 20.10 "vedge-ESR-6300-NCP" is an invalid value for template push.

CSCwd85846

The DTLS session with the Cisco SD-WAN Validator does not come up due to OOO packets received at the Cisco vEdge devices.

CSCwe38227

MT overlay not coming up with 20.3.7 image

Bugs for Cisco SD-WAN Release 20.3.6

Resolved Bugs for Cisco SD-WAN Release 20.3.6

Identifier

Headline

CSCvy07589

The cflowd flows are being shown in “show app logs flows”

CSCwa82541

Cisco vEdge Device: ECMP for DP based DIA is not maintained if AAR policy applied

CSCvy66289

Cisco vEdge Device not initiating arp request after upgrading

Open Bugs for Cisco SD-WAN Release 20.3.6

Identifier

Headline

CSCwc69219

Cisco vEdge Device/ACL is accepting traffic when default action is set to drop.

CSCwc64459

20.3.x Cisco vEdge Device SNMP template push failing from 20.6 vManage after 1st successful push

CSCwc54429

20.3.4.0.11 devices showing Sy CPU which is not showing in Top processes or on Cisco vManage GUI

CSCvw54152

Cisco vEdge Device 5k-LLQ policer rate on interface 10ge0/0 change after reboot on version 20.1.932

CSCwc55279

Cisco vEdge Device - ISR1100 4G-LTE - Cellular interface last-resort-circuit

CSCwc04078

Cisco vEdge Device 1K silent reboot Warm Reset(CHIP RESET)

CSCvz20061

Cisco vEdge Device: OSPF route isn't removed from routing table.

Bugs For Cisco Catalyst SD-WAN Control Components Release 20.3.6

Resolved Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.6

Identifier

Headline

CSCvz32341

Custom application list not replicated in Disaster Recovery for a Single Node Cisco SD-WAN Manager Cluster

CSCwc13452

Memory leak in Cisco SD-WAN Controller-OMP

CSCvy73412

Templatepush failed for C8300-2N2S-4T2X with error bad-cli-negotiation auto,parser-context

CSCvx61152

OMP crashing due to OOM during initial boot up or churn

CSCvz28684

Huge Data replication observed during DR process of 3 node cluster running 20.3.4

CSCvx77774

Null Pointer Exception is seen on visiting software image repo page on Cisco SD-WAN Manager

CSCvy40849

Password getting written in clear text in NSO audit log and Cisco SD-WAN Manager log

CSCvz24023

Root cert sync not working for large scale deployments

CSCvy67842

Cisco SD-WAN: Cisco SD-WAN Manager Software Information Disclosure Vulnerability

Open Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.6

Identifier

Headline

CSCwc72071

Control connections down due to controller certificate missing on all the controllers.

CSCwc82326

Admin-tech generation takes ~1 hour

CSCwc68006

Traffic engineering needs to be reconfigured every time new site is added to ondemand tunnels policy

CSCvv64821

Cisco SD-WAN Manager Site Health shows wrong number of sites

CSCwc52341

Cisco SD-WAN Manager takes 10 mins to resume template push following control connection flap

CSCwc08344

TLOC down/up events do not match in Cisco SD-WAN Manager cluster

CSCwc82000

Certificate is displayed on the Cisco SD-WAN Manager UI even though controller CLI no longer hold the certificate

CSCvz34413

Replication will start from time 0 if replication leader entry not present replicationstatus table

CSCwc83720

Configdb restore results in erroneous view on Software repository and Enable ZTP

CSCwc44186

Getting Maximum session limit reached when trying to ssh to Cisco edge devices from Cisco SD-WAN Manager

CSCwc41731

Cisco SD-WAN Manager does not display realtime information if the user is logged in through TACACS.

CSCwb76421

DPI stats processing is limited to 1 to 1.3 TB per day

Bugs for Cisco SD-WAN Release 20.3.5

This section details all fixed and open bugs for this release. These bugs are available in the Cisco Bug Search Tool

Resolved Bugs for Cisco SD-WAN Release 20.3.5

Bug ID

Description

CSCvw55486

Low-Bandwidth-Link does not work as expected on ISR-1100 -4G/6G

CSCvx79335

Cisco SD-WAN Software Information Disclosure Vulnerability

CSCvy02586

Additional counter to capture the mismatch between control and data plane hash table ZBF records.

CSCvy25448

Viptela device crashed after run admin-tech - Software initiated - Daemon 'fpmd' failed

CSCvy27321

vedge interface tracker reporting down status in vdebug constantly while on the CLI its up.

CSCvy46919

vEdge: Out of Order IKE Negotiation causes IKE to get stuck

CSCvy52061

vedges redistributing static nat routes into OMP which are not set to be advertised

CSCvy57380

Endpoint Tracker stays down when ip address changed from dhcp to static

CSCvy83632

DNS resolution fails from VPN 511 - request download vpn 511 <URL>

CSCvy87103

On 20.3.2 code, vEdge when turned on, interface stays down/ down with Cisco GLC-T SFP

CSCvz06515

vedge 1k running 20.3.3 crashes intermittenetly when configured for nat

CSCvz24768

Route-leak and ZBFW not picking correct VPN

CSCvz31126

Umbrella re-direction does not work for DNS packets arriving from LAN via an IPSEC interface

CSCvz56924

vEdge: IPSec IKE: DPD timeout causes IKE to get stuck

CSCvz60359

FP core files are not automatically decoded

CSCvz84293

BGP Route Aggregation causing delay in bringing up OMP after failover

CSCvz87934

vEdge marking the routes as invalid in OMP when the control policy is changed.

CSCvy81379

Implicit ACL ( Deny ) + Explicit ACL ( Default Allow ) --&gt; Allow

CSCvz86967

vEdge DST Root CA X3 Expiration causing umbrella integration to fail

CSCvu92178

CSV file upload does not import values for variables used in cli add on template

CSCvw32884

Response message (with IDP "success" status) does not match request via Cisco vManage SAML logout

CSCvx97579

Cisco vManage Multicoud on ramp, cant attach 8kv - GUI form cant see the UUIDs entered

CSCvy07698

20.4 Getting Wrong Control Site Down Alarm alarms

CSCvy22914

Cisco vManage GUI down 20.3.3 due to Full GC (Allocation Failure)

CSCvy56278

vMange crashed due to kernal panic [20.3.3.1.2]

CSCvy59469

OMP control connections of Cisco IOS XE SD-WAN device/vEdge devices goes down on decommissioning virtual vEdge

CSCvy88437

AWS VPN based: IPSEC tunnels from CGW C8kvs to TGW down on latest 20.6 build

CSCvy92487

Control connection to the vBond failing because of ERR_SER_NUM_NT_PRESENT on the vBond.

CSCvy97321

omp route propagation delays due to constant marker resets on TLOC flap

CSCvz02284

Cisco vManage disaster recovery not replicating the statistics database

CSCvz16093

Cisco vManage CSR generation failed

CSCvz28451

"request nms update-internal-ip new-ip" does not work on Cisco vManage 20.3.4

CSCvz43823

Cisco vManage is not able to discover VPCs for Multi-cloud when >14 AWS accounts provisioned

CSCvz69856

Cisco vManage - After upgrade to 20.4.2 or 20.6.1 feature template field is not optional anymore

CSCvz78622

Change user groups from operator to netadmin fails

CSCvz07202

Tenant creation is failing on 20.3.3 MT cluster Cisco vManage

CSCvx83494

Cisco vManage GUI Authentication with RADIUS working only if user with random password configured in CLI

CSCvy75593

continuous logs of "Could not load host key: /var/run/ssh/ssh_host_dsa_key"

CSCvy89784

BFD sessions goes down after interface flaps, and after configuring nat map-type

Open Bugs for Cisco SD-WAN Release 20.3.5

Bug ID

Description

CSCvw54152

Vedge 5k-LLQ policer rate on interface 10ge0/0 change after reboot on version 20.1.932

CSCvz37684

Not possible to ping VRRP Virtual IP

CSCvz43474

OMPD crash seen on vEdge2k doing an assert while doing best path calculation operation.

CSCvz56337

vEdge-2000 version 20.3.2 crashed due to (reason: Daemon 'bgpd' down in vpn 7)

CSCwa15656

Multiple Vedge's lost certificates and lost control connections.

CSCwa24992

ZBFW zone-pair (service to service) not working as expected.

CSCvs90123

Cisco vManage became unusable after CPU spiked to 100% - no were operations performed during hike

CSCvv64821

Cisco vManage Site Health shows wrong number of sites

CSCvx98106

Cisco vManage user sessions not getting cleaned up, approx 19700 active sessions

CSCvz28684

Huge Data replication observed during DR process of 3 node cluster running 20.3.4

CSCvz32341

custom application list not replicated in Disaster Recovery for a Single Node Cisco vManage Cluster

CSCvz34413

replication will start from time 0 if replication leader entry not present replicationstatus table

CSCvz40247

Security policies applied to incorrect interface in cluster mode, iptables

CSCvz62751

Cisco vManage: Noticed RouteMap attribute modification failure , while attempting through CLI Template

CSCvz63280

vEdge Does Not Respond Properly to vSmart Policy Prefix-list Changes (CLI Policy)

CSCvz75471

New sequence in RPL with set as-path has both prepend and exclude as required fields

CSCwa38524

Cisco vManage 20.3.5: Cisco IOS XE SD-WAN device upgrade fails with java.lang.Exception

CSCvz66256

Filtering the data based on local tloc is returning no data in Cisco vManage GUI for DPI stats

CSCwa08191

DB backup fail after upgrade 20.3 -&gt; 20.6 -&gt; 20.7

CSCvy69307

Token fails to get generated when trying to login to Cisco hosted Cisco vManage via GUI

CSCvy07589

cflowd flows are being shown in “show app logs flows”

Bugs for Cisco vManage Release 20.3.4.2

This section details all fixed and open bugs for this release. These bugs are available in the Cisco Bug Search Tool

Resolved Bugs for Cisco vManage Release 20.3.4.2

Bug ID

Description

CSCwa54712

Evaluation of Cisco SD-WAN for Log4j 2.x DoS vulnerability fixed in 2.17

Bugs for Cisco vManage Release 20.3.4.1

This section details all fixed and open bugs for this release. These bugs are available in the Cisco Bug Search Tool

Resolved Bugs for Cisco vManage Release 20.3.4.1

Bug ID

Description

CSCwa47745

Evaluation of Cisco vManage for Log4j RCE (Log4Shell) vulnerability

Bugs for Cisco SD-WAN Release 20.3.4

This section details all fixed and open bugs for this release. These bugs are available in the Cisco Bug Search Tool

Resolved Bugs for Cisco SD-WAN Release 20.3.4

Bug ID

Description

CSCvv76467

Vedge-5000:Auto IP feature not working on vedge5k

CSCvv97687

Performance degradation(6%-10%) observed on vEDGE-1k and 2k with 20.3.1 CCO on all the profiles.

CSCvw13663

Vedge_cloud_19.2.921 - FP misprogramming

CSCvw28254

High CPU because of process vconfd_script_vmanage_list_stats.sh

CSCvw42635

vedge vrrp stuck in init state with the sub-interface's second address

CSCvw47885

unexpected behavior for nat-tracker on vedge100M

CSCvw57492

vrrp virtual IP becomes unreachable to all external devices.

CSCvw58999

vEdge-100m Cellular interface losing its ip // Different ISPs

CSCvw91847

In vEdge5K the default route in RIB table is not getting programmed in FIB table properly

CSCvw94697

VEDGE-1000-AC-K9 change data prefix list name crash after 4-5 min

CSCvx00210

vEdge 5k crashed with reason "Software initiated - FP core watchdog fail"

CSCvx29790

vEdge suddenly stops to send packets via PPP interface

CSCvx56839

Vedges are crashing once the admin-tech is executed from GUI or CLI.

CSCvx57679

vedge crash after route leak config

CSCvx62654

FTMD crash being observed on a vEdge 5000 with FEC ADAPTIVE configuration enabled.

CSCvx79606

'Flow addition failures' observed with ZBFW on vEdge after heavy churn

CSCvx95288

Layer 7 tracker goes down with ZBFW inspect rule for self-zone

CSCvx96085

policyAccessListAssociationsAccessPolicyInterfaceListTable Not ordered correctly

CSCvy15360

ISR1100-6G keep crashing because FP core watchdog fail

CSCvy19715

ISR1100-4GLTE devices shows half duplex in 19.2.3 and 20.3.x releases

CSCvy28664

vedge 5k keep crashing because FP core watchdog fail and ysmgr got signal 9.

CSCvy36798

Not able to see the correct autoneg, speed and duplex settings from the Viptela CLI

CSCvy54443

Self generated return packet getting drop due to firewall

CSCvy57394

vEdge Cloud / 20.3.3 / Crash on bfdmgr_sla_class_next

CSCvy65545

vEdge: Show command to view PoE status is broken after upgrading to 20.3.3

Open Bugs for Cisco SD-WAN Release 20.3.4

Bug ID

Description

CSCvr89902

vEdge/vBond: default route is not installed in RIB even ARP is learnt and default GW is reachable

CSCvs70534

vEdge(x86) IPSec+QoS Performance Optimization

CSCvu48133

show ip route with filter isn't working with new confd version

CSCvw54152

Vedge 5k-LLQ policer rate on interface 10ge0/0 change after reboot on version 20.1.932

CSCvx50343

Routes redistributed to the OSPF/BGP that shouldn't be filtered by the routing-policy are filtered

CSCvx86427

vEdge IPSec/Ikev2 tunnel not getting re-initiated after being torn down due to a DELETE event

CSCvy03463

FTMD crash seen after customer tried to add a second tracker to an interface

CSCvy14512

Shaping-rate command on ISR1100-6G not taking an effect

CSCvy20256

Flows moving between circuits midflow

CSCvy20512

vEdge Template push failure: "Unable to send line feed after string <nc:unlock>"

CSCvy23912

vEdge VPN labels mis-allocated after upgrading from 18.x to 19.x

CSCvy25448

Viptela device crashed after run admin-tech - Software initiated - Daemon 'fpmd' failed

CSCvy27321

vedge interface tracker reporting down status in vdebug constantly while on the CLI its up.

CSCvy29984

vEdge1000 Silent Reload

CSCvy36186

Cisco vManage template does not push correct dead-peer-detection interval value to vEdge

CSCvy37241

Retrieving config from vEdge2K via Cisco vManage takes minutes to return complete configuration

CSCvy44469

DPI not working properly

CSCvy46919

vEdge: IKE IPSec sessions: discrepancy between StrongSwan and FTM Module Session Status

CSCvy48348

Cisco vManage upgrade causes certificates to become invalid on vEdge devices

CSCvy50990

In ISR1100-4G QOS traffic goes into default queue at higher speed.

CSCvy52061

vedges redistributing static nat routes into OMP which are not set to be advertised

CSCvy54245

IPsec flapping - "iptables-dropped"

CSCvy56075

FEC sending more packets than expected

CSCvy57380

Endpoint Tracker does not see the proper latency values

CSCvy60794

vEdge 1000 rebooted because of Daemon zebra

CSCvy63909

Multicast application stops working after vedge upgrade from 19.2.3 to 20.3.936

CSCvy66289

vEdge not initiating arp request after upgrading

CSCvy73400

"show ntp" command returns error "Line count error: expected 3 or more, got 1"

CSCvy77103

vEdge still advertises color if link is down but interface is up

CSCvy79566

NatPool + local-tloc doesn't ' work together in data-policy

CSCvy82151

vEdge sends getResponse including undefined values.

CSCvy83632

DNS resolution fails from VPN 511 - request download vpn 511 <URL>

CSCvy87103

On 20.3.2 code, vEdge when turned on, interface stays down/ down with Cisco GLC-T SFP

CSCvs08693

VPN label is changing upon Edge reboot

CSCvu73826

ND Failed with device template: Failed to edite device template if add-on CLI empty

Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.4

Resolved Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.4

Bug ID

Description

CSCvv52442

Cisco vSmart Upgrade From 20.1.12 to 20.3.1 Failing With Error "Failed to install: "

CSCvw14883

Incorrect mapping for device specific variables from interface shaping rate

CSCvw16238

Incorrect tag for omp routes in Real Time view

CSCvw20597

Variables missing in Cisco vManage during template push.

CSCvw28645

OIB: without change any ND global parameters, Cisco vManage automatically push template to all sites again

CSCvw37603

ND template stay in DB when no branch associated to and cause image delete failure

CSCvw53680

Limit of 30 notifications / min restriction for webhook alarm to be removed from UI

CSCvw62325

Not able to copy a feature template if the description or name contains "|"

CSCvw66441

Cisco vManage GUI not accessible due to too many open file descriptors.

CSCvw69181

OSPF alarm down seen on Cisco vManage, OSPF process is UP

CSCvw77794

"Invalid IPv4 address" is shown when inputting IPV6 DNS field

CSCvw78837

ND Template attach "Failed to create input variables for template: Failed to create input variables"

CSCvw82581

Cisco vBond upgrade from 20.3.1 to 20.3.2 fails

CSCvw83988

Cisco SD-WAN - Cisco vManage - ip helper not more than 1 is possible with Feature and Device Templates

CSCvw91545

We are not able to change Controller Certificate Authorization options in Cisco vManage GUI

CSCvw96264

UI showing console error after clicking on active/completed task as fails to show the details

CSCvw97278

20.4 policy name restrictions may break existing templates on upgrade

CSCvx00144

SSH via Cisco vManage GUI timeout in 180 seconds

CSCvx07049

Cisco vManage not displaying tunnel state correctly

CSCvx07210

Cisco vManage showing old device hostname

CSCvx22960

Not all routes getting pushed to device

CSCvx23886

CLI template does not push snmp-server community config

CSCvx27128

DPD with default values on feature template is not pushed to Cisco IOS XE SD-WAN device

CSCvx33184

Service proxy does not restart after ui certiticate upload

CSCvx35130

Cisco vBond software upgrade fails when selecting activate/reboot while upgrading

CSCvx37901

nms_bringup file has ^M in each line after service restart as part of DR

CSCvx44643

UC - unable to make modification to the translation rule once created from Cisco vManage UI

CSCvx52154

Could not load host key: /var/run/ssh/ssh_host_ed25519_key

CSCvx52352

CLI template does not push logging buffered community config

CSCvx52789

Cisco IOS XE SD-WAN device- template failure - An element value is not correct : inspect.

CSCvx55749

Cisco vManage logs are not pruned

CSCvx57151

Update button stops working after adding DHCP option

CSCvx57718

Remove "show internal omp rib vroute" cli from admin tech

CSCvx59998

Cisco IOS XE SD-WAN device Upgrade to 17.3.3 failing due to "Failed to check active partition information" error message

CSCvx64613

Issues detaching template when device is in CSR generated state

CSCvx66954

Cisco vManage manage-user function is not working properly

CSCvx68246

Changing Config-DB ID/Password from default to non-default on a cluster of more than 3 members

CSCvx72390

ZTP software version enforcement does not respect software install timeout

CSCvx81621

Cisco vManage dashboard doesn't show device status even when control is up/up

CSCvx83654

invalid value for: prefix-entry Error when push advertise OMP prefix under vpn

CSCvx85487

Configuration DB upgrade in cluster failed in 20.3.3 code

CSCvx86601

The CSR properties in Cisco vManage config DB does not match with the certificate settings on Cisco vManage UI.

CSCvx86804

c8500 / 17.3.2 / 17.4.1a / Cisco vManage is not pushing auto negotiation for 10Gig Interfaces on Cisco IOS XE SD-WAN device

CSCvx87163

X-Forwarded-For header is passed through to local auth, leading to session creation errors

CSCvx94730

20.3.3 alarms not working for BFD/Control issues

CSCvy01567

Device template policy dissapears from UI after selecting edit device template

CSCvy12257

Cisco vManage becomes unresponsive after a high amount of email notifications getting generated.

CSCvy12485

Mismatch self-signed root certs between primary and secondary clusters

CSCvy18932

Cisco vManage is not able to discover VPCs for Multi-cloud when >7 AWS accounts provisioned

CSCvy27218

Socket connect leak when dr is enabled

CSCvy42621

Unable to generate ciscotacro/rw token due to sessions being full

CSCvy42629

API sessions not getting cleared out when "Max Sessions Per User" is set

CSCvy60928

Continuous logs of "Could not load host key: /var/run/ssh/ssh_host_ed25519_key"

CSCvy65210

All stat-db settings except DPI is not available after DR registration

CSCvu78406

Cisco vSmart crash because of ompd process

CSCvw59643

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

Open Bugs for Cisco Catalyst SD-WAN Control Components Release 20.3.4

CSCvv64821

Cisco vManage Site Health shows wrong number of sites

CSCvw71474

Attempt to create cluster fails when adding 2nd member to standalone Cisco vManage

CSCvw73392

Frequent Cisco vManage UI timeout and stuck in Please continue waiting state.

CSCvx46554

Cisco vManage reverting API changes after 5 minutes

CSCvx93652

Push Cisco vEdge list fails to Cisco vSmart with application error.

CSCvy01378

Device Specific field is not usable

CSCvy07698

20.4 Getting Wrong Control Site Down Alarm alarms

CSCvy10009

IR1101 template push error: bad-cli - No interface

CSCvy14627

Activating changes in Security Policy that is attached to the Cisco vEdge will fail and lock the database

CSCvy15370

Cisco vManage API running too frequently under Rediscover Network resulting in Page Loading too often

CSCvy20641

SCP of WAN edge list to Cisco vBonds from Cisco vManage fails when TACACS is enabled on vBond.

CSCvy22394

Cisco vAnalytics slowness in response to a query

CSCvy22416

Security policies applied to incorrect interface in cluster mode, iptables

CSCvy29733

Attach to the device fails, when CLI template is created via REST API in Cisco vManage

CSCvy31058

zScalar configuration deletion happens in the wrong order.

CSCvy34596

Cisco vManage upgrade is failing from 20.3.3.1 > 20.3.4

CSCvy35209

Cisco vEdge auth-order change not processed correctly

CSCvy35564

Cisco vManage Webhooks doesn't work without Email notifications explicitly enabled

CSCvy38478

Cisco vManage ver 19.2.4 crash, becomes unstable/unusable

CSCvy39849

Cisco vManage pushes invalid service route command

CSCvy53930

Failed to create deviceactionstatusnode table entry in DB for device: Validation

CSCvy56278

Cisco vMange crashed due to kernal panic [20.3.3.1.2]

CSCvy59469

OMP control connections of Cisco IOS XE SD-WAN device/vEdge devices goes down on decommissioning virtual vEdge

CSCvy69307

Token fails to get generated when trying to login to Cisco hosted Cisco vManage via GUI

CSCvy75420

Cisco vManage reports 'upgrade request failed in device' error after installing the software via ZTP

CSCvy75632

Cisco vBond lost static route on vpn 0 and vpn 512 running 19.4.2

CSCvy79095

Configuration db VMANAGE ROOT CA node is not updated

CSCvy82358

On-prem Cisco vManage cluster went into a bad state and template push started failing

CSCvy82623

Cisco vManage giving error on login

CSCvy83020

Cisco vManage UI is taking time to load first time

CSCvy88637

Cisco vManage email notification - supporting special character & (ampersand) in the email address

CSCvy89483

Cannot apply endpoint-tracker to Cisco IOS XE SD-WAN device via Cisco vManage template in service VPN

CSCvy90229

Cisco vManage cluster management page should not show Sys IP in drop down of "Cisco vManage IP Address"

CSCvy90707

IPS signature update not consistent on routers after Cisco vManage upgrade to 20.3.3.1

CSCvy93261

Cisco vManage nodes in a cluster with Stats-db ran into full GC allocation failure

CSCvy93431

After upgraded the Cisco vManage from 20.3 to 20.6, UI is not getting loaded

CSCvs90123

Cisco vManage became unusable after CPU spiked to 100% - no were operations performed during hike

CSCvy80654

The edge router maintains persistent connections to Cisco vBond

CSCvx15658

1 vManage GUI login lead 4 PAM login failures so two GUI login failure lead to account lock

CSCvy73412

Template push failed for C8300-2N2S-4T2X with error bad-cli-negotiation auto,parser-context

Bugs for Cisco SD-WAN Controller Release 20.3.3.1

This section details all fixed and open bugs for this release. These are available in the Cisco Bug Search Tool through the Resolved Bug Search.

Resolved Bugs for Cisco SD-WAN Controller Release 20.3.3.1

Bug ID

Description

CSCvx35130

vBond software upgrade fails when selecting activate/reboot while upgrading

CSCvx59998

Cisco IOS XE Catalyst SD-WAN upgrade to 17.3.3 failing due to "Failed to check active partition information" error message

Bugs for Cisco SD-WAN Release 20.3.3

This section details all fixed and open bugs for this release. These are available in the Cisco Bug Search Tool through the Resolved Bug Search.

Resolved Bugs for Cisco SD-WAN Release 20.3.3

Bug ID

Description

CSCvu43317

Cisco vBond Orchestrator connection Down Alarms or Events not appearing in Cisco vManage

CSCvv08199

[SIT]: vsmart policy edit failed with transport closed error

CSCvv36080

Seeing more hVNETs than maximum allowed

CSCvv40715

Multilink interface can not be configured without ppp authentication

CSCvv41341

Higher memory utilization on Cisco vManage 20.1

CSCvv45021

PPP feature templates cannot modify IP MTU on Dialer interfacce

CSCvv48087

Task update issues, large customer setup with cluster

CSCvv52763

20.3 config-db upgrade script reports success even when it fails

CSCvv56750

Cisco vManage UI does not accept controller group more than 1

CSCvv71357

Cisco vManage GUI dashboard does not show number of Cisco vManage up when single node in cluster is down

CSCvv79430

Cisco SDWAN vManage 20.3.1 unable to display IP address of user access in audit log

CSCvv86465

Cisco vManage: Template Push fails with Unable to send line feed after string

CSCvv88104

Reassign "oom_score_adj" Values in "sysmgr.conf"

CSCvv88334

Email Notifications: with custom devices list a Number of 'Devices Attached' is blank when edit it

CSCvv89660

Failed to update configuration null error when pushing templates on 18.4.5

CSCvv98608

config preview failed with Exception in callback: BGP AS Number couldn't be retrieved in service VPN

CSCvw04082

Kernel Panic is seen after upgrade the Cisco vManage to 20.3 (watchdog)

CSCvw22190

Cluster activation failed because of a space in resource pool field in cluster config

CSCvw23740

In a cluster, an App server starting dependency should check a cluster, not just local service

CSCvw26979

Config-DB upgrade from 3.5.14 to 3.5.22 through Cisco vManage SW upgrade.

CSCvw28512

Difference in ip address of interface and json causing the stats db and config db in waiting

CSCvw31235

Add IPv6 OMP route support in Cisco vManage real time monitoring

CSCvw31737

Not able to successfully deploy vEdge routers with the cloudOnRamp wizard in Cisco vManage

CSCvw32352

SDWAN: clear control connection on vsmart can cause missing DNS resolved entries for IPv4 sessions

CSCvw37918

Confuguration-db upgrade allowed when not needed

CSCvw39302

'dns-server-list' error seen when pushing DNS server IP update from Cisco vManage

CSCvw41702

Cisco vManage dpi classification incorrect

CSCvw41883

Cisco vManage template doesn't allow interface as next hop for static route

CSCvw42971

Cisco vManage: Multiple DNS servers in DHCP template gives "Invalid IPv4 address"

CSCvw44368

Translation profile/rules configured as part of a Voice policy not applied to dial-peers

CSCvw46769

CLI template push to vBond fails with "Device failed to process request. null" error

CSCvw50664

Cisco vManage Optional OSPF Configuration Removed when Device Template Updated

CSCvw52973

Cisco vManage UI is not coming up thread are stuck while updating factory default templates during startup

CSCvw53502

Logfiles flooded with message of tcgetattr: Input/output error

CSCvw56320

on-prem Cisco vManage ungraded to 20.3.2 from 19.2.3 rebooting in an interval of 10-15 min

CSCvw58305

UC SDWAN: Not able to see policy profile in Custom options.

CSCvw62577

Reassign "oom_score_adj" Values for tracker

CSCvw63960

Raise different alarm when reaching watermarks of Stats-DB disk allocation: low/high/flood

CSCvw64026

Automatically changing Stats-DB to read-write mode when app server restart

CSCvw68661

Introduce basic stats collection backpressure [v1]

CSCvw68861

Change for configdb query planner to hint more effectively via $param instead of old-style {param}

CSCvw70138

Old vAnalytics setting should not be migrated into CloudServices from GUI

CSCvw73445

Add validation check for Blocklist and Redirect URL

CSCvw76649

Cisco vManage 6 Node CLuster on Azure takes 2 mins to login to Cisco vManage UI.

CSCvw79982

Cisco vManage 20.3.2.1 requires read-replicas to speed up GUI access

CSCvw92805

Local configuration not showing preview of config on Cisco vManage 20.3.2

CSCvx03509

Audit log flooded with logouts from DR cluster

CSCvx07685

consul service is not enabled in DR registartion wth arbitrator

CSCvx09069

Increase process wait timeout for configdb upgrade

CSCvx09308

Escalations: coordination service logs GB log file filling up disk

CSCvx12847

root-cert corrupted after upgrading to 20.3.2 code

CSCvx16200

Cisco vManage 19.2.x - Cannot edit AAA feature template for vEdges

CSCvv35569

AMP data is not populated in Graphs under network level

Open Bugs for Cisco SD-WAN Release 20.3.3

Bug ID

Description

CSCvv13313

Select control connection TAB for any vsmarts, it will never show vbond connections

CSCvv41954

Customer couldn't login to 19.2.3 Cisco vManage using SSO unless the browser cache is cleared

CSCvv86418

Cloud OnRamp for Colo Port level view mapped ports on CSP to the wrong switch

CSCvw15630

Inconsistency between "show app flowd flows" and API response of DPI stats

CSCvw16238

Incorrect tag for omp routes in Real Time view

CSCvw38077

UI throwing "Failed to list cluster information:Unknown error" on cluster management page

CSCvw45135

Mismatch in System CPU statistic -- "Real Time" and historical 1/3/6/12h

CSCvw50483

Dashboard getting blank intermittently in singlenode 20.3.2.1-no response of agg APIs from stats-db

CSCvw55764

VNF Install fail - VNF packages are not sync'd/copied in new added Cisco vManage node in Cisco vManage cluster

CSCvw62341

Cisco vManage Dashboard - Alarm time zone is tagging with incorrect time zone

CSCvw66441

Cisco vManage GUI not accessible due to too many open file descriptors.

CSCvw69181

OSPF alarm down seen on vamange, OSPF process is UP

CSCvw71474

Attempt to create cluster fails when adding 2nd member to standalone Cisco vManage

CSCvw73392

Frequent Cisco vManage UI timeout and stuck in Please continue waiting state.

CSCvw77794

"Invalid IPv4 address" is shown when inputting IPV6 DNS field

CSCvw83988

Cisco SD-WAN - Cisco vManage - ip helper not more than 1 is possible with Feature and Device Templates

CSCvw85706

Cisco vManage: UI is incorrectly showing the current version for Cisco vManage and vSmarts.

CSCvw91545

We are not able to change Controller Certificate Authorization options in Cisco vManage GUI

CSCvw91647

Issues with template created by API call

CSCvw91984

ACI APIC to Cisco vManage integration issue

CSCvw92189

Cisco vManage goes into out of memory resulting in slowness while pushing the template and accessing GUI.

CSCvw93203

serverproxy-access.log not rotating in /var/log/nms

CSCvw96264

UI showing console error after clicking on active/completed task as fails to show the details

CSCvw99518

SSO SAMLResponse Error validating SAML message at re-authentication

CSCvx00144

SSH via Cisco vManage GUI timeout in 180 seconds

CSCvx02002

Cisco vManage did not validate if the template value of an interface name was correct.

CSCvx03552

Configurations allows for multiple primary DNS servers

CSCvx05353

"request nms all status" command returning Python exception if containter-mgr svc was stopped

CSCvx08817

DHCP excluded-address command is not being pushed via Cisco vManage template

CSCvx08942

Server slowness during GUI operations, system degrades until login is not possible

CSCvx09284

Escalations: messaging service timeout

CSCvx14444

netconf connection failures while installing certificate

CSCvx14750

Cisco vManage removes \ character when imported to cli template from running configuration

CSCvx16509

audit-log: invalid session with a user due to inactivity even though app-server not shutdown

CSCvx19853

Cisco vManage CLI template push failing due to controller transaction ID error

CSCvx19889

Creation of Cisco vManage DR Cluster Failed, GUI showing duplicate entry for DR Cisco vManage

CSCvx19948

Shaper Rate and QoS Map device specific variable get reset when changed to "Per-tunnel-QoS" hub

CSCvx23886

CLI template does not push snmp-server community config

CSCvx25217

cannot remove NAT configuration from the template in a single operation if NAT translation is active

CSCvx25441

Cisco vManage cluster does not show Graphs for less than 7 Days

CSCvx26988

Cisco vManage App Route Visualization - Citrix Flows are missed in GUI

CSCvx29421

"Server Error, Details: Unable to get pcap session" is printed in the Cisco vManage GUI

CSCvx29967

Fail to upload images to software repository post Cisco vManage upgrade to 19.2.4

CSCvx34074

/dataservice/device/omp/routes/advertised?deviceId reply is empty

CSCvx34991

Cisco vManage - TACACS requests are sourced from old interface IP after IP changed

CSCvx36896

Cisco vManage is unable to push both interface and ip as a next-hop

CSCvx37025

Cisco vManage: Control connection up with Edge devices however, do not show up on Dashboard

CSCvx37092

Cisco vManage DB can not boot up due to neo4j complains about older version

CSCvw37856

Cisco vManage utd/virtual image state stuck in DEPLOYED state after cEdge device app-host list is RUNNING

CSCvx35378

Template Push to device is Failed in Cisco vManage UI.

CSCvx44527

Sharepoint flows not forwarded properly

CSCvx26148

Downloading the events CSV file results only 2 days of data irrespective of set time range.

CSCvx59840

Cisco vManage does not wait and confirm new partition when activating controllers

CSCvx37901

nms_bringup file has ^M in each line after service restart as part of DR

Bugs for Cisco SD-WAN Controller Release 20.3.2.1

This section details all fixed and open bugs for this release. These are available in the Cisco Bug Search Tool through the Resolved Bug Search.

Resolved Bugs for Cisco SD-WAN Controller Release 20.3.2.1

Bug ID

Description

CSCvv88104

Reassign "oom_score_adj" Values in "sysmgr.conf"

CSCvw04082

Kernel Panic is seen after upgrade the vmanage to 20.3

CSCvw26979

Config-DB upgrade from 3.5.14 to 3.5.22 through vManage SW upgrade.

CSCvw63960

Raise different alarm when reaching watermarks of Stats-DB disk allocation: low/high/flood

CSCvw65073

Cloudservices Radio button needs enable disable seperate check box for vAnalytics and Monitoring

CSCvw68661

Introduce basic stats collection backpressure [v1]

CSCvw68861

Change for configdb query planner to hint more effectively via $param instead of old-style {param}

Open Bugs for Cisco SD-WAN Controller Release 20.3.2.1

Bug ID

Description

CSCvw68410

Messaging server and App-server is not getting started upon VM shutdown/start

CSCvw72087

Full GC (Allocation Failure) on Standalone Cisco SD-WAN Manager running 264 devices

CSCvw72269

Cisco SD-WAN Manager GUI is not accessible: upstream connect error

CSCvw62577

Reassign "oom_score_adj" Values for tracker

Bugs for Cisco SD-WAN Release 20.3.2

This section details all fixed and open bugs for this release. These are available in the Cisco Bug Search Tool through the Resolved Bug Search.

Resolved Bugs for Cisco SD-WAN Release 20.3.2

Bug ID

Description

CSCvs31361

Template push fails with Failed to update configuration - com.tailf.maapi.MaapiException

CSCvt96030

Cisco Banner Feature Template config Absent in Config preview

CSCvu08599

vManage Feature hostname / location template should support special characters

CSCvu15259

Vedge receives a packet to remove SPIs for duplicate IKEv2 SAs but it removes all the SPIs instead.

CSCvu36324

vEdge 100m lose IP for a Cellular interface

CSCvu37189

IPsec tunnel configured on cEdge drops LAN traffic when Loopback interface is used as tunnel source.

CSCvu40495

"show ipv6 interface" command returns incomplete IPV6 ADDRESS field

CSCvu41308

Console Logging on Global Settings Template does not get applied on cEdge

CSCvu69446

20.3 : Modifying Active policies by deleting existing sequence number fails

CSCvu71411

IKE IPSec: Generate an error message, if strongSwan can't execute rekey CLI

CSCvu87957

19.2.2 template push failing for 16.10.2 cedge devices

CSCvu88512

QOS-vEdge2K : not getting desired throughput when sending traffic more than shaping-rate

CSCvu93393

Multitenant vManage may send CSR to wrong VA

CSCvv00132

vEdge crashed with error "Software initiated - Daemon 'ompd' failed. Core files found"

CSCvv04607

In vManage 20.1.1 UI bootstrap 3.2.0 is vulnerable to multiple medium CVE

CSCvv20260

LLQ policer disappears when changed policy configuration

CSCvv20941

VNF Stats and SCHM reports shows empty after vManage upgrade from 20.1 to 20.3 R 908

CSCvv22466

vEdge cannot resolve vBond. No packets going out of loopback interface.

CSCvv28709

Vmanage UI: Enforce ZTP Version Add Software Version should show when no versions are aviable

CSCvv39370

BGP Type 8 hash changes even if "Avoid recompute of type 8 encrypted passwords" is enabled

CSCvv40390

vEdge 1000 crashed in version 20.3.1

CSCvv42322

Vmanage's change in AAA Feature is generating an error "Server error: Unknown error"

CSCvv42937

No date and time info in the syslog payload

CSCvv47101

The request nms configuration-db configure command needs protection and documentation

CSCvv48564

20.3.1 messaging server reports not-running status after stop-all action, but is still running

CSCvv48890

vAnalytics - Launch vanalytics not working in vmanage UI

CSCvv50032

SSO auth errors, exception: Error determining metadata contracts

CSCvv53922

vManage 20.3.1 - Filter section never minimizes on the page Monitor > Geography

CSCvv54047

Unable to update feature template

CSCvv54671

vSmart OMPD crash on policy application

CSCvv63528

20.3 code vmanage is not accepting serial file from PnP portal or sync from smart account fails

CSCvv69070

vManage: PnP software version verification failure

CSCvv75771

XE SDWAN router crash due to system memory exhaustion caused by FTM memory growth

CSCvv75947

IP subnet as device specific variable not working for IPSec tunnel

CSCvv86113

cEdge: [no] allow-service https doesn't take effect on vManage template to the device

CSCvv09746

Cisco SD-WAN vManage Software XML External Entity Vulnerability

CSCvv21757

Cisco SD-WAN vManage Software Privilege Escalation Vulnerability

CSCvv21754

Cisco SD-WAN vManage Software Directory Traversal Vulnerability

CSCvv42376

Cisco SD-WAN Software Privilege Escalation Vulnerability

CSCvv42398

Cisco SD-WAN Software Privilege Escalation Vulnerability

CSCvv42551

Cisco SD-WAN Software Privilege Escalation Vulnerability

CSCvv42620

Cisco SD-WAN vManage Cross-Site Scripting Vulnerability

CSCvv42616

Cisco SD-WAN vManage Software Cross-Site Scripting Vulnerability

CSCvv02305

Cisco SD-WAN vManage Software XML External Entity Vulnerability

CSCvv42602

Cisco SD-WAN vManage Software Authorization Bypass Vulnerability

CSCvv03658

Cisco SD-WAN vManage Software Path Traversal Vulnerability

CSCvv21747

Cisco SD-WAN vManage Software Command Injection Vulnerability

CSCvv21749

Cisco SD-WAN vManage Software Arbitrary File Creation Vulnerability

CSCvw08529

Cisco SD-WAN vManage Cypher Query Language Injection Vulnerability

Open Bugs for Cisco SD-WAN Release 20.3.2

Bug ID

Description

CSCvo21728

vEdge forming duplicate control-connections after increasing number of cores on vSmart

CSCvq30332

fp-core watchdog failure on vEdge 5k running 18.4.1 (fp-um)

CSCvr94659

vEdge cloud - Token getting lost after rebooting vEdge Cloud for two times.

CSCvt78292

Template attaching failure, system-ip referanses to old chassis-number

CSCvu78635

Multicast autorp issue with vEdge/cEdge mixed deployment

CSCvu85034

vManage GUI shows "-" in RX Drop column, under Monitor > Network > Real Time > Interface Statistics

CSCvu94036

vManage: Client timed out waiting for request taking longer than 60s after save ND template

CSCvv04056

When generating new certificate for SSO login to vManage started to fail

CSCvv11604

ISR 4000 Cedge : Only one T1 card is getting enabled via CLI template while two are inserted

CSCvv25745

Nutella - vManage not showing the correct hostname for Nutella device

CSCvv29416

CLI template push for banner login <> configuration fails on cedge

CSCvv31065

Unable to edit vbond config via CLI , when control connection breaks from vmanage.

CSCvv36080

Seeing more hVNETs than maximum allowed

CSCvv40715

Multilink interface can not be configured without ppp authentication

CSCvv44894

Web traffic is not properly recognized by DPI

CSCvv48087

Task update issues, large customer setup with cluster

CSCvv51651

[vedge][iperf] vedge iperf doesnt work in vpn 0 on 18.4.4 as well as 19.2

CSCvv52763

20.3 config-db upgrade script reports success even when it fails

CSCvv53493

vmanage is not generating the TLS Proxy Certificate after Device comes online

CSCvv57951

cEdge: Option field in EIGRP template interface section is not working

CSCvv61427

Template attach validation error misreported

CSCvv62817

Able to ssh into a vEdge even after ciscotac{ro|rw} account is disabled.

CSCvv64821

vManage Site Health shows wrong number of sites

CSCvv71357

vManage GUI dashboard does not show number of vManage up when single node in cluster is down

CSCvv78340

17.2/20.1 MR bfd session down after enable pairwise-keying

CSCvv78705

ADFS SP initiated SSO is in continuous login loop - vManage

CSCvv79430

Cisco SDWAN vManage 20.3.1 unable to display IP address of user access in audit log

CSCvv82149

ISR1100-6G vEdge reboot after Centralized policy push

CSCvv84742

Workaround is needed for Operator user to be able to view device configurations post VManage 19.2.3

CSCvv86418

Cloud OnRamp for Colo Port level view mapped ports on CSP to the wrong switch

CSCvv86471

Performance degradation observed on Nutella with 20.3.1 CCO with all the profiles

CSCvv88334

Email Notifications: with custom devices list a Number of 'Devices Attached' is blank when edit it

CSCvv95003

Smart Sync Account sends CEC password in clear text which is a security hole.

CSCvv95571

vmanage control does not fail over if there are too many vbond addresses

CSCvv97687

Performance degradation observed on vEDGE-1k and 2k with 20.3.1 CCO

CSCvw00577

Control connections are stuck in challenge state

CSCvw00685

Data prefix list in centralise policy takes long time to process in backend to view/edit operations

CSCvw01769

Not able to configure ADSL interface.

CSCvw02925

After vManage config-db restore, the webhook checkbox is no longer selected

CSCvw03203

OMP stuck in init/down even though control is up

CSCvw03769

vEdge 1000: BGP may advertise a default route that doesn't exist in RIB or OMP

CSCvw04245

OMP routes learnt via MPLS color is showing as connected route for Biz-internet color in vManage UI

CSCvw07842

vManage Error : Failed to configure. Database [vmanagedb] instance is interrupted

CSCvw08459

API /dataservice/device/dhcp/client?deviceId= reports incorrect string

CSCvw10824

Buffer pool leak seen on ISR1100-6G

CSCvw13663

Vedge_cloud_19.2.921 - FP misprogramming

CSCvw14305

Packet forwarding incorrectly over BGP

CSCvw14318

admin tech on vEdge takes more than 2 hours to generate

CSCvw14973

Upgrade from 18.4.5 to 19.2.31 failed

CSCvw16238

Incorrect tag for omp routes in Real Time view

CSCvw16643

Device Template failing to attach after changing few device variables

CSCvw16700

OMP advertised routes is returning both advertised and what it learned from OMP in 19.2.3

CSCvw16970

vEdge running 19.2.2 has buffer pool getting depleted, core utilization going to 99.9%

CSCvw17601

Home user files changing ownership after reload

CSCvw17655

vEdge DPI for MS Teams does not work well

CSCvw17849

bfd session between vedge not come up via nat router

CSCvw18153

Template to Inject Default Route to OMP when Local DIA Used is not working

CSCvw18428

GRE interface went down after swapping configuration in 2 interfaces

CSCvw37217

Cisco SD-WAN Manager: Template push to Cisco ISR 4000 may fail after upgrading the code of Cisco SD-WAN Manager from 20.3.1 to 20.3.2

CSCvv54844

ConfigDB not updating username/password

Bugs for Cisco SD-WAN Release 20.3.1

This section details all fixed and open bugs for this release. These are available in the Cisco Bug Search Tool through the Resolved Bug Search.

Resolved Bugs for Cisco SD-WAN Release 20.3.1

Bug ID

Description

CSCvi69788

Cisco SD-WAN Manager ElasticSearch is exposed to changes from any user using the Vshell (Posix), and has no authe

CSCvr29345

"show ospf database" does not show Type 5 external LSAs

CSCvs05128

Cisco SD-WAN passwords with an exclamation character does not work on vEdges and controllers

CSCvs07518

Cisco SD-WAN Manager stores stale session and renders to j_security_check or last cached url

CSCvs39545

Cisco SD-WAN Manager: for ipsec IKE Diffie-Hellman Group 2 should be removed

CSCvs70746

[Azure] Cisco SD-WAN Manager rebooted on 19.3 with Software initiated - Kernel Panic

CSCvs72371

Cisco SD-WAN Manager showing alarm " vEdge serial file uploaded"

CSCvt00153

Cisco SD-WAN Manager Security Policy ZBF can't use Protocol Names

CSCvt00459

Template page returning Server error: Unknown error

CSCvt04564

Template locked in edit mode permanently

CSCvt21380

Cisco SD-WAN Manager fail to create bootstrap config

CSCvt29432

Support for moving packet from service VPN to VPN 0 without changing source ip

CSCvt30224

Slash symbol cannot be used in a variable value of any device specific parameter scope in templates

CSCvt38373

Cisco SD-WAN Manager periodic cfgmgr crash

CSCvt50756

Doing "simulate flows" from Cisco SD-WAN Manager running 20.1 causes FTMD crash on ASR1002-HX running 16.12.01e

CSCvt52882

Cisco SD-WAN Manager API does not accept URL encoded string as path argument (the real problem is device has / )

CSCvt55924

SSH version 2 not available via Cisco SD-WAN Manager Template

CSCvu05280

[Enhancement] "ip http client source-interface" cannot be configured via template

CSCvu05829

route leaking between VPN with natpool in one VPN is not working.

CSCvu14289

Missing callin option in "ppp authentication pap ..." after upgrading to 20.1.1

CSCvu18699

EIGRP - Removing authentication template does not remove it entirely

CSCvu30288

Cisco SD-WAN Manager does not generate and push BGP "neighbor update-source" command in cedge cli template

CSCvu31228

cfgmgr changes needed from platform to support IPv6 on VPN 512

CSCvu41144

20.1 cEdge TACACS/RADIUS password are in clear text on Cisco AAA feature template

CSCvu46222

Cisco SD-WAN Managerdoes not generate and push DHCP "ip dhcp excluded-address" command in cedge cli template

CSCvu48660

Optional field is not considered as optional.

CSCvu49030

"Chassis Number not found" fails to indicate the problematic entry - Need more details in logging

CSCvu70566

20.3:Template Migration failing if device template is created for CLI Template in 19.2.x

CSCvu71611

Disable support for weak encryption ciphers on Cisco SD-WAN Manager and vSmart.

CSCvu93775

Cisco SD-WAN Manager image validation may fail for ZTP upgrade process on cEdge

CSCvu94816

WWAN : update cellular ZTP Polish carrier list

CSCvv25817

Cisco SD-WAN Manager API call showed error message "Exceeded possible number of hits to the API".

CSCvv09807

Cisco SD-WAN Software Arbitrary File Creation Vulnerability

CSCvu71921

Cisco SD-WAN Software Privilege Escalation Vulnerability

CSCvv42576

Cisco SD-WAN vManage Cypher Query Language Injection Vulnerability

CSCvi59632

Cisco SD-WAN vManage Software Path Traversal Vulnerability

CSCvi59726

Cisco SD-WAN vManage SQL Injection Vulnerabilities

CSCvi69962

Cisco SD-WAN Information Disclosure Vulnerability

CSCvk28549

Cisco SD-WAN vManage Software Path Traversal Vulnerability

CSCvk28609

Cisco SD-WAN vManage SQL Injection Vulnerabilities

CSCvk28656

Cisco SD-WAN vManage SQL Injection Vulnerabilities

CSCvk28667

Cisco SD-WAN vManage SQL Injection Vulnerabilities

CSCvs11276

Cisco SD-WAN vManage Information Disclosure Vulnerability

CSCvs99259

Cisco SD-WAN vManage SQL Injection Vulnerabilities

Open Bugs for Cisco SD-WAN Release 20.3.1

Bug ID

Description

CSCvq77957

MTCVM: AAA login to Multi-tenant Cisco SD-WAN Manager GUI is not working via TACACS

CSCvu19795

Confg-db error during the application-server startup

CSCvu48133

show ip route vpn <id> <ip address> isn't working with new confd version

CSCvu53588

DC1 Cisco SD-WAN Manager template attachment disappear after a switchover

CSCvu69446

20.3 : Modifying Active policies by deleting existing sequence number fails

CSCvu71432

Config O356 Endpoints with prefixes less specific than 24 with Custom App from web servcies API

CSCvu77817

OMPD crash with control-policy export vpn

CSCvu78635

Multicast stops working on vEdge

CSCvu87957

19.2.2 template push failing for 16.10.2 cedge devices

CSCvu88261

vEdge HUB is missing config after Cisco SD-WAN Manager successfully attached template to vedge and is in sync

CSCvu92172

Cisco SD-WAN Manager HELP redirects to cisco Intranet pages ( Unreachable )

CSCvu93393

Multitenant Cisco SD-WAN Manager may send CSR to wrong VA

CSCvu95532

Cisco SD-WAN Manager: Cisco SD-WAN Manager dashboard is reporting error while cluster management is all fine

CSCvu99861

Vedge end of line for the banner in 20.1 is not working as it did in 19.2

CSCvv00132

vEdge crashed with error "Software initiated - Daemon 'ompd' failed. Core files found"

CSCvv00251

OMP Crash || Software initiated - Daemon 'ompd' failed

CSCvv03068

vEdge control connections goes down after CSR generation

CSCvv04056

When generating new certificate for SSO login to Cisco SD-WAN Manager started to fail

CSCvv05641

20.3.907-16 : vBond upgrade fails after image download with control not established

CSCvv06133

port 830 open for Service/Management VPN.

CSCvv06517

Cisco SD-WAN Manager running 19.2.2 may stop responding to API calls for approutestatsstatistics

CSCvv10287

CoR probes working for O365 but failing for every other SaaS application

CSCvv11071

Cisco SD-WAN Manager is attempting to strip multiple LTE modem configs from ISR1000 and template push fails

CSCvv12705

vEdge Cloud | System Initialization Stuck on KVM Platform running Ubuntu 14

CSCvv18311

fpmd crashes on vEdge1k, 2k with 19.2.1, 18.4.302

CSCvv19652

vEdge crashes with dbgd failed message when running speed test

CSCvv21710

Cisco SD-WAN Cisco SD-WAN Manager Full GC (Allocation Failure)

CSCvv22385

Cisco SD-WAN Manager GUI down due to GC Allocation Failure on 19.2.3

CSCvv22466

vE5k after upgrade to 19.2.3 isn't form control connections; doesn't able to resolve vBond URL

CSCvv25745

Nutella - Cisco SD-WAN Manager not showing the correct hostname for Nutella device

CSCvv26925

ip community-list expanded test permit 64700:[0-9]+ not able to configure on vMnanage template.

CSCvv27194

vSmart crashes during vExpress run

CSCvv28149

Email List does not accept co.in email addresses

CSCvv29989

Control connection of vEdge Cloud going down after DR.

CSCvv31065

Unable to edit vbond config via CLI , when control connection breaks from Cisco SD-WAN Manager.

CSCvv31391

Cisco SD-WAN Manager: Configuration database restore in cluster fails due to password mismatch.

CSCvv34148

Need to Remove the unsupported device - C1117-4PLTEEAWA* from Cisco SD-WAN Manager 17.3/20.3 throttle

CSCvv40966

Remove all unsupported devices from 20.3 throttle

CSCvv48890

vAnalytics - Launch vAnalytics not working in Cisco SD-WAN Manager UI

CSCvv42937

No date and time info in the syslog payload

CSCvv49157

This serial number in upload file is already associated with another vEdge Error in Cisco SD-WAN Manager 20.3.1

CSCvw35025

vEdge system buffer pool depletion and data plane stops forwarding with device-access-policy config

CSCvx68246

Changing Config-DB ID/Password from default to non-default on a cluster of more than 3 members

Interactive Help in Cisco SD-WAN Manager

To access the list of guided workflows for this release, from Cisco SD-WAN Manager, click Interactive Help.

The Interactive Help interface allows you to search for a specific workflow and filter the search results by workflow names.

Figure 1. Interactive Help in Cisco SD-WAN Manager

This release provides guided workflows for the following procedures:

Table 2. List of Workflows Using Cisco SD-WAN Manager 20.3.1

Workflow

Description

Configure Controllers and Devices

Configure Cisco Catalyst SD-WAN Validator

Configure the Cisco Catalyst SD-WAN Validator and add it to the overlay network.

Configure Cisco Catalyst SD-WAN Controller

Configure a Cisco Catalyst SD-WAN Controller to control data traffic flow throughout the network.

Configure Cisco SD-WAN Manager Instance

Configure a Cisco SD-WAN Manager instance by creating a device configuration template and adding it to the overlay network.

Configure Cisco Catalyst SD-WAN Devices

Configure Cisco IOS XE Catalyst SD-WAN devices and Cisco vEdge devices by creating configuration templates.

Manage Devices in Overlay Network

Add Devices to the Overlay Network

Add Cisco Catalyst SD-WAN devices either by using authorized serial numbers or from Cisco Smart account.

Decommission Virtual Devices

Decommission a Cisco IOS XE Catalyst SD-WAN device or Cisco vEdge device to remove the device serial number.

Remove Devices from the Overlay Network

Remove Cisco Catalyst SD-WAN devices to clear an old device configuration from the Cisco SD-WAN Manager server.

Change Device Values

Change Cisco Catalyst SD-WAN device configuration by populating the variable values for the device.

Troubleshoot Device Issues

Determine and fix common Cisco Catalyst SD-WAN device connectivity issues.

Upgrade Devices and Controllers

Install and activate an upgraded software for Cisco Catalyst SD-WAN control components and Cisco Catalyst SD-WAN devices.

You cannot use this workflow for:

  • Cisco SD-WAN controll components releases earlier than 20.3.1

  • Cisco SD-WAN device releases earlier than 17.3.1a or 20.3.1

Whom to contact for feedback?

We value your opinion and please send us your feedback at, mailto:sdwan-workflow-fb@cisco.com

Full Cisco Trademarks with Software License

THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS.

THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY.

The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California.

NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE.

IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.

All printed copies and duplicate soft copies of this document are considered uncontrolled. See the current online version for the latest version.

Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at www.cisco.com/go/offices.

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)