Release Notes for Cisco CMX Release 10.6.x
Installation and Upgrade Information
Limitations, Restrictions, and Important Notes
Resolved Caveats in Cisco CMX Release 10.6.2-89
Resolved Caveats in Cisco CMX Release 10.6.2-72
Resolved Caveats in Cisco CMX Release 10.6.2
Resolved Caveats in Cisco CMX Release 10.6.1
Resolved Caveats in Cisco CMX Release 10.6.0
Communications, Services, and Additional Information
First Published: January 30, 2019
Last Modified: May 23, 2024
Cisco Connected Mobile Experiences (Cisco CMX) Release 10.6.0 and later is a high-performing scalable software solution that addresses the mobility services requirements of high-density Wi-Fi deployments. Unless otherwise noted, Cisco Connected Mobile Experiences is referred to as Cisco CMX in this document.
This release is suitable for on-premise deployments where the following features are required:
This release is not suitable for deployments where the following are required:
What’s New in Cisco CMX Release 10.6.2-89
This is a mandatory security patch which addresses CVE-2021-45105, CVE-2021-44228 and CVE-2021-45046 vulnerability issues in Apache log4j. This patch works for Cisco CMX Release 10.6.2-89.
You must download Cisco CMX Release 10.6.2-89 patch cmx-log4j-vulnerability-patch-10.6.2-2.cmxp available at Software Download page and copy the patch file to /home/cmxadmin directory.
Note If the cmx-log4j-vulnerability-patch-10.6.2-1.cmxp patch file is previously installed, ensure that you run the cmxos patch remove command to remove the patch before installing the new patch.
To apply this patch on Cisco CMX High Availability, you must break High Availability and rebuild it.
To install Cisco CMX Release 10.6.2-89 patch:
Step 1 Log in to Cisco Connected Mobile Experiences (Cisco CMX) through SSH.
Step 2 Enter the cmxos patch list command to check if a patch file is installed.
Step 3 Enter the cmxos patch remove command to remove any installed patch.
Run the command and provide the patch name that needs to be removed.
Step 4 Enter the cmxctl restart command to restart Cisco CMX services.
Step 5 Download Cisco CMX Release 10.6.2-89 patch cmx-log4j-vulnerability-patch-10.6.2-2.cmxp available at Software Download page.
Step 6 Copy the patch file to /home/cmxadmin directory.
Step 7 Enter the cmxos patch install command to install the patch.
Run the command and provide the patch name as cmx-log4j-vulnerability-patch-10.6.2-2.cmxp.
Note This patch restarts all Cisco CMX services and might take few minutes to complete. We recommend that you wait until the installation process is complete.
Cisco DNA Spaces is a cloud-based location platform that provides a single pane for all location services. From Cisco CMX, you can configure location updates on the services enabled on Cisco DNA Spaces. For information about Cisco DNA Spaces, see https://dnaspaces.cisco.com/. |
|
When Cisco CMX and Cisco DNA Spaces have an established connection, Cisco CMX provides traffic-related notifications, such as the destination of the traffic and the amount of traffic sent to Cisco DNA Spaces. |
|
On Cisco CMX, Linux commands are restricted to prevent unauthorized users from inadvertently modifying the system configuration. For more information, see the “Restricted CLI” section in the Chapter “Getting Started” of the Cisco CMX Configuration Guide for this release at: https://www.cisco.com/c/en/us/support/wireless/connected-mobile-experiences/products-installation-and-configuration-guides-list.html. |
|
Cisco CMX implements software changes that are required for FIPS 140-2 security standard compliance. This standard is used to validate cryptographic modules. This feature is disabled by default, but FIPS mode can be configured on Cisco CMX. |
|
Cisco CMX implements software changes required for the CC certification process. This is a testing standard to verify that a product provides security functions. CC is enabled when FIPS mode is enabled on Cisco CMX. This feature is disabled by default. |
|
U.S. Department of Defense (DoD) Unified Capabilities Approved Product List (UCAPL) compliance |
Cisco CMX implements the software changes required for the U.S. DoD UCAPL compliance. The compliance certification is in progress. This feature is disabled by default, but UCAPL can be configured on Cisco CMX. |
Note Cisco CMX does not support VMware tools.
Table 6 lists the Cisco CMX Release 10.6.x hardware guidelines for a virtual Cisco MSE appliance on VMware. For complete requirements, see the Cisco Connected Mobile Experiences Data Sheet at: https://www.cisco.com/c/en/us/products/wireless/mobility-services-engine/datasheet-listing.html.
1.For Cisco CMX OVA installation, 160 GB is the default hard disk drive (HDD) on standard and high-end virtual machines. We strongly recommend that immediately after deploying the OVA file and before powering on the VM, you increase the disk space to the recommended amount specified in this table, so that the HDD resource does not run low while using Cisco CMX. If you do not know how to increase the disk space before powering on the VM, see the VMWare 6.7 guidelines on how to increase disk space at: https://docs.vmware.com/en/VMware-vSphere/6.7/com.vmware.vsphere.vm_admin.doc/GUID-79116E5D-22B3-4E84-86DF-49A8D16E7AF2.html |
Before you deploy Cisco CMX, we strongly recommend that you see the following documents:
Note that the calculator applies to Cisco CMX Release 10.3 or later, even though the calculator refers only to Cisco CMX Release 10.3.
– Cisco Connected Mobile Experiences Data Sheet at: https://www.cisco.com/c/en/us/solutions/enterprise-networks/connected-mobile-experiences/white-paper-listing.html.
– Cisco Connected Mobile Experiences (CMX) 10 Ordering and Licensing Guide at: https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/connected-mobile-experiences/guide-c07-734430.html.
Note If you are using Google Chrome Version 72 or later, we recommend that you use Mozilla Firefox as your browser, or downgrade to Google Chrome Version 63.
For more information about Cisco CMX feature parity with Cisco Prime Infrastructure and Cisco MSE appliance, see the “Cisco CMX Feature Parity” section in the Chapter “Getting Started” in the Cisco CMX Configuration Guide for this release at: https://www.cisco.com/c/en/us/support/wireless/connected-mobile-experiences/products-installation-and-configuration-guides-list.html.
– If you do not have a valid SSL certificate to install, you need a self-signed certificate.
– If neither a valid SSL certificate nor a self-signed certificate is available, Cisco CMX Analytics might not work as expected.
For information on installing a certificate, see the “Importing Certificates” section in the Cisco CMX Configuration Guide for this release at: https://www.cisco.com/c/en/us/support/wireless/connected-mobile-experiences/products-installation-and-configuration-guides-list.html.
Two weeks before the evaluation license expires, you will receive a daily alert for obtaining a permanent license. If the evaluation license expires, you will not be able to access the Cisco CMX GUI or APIs. Cisco CMX will continue to run in the background and collect data until you add a permanent license and regain access to it.
For information about procuring Cisco CMX licenses, see the Cisco Connected Mobile Experiences (CMX) Version 10 Ordering and Licensing Guide for this release at: https://www.cisco.com/c/en/us/solutions/collateral/enterprise-networks/connected-mobile-experiences/guide-c07-734430.html.
For information about adding and deleting licenses, see the “Managing Licenses” section in the Cisco CMX Configuration Guide for this release at: https://www.cisco.com/c/en/us/support/wireless/connected-mobile-experiences/products-installation-and-configuration-guides-list.html.
For complete information about the relevant procedures, see the Cisco Mobility Services Engine Virtual Appliance Installation Guide for this release at: https://www.cisco.com/c/en/us/support/wireless/connected-mobile-experiences/products-installation-guides-list.html.
For information about upgrading from an earlier Cisco CMX release to this release, see the Chapter “Upgrading” in the Cisco Mobility Services Engine Virtual Appliance Installation Guide for Cisco CMX for this release at: https://www.cisco.com/c/en/us/support/wireless/connected-mobile-experiences/products-installation-guides-list.html.
For information about upgrading from Cisco MSE appliance Release 8.x to Cisco CMX Release 10.x, see the applicable Release Notes for Cisco Mobility Services Engine, Release 8.0.x at: https://www.cisco.com/c/en/us/support/wireless/mobility-services-engine/products-release-notes-list.html.
To restart Cisco CMX services, follow these steps:
1. Enter the cmxctl stop -a command.
2. Enter the cmxctl start -a command.
Note Contact Cisco Customer Support (https://www.cisco.com/c/en/us/support/index.html) for the patch file.
Note If a Cisco CMX CLI or GUI user account is inactive for 60 days or more, the account is locked. A Cisco CMX admin user (cmxadmin) can unlock the account and use the applicable command:
If the Cisco CMX admin user account is locked out, the admin user must connect directly to the console and use the applicable command: cmxctl users unlock gui < userID > or cmxctl users unlock cli < userID >.
In contrast, Cisco CMX Release 10.6.2 and later with FIPS mode enabled cannot establish an NMSP connection with Cisco WLCs running Release 8.x.
Note Before enabling FIPS mode on Cisco CMX, remove all the non-FIPS compliant controllers from Cisco CMX. Otherwise, establishing NMSP connectivity after restarting Cisco CMX services will require an extensive amount of time.
ERROR com.cisco.mse.matlabengine.heatmap.BaseMatlabHeatmapBuilder - MatlabHeatmapBuilder#createApInterfaceHeatmap Number of heavy walls used by Matlab: <nn> not equal to count reported by Java: <nn> during heatmap calculation for AP Interface: 88:f0:31:08:06:70-5.0-2
.
The sources of interference are:
– Bluetooth Paging Inquiry: A Bluetooth discovery (802.11b/g/n only)
– Bluetooth Sco Acl: A Bluetooth link (802.11b/g/n only)
– Generic DECT: A digital, enhanced cordless communication-compatible phone
– Generic TDD: A time division duplex (TDD) transmitter
– Generic Waveform: A continuous transmitter
– Microwave: A microwave oven (802.11b/g/n only)
– Canopy: A canopy bridge device
– Spectrum 802.11 FH: An 802.11 frequency-hopping device (802.11b/g/n only)
– Spectrum 802.11 inverted: A device using spectrally inverted Wi-Fi signals
– Spectrum 802.11 non std channel: A device using nonstandard Wi-Fi channels
– Spectrum 802.11 SuperG: An 802.11 SuperAG device
– Spectrum 802.15.4vAn 802.15.4 device (802.11b/g/n only)
– Video Camera: An analog video camera
– WiMAX Fixed: A WiMAX fixed device (802.11a/n/ac only)
– WiMAX Mobile: A WiMAX mobile device (802.11a/n/ac only)
– XBox: A Microsoft Xbox (802.11b/g/n only)
1. Use the cmxos date command to make sure that the Cisco CMX system date matches the current date. If the dates do not match, use the NTP server to synchronize the dates.
2. Enter the cmxctl stop –a command to shut down Cisco CMX services.
3. Enter the cmxctl start command to restart the services.
(On Apple iPads) The custom portal page appears twice before authentication is successful.
[object Object]
is also displayed.With VMware vSphere ESXi 6.5 and VMware vSphere ESXi 6.5 Update 1, the deployment options are not displayed.
Note From Cisco CMX Release 10.4.1-15, the Feature Flags setting is disabled by default. If your system is running an earlier release of Cisco CMX, we recommend that you disable the Feature Flags setting.
To disable the Feature Flags setting, enter these commands:
a. cmxctl config featureflags location.compactlocationhistory false
To import maps from Cisco Prime Infrastructure Release 3.5 to Cisco CMX with FIPS mode enabled, you must download the tar file of Cisco Prime Infrastructure, and then upload the tar file to Cisco CMX, as described in the “Importing Maps” section in the Cisco CMX Configuration Guide at: https://www.cisco.com/c/en/us/support/wireless/connected-mobile-experiences/products-installation-and-configuration-guides-list.htm.
Cisco CMX in FIPS mode supports only the aes128-cbc, aes256-cbc, aes128-gcm@openssh.com, and aes256-gcm@openssh.com ciphers.
Use the cmxctl config auth settings command to configure the Session idle timeout in minutes setting. The time range is 1 to 720 minutes. The default value is 30 minutes.
This timeout period does not apply to Cisco CMX CLI sessions.
– If you are running Cisco CMX Release 10.6.2-72 or earlier, install the cmx-disableanalytics-patch-10.6.2-1.cmxp patch file. Contact Cisco Customer Support ( https://www.cisco.com/c/en/us/support/index.html) for the patch file.
– If you are running Cisco CMX Release 10.6.2-89 or later, use the cmxctl disable analytics command.
Note The cmxctl disable analytics command is supported only on Cisco CMX Release 10.6.2-89 and later.
The Cisco Bug Search Tool (BST) allows partners and customers to search for software bugs based on product, release, and keyword, and aggregates key data such as bug details, product, and version. The BST is designed to improve the effectiveness in network risk management and device troubleshooting. The tool has a provision to filter bugs based on credentials to provide external and internal bug views for the search input.
For more information about the Cisco Bug Search Tool, including how to set email alerts for bugs and to save bugs and searches, see Bug Search Tool Help & FAQ.
Note Explore the Content Hub, the all new portal that offers an enhanced product documentation experience.
Get started with the Content Hub at content.cisco.com to craft a personalized documentation experience. Do provide feedback about your experience with the Content Hub.
Cisco Support Community is a forum for you to ask and answer questions, share suggestions, and collaborate with your peers. Join the forum at Cisco Community.
To receive timely, relevant information from Cisco, sign up at Cisco Profile Manager.
To get the business impact you are looking for with the technologies that matter, visit Cisco Services.
To submit a service request, visit Cisco Support.
To discover and browse secure, validated enterprise-class applications, products, solutions and services, visit Cisco Marketplace.
To obtain general networking, training, and certification titles, visit Cisco Press.
To find warranty information for a specific product or product family, access Cisco Warranty Finder.