About Cisco 1000 Series Integrated Services Routers
The Cisco 1000 Series Integrated Services Routers (also referred to as router in this document) are powerful fixed branch routers based on the Cisco IOS XE operating system. They are multi-core routers with separate core for data plane and control plane. There are two primary models with 8 LAN ports and 4 LAN ports. Features such as Smart Licensing, VDSL2 and ADSL2/2+, 802.11ac with Wave 2, 4G LTE-Advanced and 3G/4G LTE and LTEA Omnidirectional Dipole Antenna (LTE-ANTM-SMA-D) are supported on the router.
Smart Licensing Using Policy
Starting with Cisco IOS XE Amsterdam 17.3.2 release, with the introduction of Smart Licensing Using Policy, even if you configure a hostname for a product instance or device, only the Unique Device Identifier (UDI) is displayed. This change in the display can be observed in all licensing utilities and user interfaces where the hostname was displayed in earlier releases. It does not affect any licensing functionality. There is no workaround for this limitation.
The licensing utilities and user interfaces that are affected by this limitation include only the following:
-
Cisco Smart Software Manager (CSSM),
-
Cisco Smart License Utility (CSLU), and
-
Smart Software Manager On-Prem (SSM On-Prem).
Product Field Notice
Cisco publishes Field Notices to notify customers and partners about significant issues in Cisco products that typically require an upgrade, workaround or other user action. For more information, see https://www.cisco.com/c/en/us/support/web/field-notice-overview.html.
We recommend that you review the field notices to determine whether your software or hardware platforms are affected. You can access the field notices from https://www.cisco.com/c/en/us/support/web/tsd-products-field-notice-summary.html#%7Etab-product-categories.
New and Changed Hardware Features
There are no new hardware features in this release.
New and Changed Software Features in Cisco IOS XE 26.2.1
|
Product impact |
Feature |
Description |
|---|---|---|
|
API experience |
Adds DHCPv6-PD as an IPv6 address-discovery option in the ZTP/PnP workflow for Cisco IOS XE Catalyst SD-WAN devices. ZTP runs IPv4 and IPv6 address discovery in parallel, and IPv6 discovery can use stateful DHCPv6, SLAAC, or DHCPv6-PD. |
|
|
Upgrade |
Secure Router NGFW introduces Cisco Catalyst NGFW, a new security-application container for supported Cisco Catalyst 8000 Series Secure Routers. In Cisco IOS XE Catalyst SD-WAN Release 26.2.1 and Cisco Catalyst SD-WAN Manager Release 26.2.1, the feature provides workflows to install Catalyst NGFW and migrate supported settings from NGFW V1 Engine (UTD) to NGFW V2 Engine (Catalyst NGFW). IPS and IDS retain their core detection and prevention behavior while using Talos Lightweight Security Package (LSP) content. The release also adds Encrypted Visibility Engine (EVE) for encrypted-flow analysis without payload decryption and introduces Snort ML inspection for supported threats. Catalyst NGFW replaces the UTD community/subscriber signature-package workflow with independently managed LSP and Vulnerability Database (VDB) packages. LSP contains Talos rules and detectors; VDB provides application, fingerprint, and enrichment information. |
|
|
Ease of Use |
Configures speed, duplex, and negotiation auto in a single command. |
|
|
Software Reliability |
Cisco IOS XE 26.2.1 introduces Packet-Order Preservation during tunnel underlay reassembly that ensures a tunnel endpoint forwards completed, reassembled packets from the same traffic flow in correct order. The feature operates with packet reassembly boost mode on supported Cisco IOS XE Catalyst SD-WAN devices and Cisco SD-WAN Manager. |
|
|
Ease of Use |
Discontiguous Subnet Mask Support for IPv4 Network Object Groups |
Adds support for discontiguous subnet mask entries in IPv4 data prefixes and IPv4 network object groups used by NGFW Policy. You can use discontiguous subnet mask entries in IPv4 source and destination match conditions, rule sets, object groups, and deploy-time data prefix variables. |
|
CUBE FEATURES |
||
|
Security |
Automatic conversion of password formats into secure types |
Starting with Cisco IOS XE 26.2.1, it is recommended to use Type 6 (AES) for provisioning all credentials to comply with security standards. CUBE supports auto-conversion of Type 0 or Type 7 to reversible Type 6 encryption. |
|
Security |
Security warnings for non-secure protocols |
Starting with Cisco IOS XE 26.2.1, a warning message is displayed when insecure protocols such as HTTP, FTP, or TFTP are used. For CUBE, use secure alternatives such as HTTPS, SFTP, or SCP. |
|
Resilient Infrastructure |
||
|
Hardware reliability |
As part of Cisco's Resilient Infrastructure program and Cisco's commitment to secure infrastructure, this release includes additional changes aimed towards continuing to make Cisco IOS XE more secure by default. Note that some of these changes may require operational changes if you are not following secure best practices. This release includes the following changes:
For more information, refer Resilient Infrastructure. |
|
Cisco ISR1000 ROMmon Compatibility Matrix
The following table lists the ROMmon releases supported in Cisco IOS XE 16.x.x releases and Cisco IOS XE 17.x.x releases.
Warning |
Device unrecoverable after upgrade failure If a device running certain older Cisco IOS XE releases (earlier than 17.5.x) has password recovery disabled and experiences an upgrade failure to Cisco IOS XE 17.11.x or later, the device may become unrecoverable. To mitigate this risk, upgrade the device to any Cisco IOS XE image between 17.5.x and 17.10.x before upgrading to the destination Cisco IOS XE release (17.11.x or later). Refer to the Release Notes for Cisco 1000 Series Integrated Services Routers, Cisco IOS XE 17.11.x for specific upgrade steps. Subsequent release notes include this guidance. For example, refer to the Release Notes for Cisco ISR 1000 Series, Cisco IOS XE Dublin 17.13.1. |
Warning |
Recommendations before upgrade Before you upgrade, consider these actions:
(After upgrade) |
Note |
Reset button behavior The Reset button behavior changes when specific ROMmon and Cisco IOS XE versions are in use:
|
Note |
To identify the manufacturing date, use the show license udi command. For example:
The xxxx in the command output represents the manufacturing date.
|
Note |
To upgrade to Cisco IOS XE Dublin 17.12.x, follow these steps:
|
|
Cisco IOS XE Release |
Minimum ROMmon Release for IOS XE |
Recommended ROMmon Release for IOS XE |
|---|---|---|
|
26.1.x |
17.5(1r) |
26.1(1r) |
Changes in Behavior in Cisco IOS XE 26.2.x
Changes in Behavior in Cisco IOS XE 26.2.1
|
Description |
Behavior changes |
|---|---|
|
The ip nat translation nonpat-timeout keyword allows configuring a timeout from 0 to 536870 seconds or setting it to never. |
Refer to the ip nat translation (timeout) command. |
|
DHCP relay is always enabled by Cisco IOS and provide status verification for cellular modems |
Refer to the Configuring the DHCP Client section. |
|
Certificate hexadecimal data appears under crypto pki certificate chain in show running-config by default. Starting with Cisco IOS XE Release 26.2, configure the crypto pki certificate hidehex command hides certificate hexadecimal data from show running-config output while retaining the certificate chain and entry. |
Refer to the Certificate Hexadecimal Data Output Example. |
|
The procedure for configuring a trustpoint for EST is updated. |
Refer to the Configure a trustpoint for EST section. |
Resolved and Open Bugs in Cisco IOS XE 26.2.x
Resolved Bugs in Cisco IOS XE 26.2.1
Note |
Note: This software release may contain bug fixes first introduced in other releases. To see additional information, click the bug ID to access the Cisco Bug Search Tool. To search for a documented Cisco product issue, type in the browser: <bug_number> site:cisco.com. |
|
Identifier |
Headline |
|---|---|
|
SDWAN edge router device crashed after attempting to push a config group |
|
|
SDWAN edge router: upgrade process may report enormous "Required space" |
|
|
[IOS XE] 6VPE: Locally terminated IPv6 traffic fails over BDI interface |
|
|
17.18/26.1: Tracker probe id set to 0 while changing Invalid DNS endpoint to endpoint-ip |
|
|
SDWAN edge router: UTD may silently drop large fragmented RADIUS packets |
|
|
SDWAN edge router Router Reset due to PuntInject Keepalive Timeout (No Ucode File Generated) |
|
|
L2TPv3 xconnect session fails to establish when the traffic traverses through IPsec tunnel interface. |
|
|
IOS-XE not parsing transform payload with unknown attributes |
|
|
Unexpected reload due to ftmd fault on SDWAN edge router with On‑Demand Tunnels |
|
|
BFD echo packet counters report a fixed 2:1 tx/rx ratio (false 50% packet loss) on all tunnels after enabling Enhanced Application Aware Routing |
|
|
Unexpected Reload in CPP Server (cpp_sp_svr) Code |
|
|
Posture redirection not working on Sdwan router switch module |
|
|
SD-WAN Edge: Periodic Service Restart May Generate Crash Files |
|
|
SDWAN edge router : Power reset during cEdge boot causes router to enter ROMMON |
|
|
Endpoint-tracker HTTP probe sends IP address instead of FQDN in 17.15 |
|
|
Kernel Core Files Deleted From Flash When Incomplete Admin Tech is Generated |
|
|
Intermittent issue with RRI being lost on the Flex Hub |
|
|
Router intermittently loses ip address dynamically assigned to tunnel interface |
|
|
SDWAN Template push or CLI config update fails due to the duplication of VTY or Async lines in the configuration |
|
|
20.12.5 C1121-4PLTEP intermittent attach failure during onboarding due to unsupported AUX/native line commands |
|
|
Unexpected reload on CGM (Class-Group Manager) when updated |
|
|
Device in controller mode crashes with Critical process cpp_ha_top_level_server fault on fp_0_0 (rc=69) |
|
|
Memory Leak in cpp_sp_svr due to Classification Objects |
|
|
SDWAN edge router OMPD crash on malformed SD-WAN identity IP-to-user update from vSmart pxGrid integration |
|
|
BFD session establishment failed due to ARP resolution failure. |
|
|
VPN ID is not maintained after UTD feature causing ZBFW to evaluate against incorrect policy |
|
|
ncsshd process fails to terminate after "no netconf" and netconf refuses connection |
|
|
L2TP: Seeing "protocol l2tpv2 L2TP_CLASS_011" config getting lost with clear ppp all cli |
|
|
Router crashed while decrypting NAT-T IPsec traffic with CTS SGT enabled |
|
|
High QFP utilization due to NAT translation timeout and concurrent translation creation causing allocator contention |
|
|
Unable to configure stream on cellular interface |
|
|
SDWAN edge router upgrade fails with "timeout" when confd Phase 0 failure |
|
|
Sessions appear as two unidirectional records instead of one bidirectional flow |
|
|
SDWAN edge router : BOW in EAAR not working when tunnels are outside SLA and outside variance |
|
|
UDP packets multicast destination not seen on FIA-Trace nor EPC over xconnect |
|
|
Application Policy: IPv6 BGP Neighborship Fails When Using Basic Policy with Default Drop Action |
|
|
QFP command displays incorrect App-Probe-Class (APC) queue assignment |
|
|
vdaemon may flap SD-WAN control connections with HWCERTREN when multiple vManage-signed edge certificates have identical Not Before timestamps. |
|
|
Device may reload after remove an endpoint. |
|
|
Unexpected reload on SDWAN edge router device after changing secuity policy to none on template |
|
|
Buffer Overflow in Domain Name Pattern Handling Causes Pointer Corruption and System Crash |
|
|
Enable alerts for the EC genet server (Transform) dying or timing out |
|
|
fpmd crash seen with 17.12.6B respin image with longer soak + clear sdwan omp events |
|
|
Crash while processing packet in AppNav Tunnel |
|
|
Endpoint tracker is unable to determine next-hop for DNS name resolution from Dialer interface |
|
|
SSE Tunnels with Cisco Secure Access are stuck in SD-WAN Configuration Database |
|
|
Unexpected reload due to race condition in QoS service group configuration |
|
|
Crash in OMP process during end point tracker teardown |
|
|
NULL Dereference in NHRP MIB |
|
|
Update "reason for state change: MAX" in BFD Syslog |
|
|
Not able to disable "log" feature in NGFW Policies vManage for "Drop" rules. |
|
|
SD-WAN redirect-dns Destination NAT session collides with SIG tunnel IKEv2 control plane traffic |
|
|
ICMP TTL Expired packet sent via incorrect VRF |
|
|
SDWAN: Crash while updating Adaptive QOS Session Policy due to minimal traffic size |
|
|
Service-chain config modify to local svc-chain failed to delete old TLOC list action leading to packet drops |
|
|
Secondary OU is not generated in CSR for SD-Routing(Autonomous mode) devices |
|
|
HTTP SIG Tracker trying to resolve endpoint-api-url IP address via DNS after upgrade to 17.15.05 |
|
|
cpp_cp_svr crashes with SIGSEGV whle printing packet trace data |
|
|
Unexpected reload on router in SDWAN CCE (Classifier and Classification Engine) |
|
|
Critical Process cpp_ha_top_level_server crash (rc=69) Crash after adding zone based firewall setup configuration on the router |
|
|
Packet reordering observed when application performance-monitor service policy enabled |
|
|
Once we enable the DHCP snooping on the router, we can see that the destination and source MAC of the DHCP discovery are being corrupted. |
|
|
QFP crash with qfp-ucode and cpp_cp_svr cores. |
|
|
Standalone endpoint-tracker UP recovery syslog missing intermittently on SDWAN edge router |
|
|
Router unexpectedly reloads after IKEv2 operations |
|
|
BFD SD-WAN PMTUD: PMTU Converges Unexpectedly to 970 Bytes After dbg2:1 Event |
|
|
Ucode Code Crash while Printing Log for FW Drop for Packet with Invalid Header |
|
|
Ikev2 PPK Unable To Switch Back to PSK When 'Required' Is Used in Keyring |
Open Bugs in Cisco IOS XE 26.2.1
This software release may contain open bugs first identified in other releases. To see additional information, click the bug ID to access the Cisco Bug Search Tool. To search for a documented Cisco product issue, type in the browser: <bug_number> site:cisco.com.
|
Identifier |
Headline |
|---|---|
|
SDWAN Degradation of ~6% seen in profiles IPSEC_MCAST-512V_1400 and IPSEC_QOS_DPI_FNF_MCAST-512V_1400 |
|
|
Unexpected reload due to NAT pool exhaustion |
|
|
17.12.6 likely change in the SDWAN edge router code is causing the control connections failing to come up |
|
|
Umbrella tunnels down, reporting cdb-validate-info failed state with 401 authentication error. |
|
|
CoR-SaaS custom-app endpoint-url probing on free configurable port |
|
|
C1131 SD-WAN TLOCs remain disabled after upgrade to 17.15.04c due to IOS/FTMD/vdaemon interface-state reconciliation failure |
|
|
[SMTC# 01931673] C1111-4PLTEEA EM7455 SMS transmission gets stuck with pending SMS and ngiolite crash, requiring full router reload |
|
|
Standby RP Rebooting Frequently After Applying Static Named NAT Entry |
|
|
IOSd crash in "Open DNS Dev-Reg" process on 17.12.6 despite CSCwp09231 fix (Umbrella device-registration UAF during config churn) |
|
|
SDWAN ICMP interface tracker goes up everytime the router resolves the DNS-name configured |
|
|
CSCwv91764 - 26.2 Zscaler SSE GRE:The Public IP address for every tunnels entered on the vManage doe |
|
|
Update outdated GeoDB in 17.18.x |
|
|
SDWAN edge router .sdwaninstaller accounting for rollback files in disk space calculation |
|
|
UTD context with no inspection features enabled stays in Divert mode; traffic black-holed at memif |
|
|
IOSd crash in router_init due to stale PDB pname during routing process creation |
|
|
SDWAN edge router - 17.12.8 endpoint-tracker reports all shared-tracker tunnels Down when one tunnel fails DNS |
Related Information
Communications, Services, and Additional Information
-
To receive timely, relevant information from Cisco, sign up at Cisco Profile Manager.
-
To get the business results you’re looking for with the technologies that matter, visit Cisco Services.
-
To submit a service request, visit Cisco Support.
-
To discover and browse secure, validated enterprise-class apps, products, solutions and services, visit Cisco Marketplace.
-
To obtain general networking, training, and certification titles, visit Cisco Press.
-
To find warranty information for a specific product or product family, access Cisco Warranty Finder.
Cisco Bug Search Tool
Cisco Bug Search Tool (BST) is a web-based tool that acts as a gateway to the Cisco bug tracking system that maintains a comprehensive list of defects and vulnerabilities in Cisco products and software. BST provides you with detailed defect information about your products and software.
Documentation Feedback
To provide feedback about Cisco technical documentation, use the feedback form available in the right pane of every online document.
Troubleshooting
For the most up-to-date, detailed troubleshooting information, see the Cisco TAC website at https://www.cisco.com/en/US/support/index.html.
Go to Products by Category and choose your product from the list, or enter the name of your product. Look under Troubleshoot and Alerts to find information for the issue that you are experiencing.
Feedback