The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Feedback
Contents
Catalyst 8500 Edge Platform, Release 26.2.x
What’s New in the ROMmon release
Catalyst 8500 Edge Platform, Release 26.2.x
Cisco 26.2.1 is the first release for Cisco Catalyst 8500 Series Edge Platforms in the Cisco IOS XE 26.2.x release series.
This section provides a brief description of the new software features introduced in this release.
New software features in Cisco IOS XE 26.2.1
| Product impact |
Feature |
Description |
| Hardware reliability
|
Resilient Infrastructure Changes
|
As part of Cisco’s Resilient Infrastructure program and Cisco’s commitment to secure infrastructure, this release includes additional changes aimed towards continuing to make Cisco IOS XE more secure by default.
· The RADIUS client appends the Message-Authenticator attribute (Attribute 80 HMAC-MD5) to all outgoing Access-Request packets to mitigate cryptographic forgery and Blast-RADIUS vulnerabilities (CVE-2024-3596). · The RADIUS client drops incoming Access-Accept, Access-Reject, and Access-Challenge packets if the Message-Authenticator packet is absent or invalid. Ensure AAA servers (example, Cisco ISE) are configured to return Attribute 80. · Outbound SSH connections enforce Trust-On-First-Use (TOFU). The device prompts to verify and store remote server host keys in the known-hosts database on first connection and validates against them on subsequent sessions. · Proxy ARP is disabled by default across all routed interfaces, SVIs, and subinterfaces to reduce Layer 2 broadcast domains and prevent ARP spoofing. Configure the ip proxy-arp command explicitly if required. · The embedded web server daemon is disabled by default on factory configurations to restrict unauthenticated management access. Web UI and RESTCONF require explicit enablement of the ip http secure-server command. · The IOS XE device rejects unauthenticated NTP Mode 6 and Mode 7 control queries (monlist) to prevent NTP reflection and amplification DDoS attacks. Standard time synchronization (Modes 3 and 4) is unaffected. · Warning messages are emitted on the console and logged to syslog whenever legacy insecure protocols (telnet, ftp, tftp, http) are enabled in the configuration. · Real-time tracking of active insecure services is published to the operational database (operDB) and YANG data models, allowing management controllers (such as Cisco Catalyst Center) to monitor security compliance. For more information, refer Resilient Infrastructure.
|
| API experience
|
Adds DHCPv6-PD as an IPv6 address-discovery option in the ZTP/PnP workflow for Cisco IOS XE Catalyst SD-WAN devices. ZTP runs IPv4 and IPv6 address discovery in parallel, and IPv6 discovery can use stateful DHCPv6, SLAAC, or DHCPv6-PD. |
|
| Upgrade
|
Secure Router NGFW introduces Cisco Catalyst NGFW, a new security-application container for supported Cisco Catalyst 8000 Series Secure Routers. In Cisco IOS XE Catalyst SD-WAN Release 26.2.1 and Cisco Catalyst SD-WAN Manager Release 26.2.1, the feature provides workflows to install Catalyst NGFW and migrate supported settings from NGFW V1 Engine (UTD) to NGFW V2 Engine (Catalyst NGFW). IPS and IDS retain their core detection and prevention behavior while using Talos Lightweight Security Package (LSP) content. The release also adds Encrypted Visibility Engine (EVE) for encrypted-flow analysis without payload decryption and introduces Snort ML inspection for supported threats. Catalyst NGFW replaces the UTD community/subscriber signature-package workflow with independently managed LSP and Vulnerability Database (VDB) packages. LSP contains Talos rules and detectors; VDB provides application, fingerprint, and enrichment information. |
|
| Ease of use
|
Configures speed, duplex, and negotiation auto in a single command. |
|
| Software Reliability
|
Cisco IOS XE 26.2.1 introduces Packet-Order Preservation during tunnel underlay reassembly that ensures a tunnel endpoint forwards completed, reassembled packets from the same traffic flow in correct order. The feature operates with packet reassembly boost mode on supported Cisco IOS XE Catalyst SD-WAN devices and Cisco SD-WAN Manager. |
|
| Ease of use
|
Discontiguous Subnet Mask Support for IPv4 Network Object Groups |
Adds support for discontiguous subnet mask entries in IPv4 data prefixes and IPv4 network object groups used by NGFW Policy. You can use discontiguous subnet mask entries in IPv4 source and destination match conditions, rule sets, object groups, and deploy-time data prefix variables. |
| Ease of setup
|
|
This feature adds support for EVPN VPWS over SRv6 transport. EVPN VPWS uses EVPN signalling and SRv6 encapsulation to provide point-to-point Layer 2 VPN service between provider edge devices. |
This section provides a brief description of the behavior changes introduced in this release.
Table 1. Behavior changes for Catalyst 8500 Series Edge Platforms, Release 26.2.1
| Description |
Behavior changes |
| The ip nat translation nonpat-timeout keyword allows configuring a timeout from 0 to 536870 seconds or setting it to never. |
Refer to the ip nat translation (timeout) command. |
| You can verify the FEC type from the show interface command only for 100G interfaces. |
Refer to the Configuring FEC section. |
| DHCP relay is always enabled by Cisco IOS and provide status verification for cellular modems |
Refer to the Configuring the DHCP Client section. |
| Certificate hexadecimal data appears under crypto pki certificate chain in show running-config by default. Starting with Cisco IOS XE Release 26.2, configure the crypto pki certificate hidehex command hides certificate hexadecimal data from show running-config output while retaining the certificate chain and entry. |
Refer to the Certificate Hexadecimal Data Output Example. |
| The procedure for configuring a trustpoint for EST is updated. |
Refer to the Configure a trustpoint for EST section. |
This table lists the resolved issues in this specific software release.
Note: This software release may contain bug fixes first introduced in other releases. To see additional information, click the bug ID to access the Cisco Bug Search Tool.
Resolved issues in Cisco IOS XE 26.2.1
Table 2. Resolved issues for Cisco 8500 Edge Platform, Release 26.2.1
| Bug ID |
Description |
| SDWAN edge router device crashed after attempting to push a config group |
|
| SDWAN edge router: upgrade process may report enormous "Required space" |
|
| [IOS XE] 6VPE: Locally terminated IPv6 traffic fails over BDI interface |
|
| 17.18/26.1: Tracker probe id set to 0 while changing Invalid DNS endpoint to endpoint-ip |
|
| C8500 modify fragment IPV6 identifier |
|
| SDWAN edge router: UTD may silently drop large fragmented RADIUS packets |
|
| SDWAN edge router Router Reset due to PuntInject Keepalive Timeout (No Ucode File Generated) |
|
| L2TPv3 xconnect session fails to establish when the traffic traverses through IPsec tunnel interface. |
|
| IOS-XE not parsing transform payload with unknown attributes |
|
| Unexpected reload due to ftmd fault on SDWAN edge router with OnDemand Tunnels |
|
| BFD echo packet counters report a fixed 2:1 tx/rx ratio (false 50% packet loss) on all tunnels after enabling Enhanced Application Aware Routing |
|
| Unexpected Reload in CPP Server (cpp_sp_svr) Code |
|
| SD-WAN Edge: Periodic Service Restart May Generate Crash Files |
|
| SDWAN edge router : Power reset during cEdge boot causes router to enter ROMMON |
|
| Endpoint-tracker HTTP probe sends IP address instead of FQDN in 17.15 |
|
| Kernel Core Files Deleted From Flash When Incomplete Admin Tech is Generated |
|
| Intermittent issue with RRI being lost on the Flex Hub |
|
| Router intermittently loses ip address dynamically assigned to tunnel interface |
|
| SDWAN Template push or CLI config update fails due to the duplication of VTY or Async lines in the configuration |
|
| [C8500] Port-channel sub-interfaces fail to pass traffic after bulk configuration |
|
| Unexpected reload on CGM (Class-Group Manager) when updated |
|
| Device in controller mode crashes with Critical process cpp_ha_top_level_server fault on fp_0_0 (rc=69) |
|
| Memory Leak in cpp_sp_svr due to Classification Objects |
|
| SDWAN edge router OMPD crash on malformed SD-WAN identity IP-to-user update from vSmart pxGrid integration |
|
| BFD session establishment failed due to ARP resolution failure. |
|
| VPN ID is not maintained after UTD feature causing ZBFW to evaluate against incorrect policy |
|
| ncsshd process fails to terminate after "no netconf" and netconf refuses connection |
|
| L2TP: Seeing "protocol l2tpv2 L2TP_CLASS_011" config getting lost with clear ppp all cli |
|
| Router crashed while decrypting NAT-T IPsec traffic with CTS SGT enabled |
|
| High QFP utilization due to NAT translation timeout and concurrent translation creation causing allocator contention |
|
| Critical Process cpp_ha_top_level_server crash (rc=69) Crash after adding zone based firewall setup configuration on the router |
|
| SDWAN edge router upgrade fails with "timeout" when confd Phase 0 failure |
|
| Sessions appear as two unidirectional records instead of one bidirectional flow |
|
| SDWAN edge router : BOW in EAAR not working when tunnels are outside SLA and outside variance |
|
| C8500: infra timer expiry with high traffic rate |
|
| UDP packets multicast destination not seen on FIA-Trace nor EPC over xconnect |
|
| Application Policy: IPv6 BGP Neighborship Fails When Using Basic Policy with Default Drop Action |
|
| QFP command displays incorrect App-Probe-Class (APC) queue assignment |
|
| C8000V vdaemon may flap SD-WAN control connections with HWCERTREN when multiple vManage-signed edge certificates have identical Not Before timestamps. |
|
| Unexpected reload on SDWAN edge router device after changing secuity policy to none on template |
|
| Buffer Overflow in Domain Name Pattern Handling Causes Pointer Corruption and System Crash |
|
| Enable alerts for the EC genet server (Transform) dying or timing out |
|
| fpmd crash seen with 17.12.6B respin image with longer soak + clear sdwan omp events |
|
| Crash while processing packet in AppNav Tunnel |
|
| Endpoint tracker is unable to determine next-hop for DNS name resolution from Dialer interface |
|
| QFP Ucode C8500L crash on 17.15.4c |
|
| SSE Tunnels with Cisco Secure Access are stuck in SD-WAN Configuration Database |
|
| Unexpected reload due to race condition in QoS service group configuration |
|
| Crash in OMP process during end point tracker teardown |
|
| NULL Dereference in NHRP MIB |
|
| Update "reason for state change: MAX" in BFD Syslog |
|
| Not able to disable "log" feature in NGFW Policies vManage for "Drop" rules. |
|
| SD-WAN redirect-dns Destination NAT session collides with SIG tunnel IKEv2 control plane traffic |
|
| ICMP TTL Expired packet sent via incorrect VRF |
|
| SDWAN: Crash while updating Adaptive QOS Session Policy due to minimal traffic size |
|
| Service-chain config modify to local svc-chain failed to delete old TLOC list action leading to packet drops |
|
| Secondary OU is not generated in CSR for SD-Routing(Autonomous mode) devices |
|
| C8500-12X4QC experienced unexpected ESP reload when using the Packet Trace feature |
|
| HTTP SIG Tracker trying to resolve endpoint-api-url IP address via DNS after upgrade to 17.15.05 |
|
| cpp_cp_svr crashes with SIGSEGV whle printing packet trace data |
|
| Unexpected reload on router in SDWAN CCE (Classifier and Classification Engine) |
|
| Packet reordering observed when application performance-monitor service policy enabled |
|
| QFP crash with qfp-ucode and cpp_cp_svr cores. |
|
| Standalone endpoint-tracker UP recovery syslog missing intermittently on SDWAN edge router |
|
| Catalyst 8500 Reload Due to CPP Stuck Threads in BFD SDWAN Transmit Path |
|
| Unexpected reload on CAT8500L due to IKE SA LIMIT REACHED |
|
| Router unexpectedly reloads after IKEv2 operations |
|
| BFD SD-WAN PMTUD: PMTU Converges Unexpectedly to 970 Bytes After dbg2:1 Event |
|
| Ucode Code Crash while Printing Log for FW Drop for Packet with Invalid Header |
|
| Ikev2 PPK Unable To Switch Back to PSK When 'Required' Is Used in Keyring |
Open issues in Cisco IOS XE 26.2.1
Table 3. Open issues for Catalyst 8500 Edge Platform, Release 26.2.1
| Bug ID |
Description |
| SDWAN Degradation of ~6% seen in profiles IPSEC_MCAST-512V_1400 and IPSEC_QOS_DPI_FNF_MCAST-512V_1400 |
|
| Unexpected reload due to NAT pool exhaustion |
|
| 17.12.6 likely change in the SDWAN edge router code is causing the control connections failing to come up |
|
| Umbrella tunnels down, reporting cdb-validate-info failed state with 401 authentication error. |
|
| CoR-SaaS custom-app endpoint-url probing on free configurable port |
|
| [17.15.4] Traffic completely stalls on a agg qos port channel |
|
| Standby RP Rebooting Frequently After Applying Static Named NAT Entry |
|
| IOSd crash in "Open DNS Dev-Reg" process on 17.12.6 despite CSCwp09231 fix (Umbrella device-registration UAF during config churn) |
|
| SDWAN ICMP interface tracker goes up everytime the router resolves the DNS-name configured |
|
| CSCwv91764 - 26.2 Zscaler SSE GRE:The Public IP address for every tunnels entered on the vManage doe |
|
| Update outdated GeoDB in 17.18.x |
|
| SDWAN edge router .sdwaninstaller accounting for rollback files in disk space calculation |
|
| UTD context with no inspection features enabled stays in Divert mode; traffic black-holed at memif |
|
| IOSd crash in router_init due to stale PDB pname during routing process creation |
|
| SDWAN edge router - 17.12.8 endpoint-tracker reports all shared-tracker tunnels Down when one tunnel fails DNS |
This section lists the ROMmon version required for your Catalyst 8500 model:
Table 4. Compatibility information for Catalyst 8500 Edge Platform, Release 26.2.1
| Platforms |
DRAM |
Minimum ROMMON |
Recommended ROMMON |
| C8500-12X4QC and C8500–12X |
16 GB(default) |
17.2(1r) |
17.11(1r) |
|
|
32 GB |
17.2(1r) |
17.11(1r) |
|
|
64 GB |
17.3(2r) |
17.11(1r) |
| C8500-20X6C |
All variants |
17.10(1r) |
17.15(1r) Note: Downgrading to a ROMmon version lower than 17.15(1r) is not supported. |
| C8500L-8S4X |
- |
17.10(1r) |
17.14(1r) This version of ROMmon is only available with Cisco IOS XE 17.15.1a onwards. |
Note: In case of C8500L-8S4X platform, the ROMmon image is bundled with the Cisco IOS XE software image which ensures that when the device is booted up, the ROMmon image is also automatically upgraded to the recommended version.
What’s New in the ROMmon release
This section lists changes in the ROMmon package
| ROMmon Release for C8500-12X4QC, C8500-12X |
Fixes |
| 17.3(1r) |
Supports 64GB DRAM for C8500-12X4QC & C8500-12X |
| 17.10 (1r) |
Added support for new platform C8500-20X6C |
| ROMmon Release for C8500L-8S4X |
Fixes |
| 17.14(1r) |
CSCwf98337 - Evaluation of C8500L-8S4X for Intel 2023.3 IPU and SMRAM vulnerabilities. CSCwe21026 - Evaluation of C8500L-8S4X for Intel 2023.1 IPU and SMM vulnerabilities.
|
| ROMmon Release for C8500-20X6C |
Fixes |
| 17.15(1r) |
CSCwf98335 - Evaluation of all_routing_iosxe for Intel 2023.3 IPU and SMRAM vulnerabilities.
CSCwd96405 - ASR1k:BL and ML hashes not seen in the "Show system intergrity" CLI for Aikido based platforms. Additional minor fixes. |
To upgrade the ROMmon version of your device, use these steps:
1. Check the existing version of ROMmon by using show rom-monitor r0 command. If you are installing Cisco IOS XE software on a new device, skip this step.
2. Review Minimum and Recommended ROMmon Releases to identify the recommended version of ROMmon software for the device you plan to upgrade.
3. Go to https://software.cisco.com/# and download the ROMmon package file.
4. Copy the ROMmon file to flash drive:
copy ftp:// username:password@IP addressROMmon package file flash:
5. Upgrade the ROMmon package using the following command:
upgrade rom-monitor filename bootflash: ROMmon package name all
6. Execute reload command to complete the ROMmon upgrade process
7. Execute show rom-monitor r0 command to ensure the ROMmon software is upgraded.
· Hardware Installation Guide for Catalyst 8500 Series Edge Platforms
· Hardware Installation Guide for Catalyst 8500L Series Edge Platforms
· Smart Licensing Using Policy for Cisco Enterprise Routing Platforms
· Software Configuration Guide for Catalyst 8500 Series Edge Platforms
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1110R)
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.
© 2026 Cisco Systems, Inc. All rights reserved.