Release Notes for Cisco SD-WAN Release 19.2.x


Note

The documentation set for this product strives to use bias-free language. For purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on standards documentation, or language that is used by a referenced third-party product.


These release notes accompany the Cisco SD-WAN Release 19.2.x, which provides Cisco SD-WAN capabilities for Cisco vEdge devices—including Cisco vSmart Controllers, Cisco vBond Orchestrators and Cisco vManage as applicable to Cisco vEdge devices.

For release information about Cisco IOS XE SD-WAN devices, refer to Release Notes for Cisco IOS XE SD-WAN Release 16.12.x.

What's New for Cisco SD-WAN Release 19.2.x

This section applies to Cisco vEdge devices.

Cisco is constantly enhancing the SD-WAN solution with every release and we try and keep the content in line with the latest enhancements. The following table lists new and modified features we documented in the Configuration, Command Reference, and Hardware Installation guides. For information on additional features and fixes that were committed to the SD-WAN solution, see the Resolved and Open Bugs section in the Release Notes.

Table 1. What's New for Cisco vEdge Device

Feature

Description

Getting Started

API Cross-Site Request Forgery Prevention

This feature adds protection against Cross-Site Request Forgery (CSRF) that occurs when using Cisco SD-WAN REST APIs. This protection is provided by including a CSRF token with API requests. You can put requests on an allowed list so that they do not require protection if needed. See Cross-Site Request Forgery Prevention.

Systems and Interfaces

Secure Shell Authentication Using RSA Keys

This feature helps configure RSA keys by securing communication between a client and a Cisco SD-WAN server. See SSH Authentication using vManage on Cisco XE SD-WAN Devices. See Configure SSH Authentication.

Policies

Packet Duplication for Noisy Channels

This feature helps mitigate packet loss over noisy channels, thereby maintaining high application QoE for voice and video. See Configure and Monitor Packet Duplication.

Control Traffic Flow Using Class of Service Values

This feature lets you control the flow of traffic into and out of a Cisco device's interface based on the conditions defined in the quality of service (QoS) map. A priority field and a layer 2 class of service (CoS) were added for configuring the re-write rule. See Configure Localized Data Policy for IPv4 Using Cisco vManage.

Security

Secure Communication Using Pairwise IPsec Keys

This feature allows you to create and install private pairwise IPsec session keys for secure communication between an IPsec device and its peers. For related information, see IPSec Pairwise Keys Overview.

Configure IKE-Enabled IPsec Tunnels

The pre-shared key needs to be at least 16 bytes in length. The IPsec tunnel establishment fails if the key size is less than 16 characters when the router is upgraded to version 19.2. See Configure IKE-Enabled IPsec Tunnels.

Network Optimization and High Availability

Disaster Recovery for vManage

This feature helps you configure Cisco vManage in an active or standby mode to counteract hardware or software failures that may occur due to unforeseen circumstances. See Configure Disaster Recovery.

Share VNF Devices Across Service Chains

This feature lets you share Virtual Network Function (VNF) devices across service chains to improve resource utilisation and reduce resource fragmentation. See Share VNF Devices Across Service Chains.

Monitor Service Chain Health

This feature lets you configure periodic checks on the service chain data path and reports the overall status. To enable service chain health monitoring, NFVIS version 3.12.1 or later should be installed on all CSP devices in a cluster. See Monitor Service Chain Health.

Manage PNF Devices in Service Chains

This feature lets you add Physical Network Function (PNF) devices to a network, in addition to the Virtual Network function (VNF) devices. These PNF devices can be added to service chains and shared across service chains, service groups, and a cluster. Inclusion of PNF devices in the service chain can overcome the performance and scaling issues caused by using only VNF devices in a service chain. See Manage PNF Devices in Service Chains.

Important Notes, Known Behavior, and Workaround

When you complete a Cisco SD-WAN software downgrade procedure on a device, the device goes into the configuration mode that it was in when you last upgraded the Cisco SD-WAN software on the device. If the device is in a different configuration mode when you start the downgrade than it was when you last upgraded, the device and Cisco vManage show different configuration modes after the downgrade completes. To put the configuration modes back in sync, reattach the device to a device template. After you reattach the device, both the device and Cisco vManage show that the device is in the vManage configuration mode.

Cisco vManage Upgrade Paths

Table 2.
Starting Cisco vManage Version Destination Version

19.2.x

18.x/19.2.x

Direct Upgrade

20.1.x

Not Supported

20.3.x

Not Supported

20.4.x

Not Supported

Resolved and Open Bugs

About the Cisco Bug Search Tool

Use the Cisco Bug Search Tool to access open and resolved bugs for a release.

The tool allows you to search for a specific bug ID, or for all bugs specific to a product and a release.

You can filter the search results by last modified date, bug status (open, resolved), severity, rating, and support cases.

Resolved and Open Bugs

All resolved and open bugs for this release are available in the Cisco Bug Search Tool.

Resolved and Open Bugs for Cisco SD-WAN Release 19.2.4

Table 3. Resolved Bugs for Cisco SD-WAN Release 19.2.4

Bug ID

Description

CSCvp21016

vEdge FTMD crash when using FQDN as tunnel-destination

CSCvq30332

fp-core watchdog failure on vEdge 5k running 18.4.1 (fp-um)

CSCvr54226

don't add certificate errors into configure DB

CSCvr84704

vManage fails to login if Encryption algorithm is set to SHA-256 for ADFS

CSCvs07518

vManage stores stale session and renders to j_security_check or last cached url

CSCvs48535

%IPSEC-3-REPLAY_ERROR: + BFD down and drops IN_CD_COPROC_ANTI_REPLAY_FAIL

CSCvs96019

19.2 vSmart omp keeps crashing when edge device is higher version than vSmart

CSCvt12098

vedge cloud 18.4.3/19.2.1 on top of NFVIS(3.12.3 RC4) stop fowarding traffic when CU flap interface.

CSCvt26948

vManage re-arrange rules issue

CSCvt30224

Slash symbol cannot be used in a variable value of any device specific parameter scope in templates

CSCvt48880

vManage: real time omp advertised routes in vmanage showing received routes as well.

CSCvt55446

Misleading logout event

CSCvt84946

Cloud onRamp for IaaS on AWS: default route to null0 blackholes traffic sent to Internet

CSCvu05829

route leaking between VPN with natpool in one VPN is not working.

CSCvu06877

Regression: vEdge2000 cannot exceed more than 65K NAT sessions over GRE or IKE IPSec tunnel

CSCvu08599

vManage Feature hostname / location template should support special characters

CSCvu15259

Vedge receives a packet to remove SPIs for duplicate IKEv2 SAs but it removes all the SPIs instead.

CSCvu19754

Cannot ssh into vsmart, vbond with GCM ciphers

CSCvu21309

BFD sessions flap after multiple control connection flaps to the vSmart.

CSCvu23499

"show ip route vpn " output not showing specific routes for omp routes

CSCvu29677

vManage misleading error regarding multitenancy in singe tenant environment cluster

CSCvu31137

CSR signed certificate fails when vManage configured with timezone America/Sao_Paulo with Cisco PKI

CSCvu31763

Cisco SD-WAN Denial of Service Vulnerabilities

CSCvu35813

A tenant logged into vManage using tenantadmin fails to attach a device to a template (feature/cli)

CSCvu36324

vEdge 100m lose IP for a Cellular interface

CSCvu36501

''ftmd' crash on vEdge when cellular interface is present and "show interface" is executed

CSCvu38473

ISR1100-4GLTE not showing when SIM is Locked

CSCvu49885

traffic flows are not load-balanced fairly across all available cores when using GRE tunnel in vedge

CSCvu50167

vSmart seeing crashes with high policy-queue.

CSCvu53588

DC1 vmanage template attachment disappear after a switchover

CSCvu53617

Make 30 notifications / min restriction for webhook alarm notification configurable

CSCvu54906

Template update :Request time out:Client timed out waiting for request taking longer than 90 secs

CSCvu56405

Uploaded WAN-Edge list rejected, chassis tag missing

CSCvu58050

SSO SAMLResponse redirect points to loginError.html unexpectedly

CSCvu58459

Critical customer with 19.2.2, 4 vManage cluster is running into Full GC allocation failure

CSCvu60421

Downgrade of vmanage should be blocked as a part of activate also along with install workflows.

CSCvu64608

vbond information is lost during replication after multiple failovers

CSCvu69390

error message "Server error Unknown error" while accessing tloc and tunnel in WAN status

CSCvu69444

SNMP Query for Interface Description OID breaks if description is longer than 32 characters.

CSCvu71611

Disable support for weak encryption ciphers on vManage and vSmart.

CSCvu74275

MSP: wildfly: kafka is not yet functional

CSCvu74421

SNMP v3 walk is failing in vsmart and vedges

CSCvu77817

OMPD crash with control-policy export vpn

CSCvu79620

tunnel interface is admin up and oper down but local properties show admin and oper as down

CSCvu87254

vManage spends 60+ seconds to parse the device template with 500+ variables

CSCvu87754

100M shaper will introduce inaccurate throughput with traffic oversubscribed on ISR1100-4G

CSCvu92440

Cisco PKI Root Certificates not installed in recent images

CSCvu97198

vManage: Only allow 1yr option since 2/3yr options are deprecated

CSCvv00116

Vmanage 20.1.12 when selecting "Mark as optional" under radius will fail with an error

CSCvv00132

vEdge crashed with error "Software initiated - Daemon 'ompd' failed. Core files found"

CSCvv03068

vEdge control connections goes down after CSR generation

CSCvv07412

Device is unreachble, interfaces are showing as up

CSCvv10287

CoR probes working for O365 but failing for every other SaaS application

CSCvv14033

vManage revokes devices enterprise cert after hitting "Send to Controllers"

CSCvv17381

vEdge5000: control connection stuck in "Challenge" phase - Failed to create IdentityReqBlob

CSCvv18138

vegde is dropping bfd packets from cedge.

CSCvv18311

Large number of sequences in localized policy causing fpmd crash.

CSCvv18872

On the NSO of the vManage, the address of the vSmarts was set as 0.0.0.0

CSCvv19403

MSP: user is logged out of GUI eventhough client session timeout is disabled

CSCvv19652

vEdge crashes with dbgd failed message when running speed test

CSCvv20260

LLQ policer disappears when changed policy configuration

CSCvv22275

Unable to see stats on vAnalytics in 18.4.5

CSCvv22466

vEdge cannot resolve vBond. No packets going out of loopback interface.

CSCvv24320

Multiples vEdges crashing with "Software initiated - Daemon 'ftmd' failed"

CSCvv32465

Pointing to a wrong URL for changing the default config. DB username and password

CSCvv32615

ConfigDB credentials are exposed in cleartext

CSCvv37343

WebHooks fails in vManage when more than one is configured

CSCvv39961

Frequent Exceptions "Unable to process request = /clusterManagement/tenancy/mode from client X"

CSCvv42937

No date and time info in the syslog payload

CSCvv44894

Web traffic is not properly recognized by DPI

CSCvv47101

The request nms configuration-db configure command needs protection and documentation

CSCvv50032

SSO auth errors, exception: Error determining metadata contracts

CSCvv52553

Messaging server crash information saved in ramdrive

CSCvv54150

vedge_azurecloud_cloud_18_4_0 console logs are getting filled with HTTP logs

CSCvv54671

vSmart OMPD crash on policy application

CSCvv54844

ConfigDB not updating username/password

CSCvv58559

vmanage triggered alert "Could not store alarm:" resulting alarm trigger at provider.

CSCvv59996

vAnalytics launch lands on a "about:blank" page on 19.2.3 image version

CSCvv60007

DCA engine may not be able to reach vManage

CSCvv61236

SNMP community not accepting exclamation ! in string

CSCvv65954

UI timeout before Centralized Policybackend operation is completed

CSCvv66595

dbgd crash observed on the vEdge router while running a speed test.

CSCvv75130

/opt/data/backup permission denied

CSCvv79647

UI timeout needs to be changed to 180 seconds for policy and security view generation

CSCvv82149

ISR1100-6G vEdge reboot after Centralized policy push

CSCvv84742

Workaround is needed for Operator user to be able to view device configurations post VManage 19.2.3

CSCvv90381

Vedge reversing the src and dst MAC instead of using its own src-mac.

CSCvw10824

Buffer pool leak seen on ISR1100-6G

CSCvw17655

vEdge DPI for MS Teams does not work well

CSCvw28614

Unable to login through SSO with vManage on 19.2.31

CSCvw35718

drconsul service start in cluster while arbitrator is not in use

CSCvw53100

Enhance syslog format for SDWAN to align with RFC standard

CSCvw55778

vManage reverts a CLI template to its original version incorrectly.

CSCvs52888

Add host-name or personality in the admin-tech filename

CSCvu16655

Ater doing a manual DR, the "make primary" button did not show in new standby

CSCvi59635

Cisco SD-WAN Command Injection Vulnerabilities

CSCvi59639

Cisco SD-WAN Command Injection Vulnerabilities

CSCvi69982

Cisco SD-WAN Command Injection Vulnerabilities

CSCvm26011

Cisco SD-WAN Command Injection Vulnerabilities

CSCvu28387

Cisco SD-WAN Command Injection Vulnerabilities

CSCvu28443

Cisco SD-WAN Command Injection Vulnerabilities

Table 4. Open Bugs for Cisco SD-WAN Release 19.2.4

Bug ID

Description

CSCvx24858

Disaster recovery feature failing with error apoc.periodic.iterate

CSCvx29967

Fail to upload images to software repository post Cisco vManage upgrade to Cisco SD-WAN Release 19.2.4

Resolved and Open Bugs for Cisco SD-WAN Release 19.2.31

Table 5. Resolved Bugs for Cisco SD-WAN Release 19.2.31

Bug ID

Description

CSCvs48535

%IPSEC-3-REPLAY_ERROR: + BFD down and drops IN_CD_COPROC_ANTI_REPLAY_FAIL

CSCvt12098

vedge cloud 18.4.3/19.2.1 on top of NFVIS(3.12.3 RC4) stop fowarding traffic when CU flap interface.

CSCvt84946

Cloud onRamp for IaaS on AWS: default route to null0 blackholes traffic sent to Internet

CSCvu36501

''ftmd' crash on vEdge when cellular interface is present and "show interface" is executed

CSCvu58459

Critical customer with 19.2.2, 4 vManage cluster is running into Full GC allocation failure

CSCvu69444

SNMP Query for Interface Description OID breaks if description is longer than 32 characters.

CSCvu77817

OMPD crash with control-policy export vpn

CSCvu98521

Device's are not booting up after a power outage

CSCvv03068

vEdge control connections goes down after CSR generation

CSCvv14033

vManage revokes devices enterprise cert after hitting "Send to Controllers"

CSCvv18311

fpmd crashes on vEdge1k, 2k with 19.2.1, 18.4.302

CSCvv18872

On the NSO of the vManage, the address of the vSmarts was set as 0.0.0.0

CSCvv19652

vEdge crashes with dbgd failed message when running speed test

CSCvv22385

vManage GUI down due to GC Allocation Failure on 19.2.3

CSCvv24320

Multiples vEdges crashing with "Software initiated - Daemon 'ftmd' failed"

CSCvv55152

Unable to edit the device template if security policy is attached

CSCvv65954

UI timeout before Centralized Policybackend operation is completed

CSCvv79647

UI timeout needs to be changed to 180 seconds for policy and security view generation

CSCvr54226

don't add certificate errors into configure DB

CSCvs58213

Vedge-5000:Auto IP feature support for feature parity.

CSCvu74421

SNMP v3 walk is failing in vsmart and vedges

CSCvv22275

Unable to see stats on vAnalytics in 18.4.5

CSCvv60007

DCA unable to reach vManage

CSCvv66595

dbgd crash observed on the vEdge router while running a speed test.

CSCvu06877

Regression: vEdge2000 cannot exceed more than 65K NAT sessions over GRE or IKE IPSec tunnel

CSCvu87754

100M shaper will introduce inaccurate throughput with traffic oversubscribed on ISR1100-4G

CSCvq30332

fp-core watchdog failure on vEdge 5k running 18.4.1 (fp-um)

CSCvs70534

vEdge(x86) IPSec+QoS Performance Optimization

CSCvu58050

SSO SAMLResponse redirect points to loginError.html unexpectedly

CSCvv89447

Cisco SD-WAN vManage cluster kills session after idle-timeout expires even when traffic is present

CSCvw10824

Buffer pool leak seen on ISR1100-6G

CSCvv09746

Cisco SD-WAN vManage Software XML External Entity Vulnerability

CSCvv02305

Cisco SD-WAN vManage Software XML External Entity Vulnerability

CSCvv03658

Cisco SD-WAN vManage Software Path Traversal Vulnerability

Open Bugs for Cisco SD-WAN Release 19.2.31

Table 6. Open Bugs for Cisco SD-WAN Release 19.2.31

Bug ID

Description

CSCvw28614

Unable to login through SSO with vManage on 19.2.31

CSCvu35608

Disaster Recovery: Secondary vmanage cluster shows 200,000 vmanages instead of 3 on main dashboard

CSCvv54844

ConfigDB not updating username/password

Resolved and Open Bugs for Cisco SD-WAN Release 19.2.3

Resolved Bugs for Cisco SD-WAN Release 19.2.3

Table 7. Resolved Bugs for Cisco SD-WAN Release 19.2.3

Bug ID

Description

CSCvo72974

vE5K performance drops significantly using loopback TLOC without 'bind' configuration

CSCvq30348

fp-core watchdog falure on vEdge 5k running 18.4.1 tcpd crash

CSCvq68888

vManage is showing certificate expiry alarms under the 'Certificates' pane on the dashboard

CSCvq91658

Error in sending device list for Push vSmart List to vBond

CSCvr35741

DPI statistics database configuration memory increase

CSCvr52733

vedge frequently establishing control connections to the vBond even though it is in equilibrium

CSCvr92326

Cloud on Ramp not pushing configuration to vEdge-Cloud when adding Sites

CSCvs10190

vEdge WLAN iPhone Wireless Clients dropping connection after 1-3 mins

CSCvs14717

IPsec tunnel stuck in IKE_INIATE with vEdge not initiating IKE packets.

CSCvs26265

Data collection is slow on vManage after enabling vAnalytics

CSCvs34951

API should validate value of platformFamily + Enforce sw version ZTP configures isr1100 for x86 img

CSCvs36978

Enforce Software Version : Device already has image error

CSCvs49176

vEdge VRRP fail to receive unicast traffic over i40evf

CSCvs64250

regression: can't configure dhcp default route in vManage 19.3.0

CSCvs67769

Can not create vManage user to access disaster recovery other than admin user

CSCvs70961

vmanage gui not accessible as /opt/data is 100% full. App server down

CSCvs83609

Dbgd daemon crashed with signal 6 after running vEdge packet capture

CSCvs84918

Traffic simulation is not working properly on 19.2.1

CSCvs95487

vEdge 2k with 17.2.8 see high CPU because of process vconfd_script_vmanage_list_stats.sh

CSCvs96758

Not getting omp label on the edge devices which is causing traffic to take another link.

CSCvt16841

Vedge ipsec tunnel stops passing traffic during high load and rekey

CSCvt25691

Vmanage reloads with reason: Daemon 'cfgmgr' failed

CSCvt28482

vedge SRIOV networks are unreachable after remote interface flap

CSCvt34095

vBond DNS resolution may fail in ECMP environment

CSCvt39342

ZBFW + IRB show severe packet loss

CSCvt42611

Performance is very low with subinterfaces on vEdge5k

CSCvt46779

Route export not working as desired during failover testing

CSCvt54485

Nat over IPsec not working with ZBFW

CSCvt61421

vedge-cloud with SRIOV interfaces unable to receive IP packets more than 1496 bytes

CSCvt61717

Route export not working as expected during failover testing

CSCvt62324

TS/SS: Fail to push template and create admin log from UI. Failed to publish the task on message bus

CSCvt65197

vEdge SDWAN IPsec tunnel flapping due IKE packet drops

CSCvt66337

Shaping rate in x86 platform not working properly for TCP traffic

CSCvt70360

Inconsistency between "show app dpi flows" output and Current flows count in show app dpi summary

CSCvt71865

SNMP not working on tunnel interface and to loopback interface in vpn 0.

CSCvt74507

RDP Session resets with 802.1x running with default reauth and inactivity values

CSCvt76335

vedge frequently establishing control connections to the vBond even though it is in equilibrium

CSCvt95983

vEdge Cloud: vEdge on Azure may go into a bootloop state after an upgrade from 18.x.x to 19.2.2

CSCvt97764

Dhcp helper option not available in static mode in feature template for vedge and xe-sdwan

CSCvu26847

isr1100 unable to communicate with vbond due to Board ID Signature Verify Failure

CSCvu28927

vmanage dr standby cluster not replicating feature templates even config-db replication is success

CSCvu44708

Vedge doesn't initiate an IKE negotiation, it sends a CREATE_CHILD_SA instead

CSCvu59327

VManage alarms Control TLOC Down and BFD TLOC Down are not raised on the GUI all the time

CSCvt65634

Show system status shows CPU allocation is 3 when deployed with 2

CSCvt66319

Traffic stop sending across WAN when WAN link got unplugged and packet duplication is on :ISR1100-4G

CSCvs48327

ISR1100-4G, ISR1100-6G Fixed speed 100/10 full duplex config are not supported on RJ45 ports.

CSCvu36501

SDWAN 20.3 - 'ftmd' crash on vEdge100WM while activating/deactivating policy from vSmart.

CSCvs21315

Insecure Product Design exposes sensitive information to non-admin user.

CSCvv42576

Cisco SD-WAN vManage Cypher Query Language Injection Vulnerability

CSCvw08529

Cisco SD-WAN vManage Cypher Query Language Injection Vulnerability

CSCvs11276

Cisco SD-WAN vManage Information Disclosure Vulnerability

CSCvs99259

Cisco SD-WAN vManage SQL Injection Vulnerabilities

Open Bugs for Cisco SD-WAN Release 19.2.3

Table 8. Open Bugs for Cisco SD-WAN Release 19.2.3

Bug ID

Description

CSCvk78938

Upload of a corrupted serial file can lead to DOS situation

CSCvr89902

vEdge/vBond: default route is not installed in RIB even ARP is learnt and default GW is reachable

CSCvs76326

SDWAN 19.2.1: IPv6 vBond not reachable/UP from vManage when DNS name

CSCvt14398

edge device is not coming UP in vManage GUI, control connection is UP

CSCvt38373

vManage periodic cfgmgr crash

CSCvt63771

vManage generates 'Failed to create input variables' error after feature template edit

CSCvt94743

controller affinity making high CPU to 95% when we have 74k routes

CSCvu21309

BFD sessions flap after multiple control connection flaps to the vSmart.

CSCvu31137

CSR signed certificate fails when vManage configured with timezone America/Sao_Paulo with Cisco PKI

CSCvu35608

Disaster Recovery: Secondary vmanage cluster shows 200,000 vmanages instead of 3 on main dashboard

CSCvu44749

Cluster vManage running 18.4.3 - Messaging server went into waiting state with error corrupt index.

CSCvu44832

failover fails with a nullpointerexception with one vbond down

CSCvu47933

Software initiated - FP core watchdog fail after upgrade to 19.2.2 on vEdge1K

CSCvu54628

Arbitrator NullPointerException@getLocalDataCenterMemberDetails & up GUI status of isolated DC1/DC2

CSCvu58050

SSO broken on 19.2.2

CSCvu58459

A critical customer with 19.2.2, 4 vManage cluster is running into Full GC allocation failure

CSCvu63824

vedge 100 reboots due to vademon crash

CSCvu71411

IKE IPSec: Generate an error message, if strongSwan can't execute rekey CLI

CSCvu78023

" VPN Interface Ethernet PPPoE" template with QoS causing QoS appyied on Dialer's Physical Interface

CSCvu87254

vManage spends 60+ seconds to parse the device template with 500+ variables

CSCvu87957

19.2.2 template push failing for 16.10.2 Cisco IOS XE SD-WAN devices

CSCvu88512

QOS-vEdge2K : not getting desired throughput when sending traffic more than shaping-rate

CSCvu90767

Configuration-db hitting out-of-memory condition in particular scenario with certificates

CSCvu92540

The vManage with 19.2.2 code ran into full GC allocation failure, need RCA and possible fix date

CSCvs70534

vEdge(x86) IPSec+QoS Performance Optimization

CSCvv19652

vEdge crashes with dbgd failed message when running speed test

CSCvv22466

vE5k after upgrade to 19.2.3 isn't form control connections; doesn't able to resolve vBond URL

CSCvv24320

Multiples vEdges crashing with "Software initiated - Daemon 'ftmd' failed"

CSCvv18872

On the NSO of the Cisco vManage, the address of the vSmarts was set as 0.0.0.0

CSCvv22385

Cisco vManage GUI down due to GC Allocation Failure on 19.2.3

CSCvv31065

Unable to edit vbond config via CLI , when control connection breaks from vmanage.

CSCvv36080

Seeing more hVNETs than maximum allowed

CSCvx68246

Changing Config-DB ID/Password from default to non-default on a cluster of more than 3 members

Resolved and Open Bugs for Cisco SD-WAN Release 19.2.2

Resolved Bugs for Cisco SD-WAN Release 19.2.2

Table 9. Resolved Bugs for Cisco SD-WAN Release 19.2.2

Bug ID

Description

CSCvn80264

Certificate Expired Alarm for future date

CSCvq93325

Cloud vEdge crash on bfdmgr_update_sla_mapping

CSCvr20826

OMP Feature Template - advertise ipv6 for vEdge leads to Config Preview Fail

CSCvr39991

vEdge 1000 - FP crash with Zone Based Firewall and IRB config

CSCvr45260

The config on VBond rolls back when the configs are pushed through VManage CLI template

CSCvr51104

vManage cluster GUI SSO fails during the 2nd login attempt using old cookies

CSCvr52320

vEdge2K Crashed with resolvd failed

CSCvr59166

Upgrade from 18.4.1 to 19.2 breaks ip connectivity on TenGe interface in service-side vpn

CSCvr60544

Hardware edge cert (non-SUDI) issues with CSR containing "/" in CN using Enterprise CA

CSCvr60723

Multiple fp-um crashes seen on vEdge cloud on 18.3.5

CSCvr89892

vdaemon crashes after change csr vbond ip

CSCvs02513

vManage should not push "media-type rj45" when user configures speed or duplex

CSCvs08597

Template update pushing wrong interface with UTD NAT statement on Dialer interface

CSCvs14302

vEdge 5k on the 18.4.302 code stops forwarding packets over the 10 Gig interfaces

CSCvs16452

When setting up disaster recovery, multiple nodes in cluster are in bootstrap mode

CSCvs21703

VManage UI Unresponsive or very slow in 18.3.8; Full GC (Allocation Failure)

CSCvs24783

BGP neighbor commands are missing after upgrade from 19.2.0 to 19.2.099

CSCvs27051

idle-timeout is improperly mapped on Cisco XE SD-WAN devices

CSCvs37731

ftmd core observed with forwardingv4v6 regression runs on 19.3

CSCvs42587

Disaster Recovery: vbond registering with secondary vmanage cluster after recovering from failure

CSCvs54073

API call with CSRF token returning wrong content type in header (as JSON when actually plain text)

CSCvs56652

SD-WAN router may delete newly created SA in a specific case

CSCvs56739

template push fails for ipv6 BGP nbr w/ AF enabled on upgrade scenario from 19.2.098

CSCvs68356

vedge-cloud with NAT/cflowd, forwarding performance is degraded by 50%

CSCvs68498

vManage the user ip display the local link ip address in AUDIT LOG

CSCvs68860

vManage templates are NOT available on the Secondary cluster.

CSCvs70200

UL drops observed with packet size greater than 1396 while LTE perf test on ISR1100-4G/6G

CSCvs76815

vEdge - Inbound NAT inside IPsec tunnel not working

CSCvs76945

OMP feature template - Not able to select Advertise ipv6

CSCvs82091

request csr upload fails with lost connection

CSCvs91182

vManage is pushing additional slash '\' with the banner line breaker

CSCvt00521

idle-timeout is improperly mapped on XE-SDWAN

CSCvt06999

16.12.3 ZBFW:Control conn flap error shows up during template push

CSCvt09962

Disaster Recovery: Automatic failure not done when a vbond is down

CSCvt14754

Unable to push template on 19.2 vManage and 16.12 device

CSCvs93379

vManage config preview is timing out on large config.

CSCvt62324

TS/SS: Fail to push template and create admin log from UI. Failed to publish the task on message bus

CSCvs09893

AWS C5 instances of vmanage has very slow response and crashes with "hung_task"

Open Bugs for Cisco SD-WAN Release 19.2.2

Table 10. Open Bugs for Cisco SD-WAN Release 19.2.2

Bug ID

Description

CSCvr35741

DPI statistics database configuration memory increase

CSCvr52733

vedge frequently establishing control connections to the vBond even though it is in equilibrium

CSCvs39434

vManage/vSmart system status(CPU/Memory) stuck at Zero percent

CSCvs42048

vmanage site list built through GUI not respecting syntax

CSCvs45964

Latitude/Longitude inconsistent value in vManage UI 19.2

CSCvs49176

vEdge VRRP fail to receive unit cast traffic over i40evf

CSCvs64187

vManage real time is not pulling more than 4k entries

CSCvs67750

The DR replication is not working when the secondary cluster takes over as primary cluster

CSCvs67769

Can not create vManage user to access disaster recovery other than admin user

CSCvs68870

Deleting vManage Disaster Recovery should not remove the software image from the software repository

CSCvs68879

Alarms/events are NOT replicated to the secondary vManage cluster

CSCvs70746

[Azure] vmanage rebooted on 19.3 with Software initiated - Kernel Panic

CSCvs70961

vmanage gui not accessible as /opt/data is 100% full. App server down

CSCvs71811

Vmanage goes OOM after upgrade to 19.2.1 java.lang.OutOfMemoryError: Java heap space

CSCvs76326

SDWAN 19.2.1: IPv6 vBond not reachable/UP from vManage when DNS name

CSCvs94771

19.2.1 template push failing for 16.10.2 Cisco XE SD-WAN devices

CSCvs95548

vedge-cloud with 19.2.1, 10GE interface on x520 adapter does not work after link is flapped

CSCvs96756

Cloud multi-tenant EMS images not visible on repository after migration from 18.3.x to 19.2.1

CSCvt25691

vManage reloads with reason: Daemon 'cfgmgr' failed

CSCvt31109

OMP advertises aggregate route with components from RIB even if "no advertise <protocol>" configured

CSCvt64600

Top applications UI : Y axis (usage) not shown properly

CSCvt66337

Shaping rate in ISR1100-4G not working properly for TCP traffic

CSCvt95983

vEdge Cloud: vEdge on Azure may go into a bootloop state after an upgrade from 18.4.302 to 19.2.2

CSCvs83533

Vedge 1k running 19.2.1 constantly reboots with the reason "USB controller disabled or enabled"

Resolved and Open Bugs for Cisco SD-WAN Release 19.2.1

Resolved Bugs for Cisco SD-WAN Release 19.2.1

Table 11. Resolved Bugs for Cisco SD-WAN Release 19.2.1

Bug ID

Description

CSCvk79895

callin keyword issues for feature template for dialer interfaces

CSCvr35176

Device is crashing constantly when TCP optimization is enabled.

CSCvr45260

The config on VBond rolls back when the configs are pushed through VManage CLI template

CSCvr51104

vManage cluster GUI SSO fails during the 2nd login attempt using old cookies

CSCvr84372

VPN0 interface won't come up on vbond KVM instance on RHEL7.5

CSCvs07507

vManage config preview is timing out when we have a large policy with more than 750 sequences

CSCvs08871

vManage 19.2.099 shows Invalid value if GPS Lat/Long is float

CSCvs14302

vEdge 5k on the 18.4.302 code stops forwarding packets over the 10 Gig interfaces

CSCvs16700

vEdge iPerf speed test -r option is not working as expected

CSCvs24783

BGP neighbor commands are missing after upgrade from 19.2.0 to 19.2.099

CSCvs46366

DNS configurations are not pushed to the XE-SDWAN device properly

CSCvp21016

vEdge FTMD crash

CSCvp83386

- /var/crash/kernel_panic is empty - show reboot history says "Software initiated - Kernel Panic"

CSCvq75021

vEdge 2000 - ZBFW counters stuck after stress tests

CSCvr12422

vEdge5K does not forward all fragments on service side

CSCvn52516

Guest OS type for vNIC Adapter Type to Deploy Controllers in VMWARE

CSCvr00012

vEdge100b appears to be leaking memory in sysmgrd

CSCvn53200

vrrp virtual ip not able to ping from host on ESXI vedge x86 with E1000, vmxnet3 interface I/O

Open Bugs for Cisco SD-WAN Release 19.2.1

Table 12. Open Bugs for Cisco SD-WAN Release 19.2.1

Caveat ID Number

Description

CSCvp68729

ISR1100-6G, vedge-5000 Copper SFP OIR is not working.

CSCvr35176

Device is crashing constantly when TCP optimization is enabled.

CSCvr52680

Stale vManage certs present on the vManage after we factory reset it and install a new cert

CSCvr52733

vedge frequently establishing control connections to the vBond even though it is in equilibrium

CSCvr82826

Status: Success should only be posted after the task has run to completion.

CSCvr84372

VPN0 interface won't come up on vbond KVM instance on RHEL7.5

CSCvs08748

VRRP issue on vEdge 5k for 10G physical interface on 18.4.302 and 19.2.097.

CSCvs16700

vEdge iPerf speed test -r option is not working as expected

CSCvs26265

Data collection is slow on vManage after enabling vAnalytics on 19.2.097

CSCvs45964

Latitude/Longitude inconsistent value in vManage UI 19.2

CSCvs48327

ISR1100-4G, ISR1100-6G Fixed speed 100/10 full duplex config are not supported on RJ45 ports.

CSCvs49176

vEdge VRRP fail to receive unit cast traffic over i40evf

CSCvs56739

template push fails for ipv6 BGP nbr w/ AF enabled on upgrade scenario

CSCvs94771

19.2.1 template push failing for 16.10.2 Cisco XE SD-WAN devices

Resolved Bugs for Cisco SD-WAN Release 19.2.099

Table 13. Resolved Bugs for Cisco SD-WAN Release 19.2.099

Bug ID

Description

CSCvp96887

Failed to attach template to Cisco XE SDWAN Rtr if qos-map name changed after policy-map is attached

CSCvq10160

Cellular IP is getting reset when primary transport interface Gi0/0/0 is shutdown.

CSCvq61835

interface cant be moved from vrf 0 to service vrf when it has ip address

CSCvq70071

flow data is not populated into /tmp/xml/fnf

CSCvq97954

Cellular interface doesn't get an IP address when brought up through the pnp workflow

CSCvr13244

19.2.0 regression: Can not configure NTP on SD-WAN and specify source interface in VPN

CSCvr15012

fman-fp keeps on crashing after attach app-route policy with app-family

CSCvr18082

xe-sdwan omp aggregate-only does not suppress component routes sometimes

CSCvr35568

CPP crash with Packet Duplication enabled on path failover with XE SDWAN router

CSCvr52767

microloops because of redistribution OMP<>OSPF external with DN-bit are happening on IOS-XE SD-WAN

CSCvk79895

callin keyword issues for feature template for dialer interfaces

CSCvn02180

confd died on upgrading from 18.3.X to 18.4 on 100b

CSCvp13833

snmp-server trap-source configuration is not generated for Cisco XE SD-WAN Router by vManage

CSCvp69688

'tcp adjust-mss' mapping fails for XE SDWAN router on service-side IPSec template

CSCvp92554

duplex mode shows half duplex while setting "no autonegotiate"

CSCvq26184

Enhancement for Vmanage Config Diff feature to work correctly on xe-sdwan CLI Templates.

CSCvq45303

remove tloc-list or export-to from control policy removes tloc-list or export-to from other sequence

CSCvq46947

vedge directed-broadcast should forward as 255.255.255.255 to match xe-sdwan and cisco behavior

CSCvq67476

ikev2 dpd retransmit always 1s and fails after one retry with "giving up after 1 retransmits"

CSCvq93904

With disaster recovery paused vmanage does not allow controllers to be upgraded from GUI

CSCvq95995

Getsockopt errors on vmanage console after upgrading vmanage cluster to 19.2.0

CSCvq97724

vAnalytics - Launch vanalytics not working in vmanage UI

CSCvq99226

Static NAT Optional Setting does not persist

CSCvr13605

API Try it out option on the Swagger UI(/apidocs) is stuck on 19.2 vmanage

CSCvr15242

omp routes redistributed into ospf are advertised back into omp causing a routing loop

CSCvr19231

vEdge is using ip addresses outside of the natpool range

CSCvr19249

vEdge performs NAT translation to public source port 0 or overlaps ports when all ports exhausted

CSCvr22812

Vmanage pushes incorrect config for xe-sdwan DNS under management vrf (vpn 512)

CSCvr30029

Cisco XE SD-WAN device configures IPv6 BGP neighbor under both IPv4 and IPv6 address-family

CSCvr40290

Unable to push CLI template from the vManage when the NTP source interface is configured.

CSCvr41975

CLI template based BGP configuration does not work with update-source interface

CSCvr45907

IPSEC tunnel source IP is not updated when WAN IP changes.

CSCvr20753

Fix handling of leading 0's in Cisco XE SD-WAN device certificate serial numbers

CSCvm84963

Zscaler tunnel failure when NAT selects public port 0

Resolved Bugs for Cisco SD-WAN Release 19.2.097

Table 14. Resolved Bugs for Cisco SD-WAN Release 19.2.097

Bug ID

Description

CSCvn24727

Large number of out-of-order packets seen with vEdge5k and vEdge-Cloud

CSCvq09767

core fp-um crash on vEdgecloud running 18.3.5. fp_hw_x86_pkt_remove_header

CSCvq12913

vEdge1000 crashed even after applying the 18.4.101 ES image

Resolved and Open Bugs for Cisco SD-WAN Release 19.2.0

Resolved Bugs for Cisco SD-WAN Release 19.2.0

Table 15. Resolved Bugs for Cisco SD-WAN Release 19.2.0

Bug ID

Description

CSCvm97332

config commit operation fails on ISRv on 5406 with error ext2_lookup:deleted inode referenced

CSCvn76615

source-interface mapping is missing in vmanage for tacacs and radius server group.

CSCvo03831

Unable to load Device->Template page

CSCvo68578

vManage export CSV file of feature templates(not CLI templates) with 2+ devices reordering values

CSCvo69041

SVM: server config file is empty

CSCvp13167

vEdge5000: control connection stuck in "Challenge" phase with TPM lockup

CSCvp44069

"ip address negotiated" configuration is not being pushed from a vManage running the 19.1.0 code

CSCvp44488

vManage: VPN Interface Ethernet template is not accepting 10ge as interface name

CSCvp70217

SVM: NMS app-server fails to start

CSCvp75433

Email notification - host name shows as N/A for all alerts, but alarm has the hostname.

CSCvp82758

Edit vmanage from local host to ip before cluster addition failing

CSCvp96612

snmp traps on vedge not egressing out of the snmp source interface configured

CSCvq54726

continuous nat-pool exhausted failure leads to map-db leak

CSCvp30369

NAT translation is not happening for return traffic

CSCvp60289

ftmd process crash on vEdge router

CSCvi59632

Cisco SD-WAN vManage Software Path Traversal Vulnerability

CSCvi59726

Cisco SD-WAN vManage SQL Injection Vulnerabilities

CSCvi69962

Cisco SD-WAN Information Disclosure Vulnerability

CSCvk28549

Cisco SD-WAN vManage Software Path Traversal Vulnerability

CSCvk28609

Cisco SD-WAN vManage SQL Injection Vulnerabilities

CSCvk28656

Cisco SD-WAN vManage SQL Injection Vulnerabilities

CSCvk28667

Cisco SD-WAN vManage SQL Injection Vulnerabilities

Open Bugs for Cisco SD-WAN Release 19.2.0

Table 16. Open Bugs for Cisco SD-WAN Release 19.2.0

Bug ID

Description

CSCvn24727

Large number of out-of-order packets seen with vEdge5k and vEdge-Cloud

CSCvo12826

Setting "Collect admin-tech on reboot" to On in System Feature template does not work for Cisco XE SD-WAN devices

CSCvp12510

TAIL-F: Passwords more than 32 characters in length fail when doing push from vManage (CSCvo93386)

CSCvp71933

DR: drconsul process failed to start on one vmanage in secondary cluster

CSCvq48367

Traffic does not resume after we change speed on SFP Interfaces.

CSCvq49247

line vty config getting changed to transport input none after loading from ciscosdwan.cfg

CSCvq52992

after device reboot from vmanage, vsmart boots up to shell prompt

CSCvq56780

Cisco XE SD-WAN ISR system-report files under bootflash/core need to picked up in admin-tech-from-vmanage

CSCvq68947

Prefix lists from aci not updated due to template lock

CSCvs30171

Enterprise Certs lost when upgraded from 18.4.302 to 19.2.099

CSCvv42937

No date and time info in the syslog payload