Release Notes for Cisco Catalyst 9200 Series Switches, Cisco IOS XE Amsterdam 17.1.x
Introduction
Cisco Catalyst 9200 Series Switches are entry level enterprise-class access switches that extend the power of intent-based networking and Cisco Catalyst 9000 Series Switches hardware and software innovation to a broader scale of deployments. These switches focus on offering features for the mid-market and simple branchdeployments. With its family pedigree, Cisco Catalyst 9200 Series Switches offer simplicity without compromise - it is secure, always on and provides IT simplicity.
As a foundational building block for Cisco Digital Network Architecture, this platform is built with security, mobility, cloud and IoT at its core. This gives you out of the box upgrades in security, resiliency and programmability regardless of where you are in the intent-based networking journey.
With access to Cisco’s best in class security portfolio anchored trustworthy solutions, MACsec encryption and segmentation, the platform provides advanced security features that protect the integrity of the hardware as well as the software and all data that flows through the switch and the network. These switches provide enterprise-level resiliency and keep your business up and running seamlessly with field-replaceable power supplies and fans, modular uplinks, cold patching, perpetual PoE, and the industry’s highest mean time between failures (MTBF). Combine the application visibility of full flexible NetFlow with telemetry and the open APIs of Cisco IOS XE and programmability of the UADP ASIC technology and these switches give you the best simple experience provisioning and managing your network now with investment protection on future innovations.
Whats New in Cisco IOS XE Amsterdam 17.1.1
Hardware Features in Cisco IOS XE Amsterdam 17.1.1
|
Feature Name |
Description and Documentation Link |
|---|---|
|
Cisco Catalyst 9200 Series Switches (C9200 Multigigabit Ethernet models) |
These new Multigigabit Ethernet models are introduced:
For more information about these models, see the Cisco Catalyst 9200 Series Switches Hardware Installation Guide. |
|
Cisco Catalyst 9200 Series Switches—Network Modules |
The following uplink network modules are available with the C9200 SKUs:
For information about the hardware, see the Cisco Catalyst 9200 Series Switches Hardware Installation Guide. |
Software Features in Cisco IOS XE Amsterdam 17.1.1
|
Feature Name |
Description, Documentation Link, and License Level Information |
|---|---|
|
Cisco Umbrella Integration |
Provides security and policy enforcement at the Domain Name Sever (DNS) level. It enables the administrator to split the DNS traffic and directly send some of the desired DNS traffic to a specific DNS server (DNS server located within the enterprise network).
See Security → Configuring Cisco Umbrella Integration.
(Network Advantage) |
|
Flash MIB instance retrieval count limit increase |
The limitation of Flash MIB listing 100 files per partition per device has been removed. Flash MIB can now fetch all the files from the flash file system.
See Network Management → Configuring Simple Network Management Protocol.
(Network Essentials and Network Advantage) |
|
Neighbor Discovery (ND) Inspection Feature Deprecation |
The IPv6 ND Inspection feature is deprecated. The Switch Integrated Security Features based (SISF-based) device tracking feature replaces it and offers the same capabilities.
See Security → Configuring IPv6 First Hop Security.
(Network Essentials and Network Advantage) |
|
Opening or Closing SNMP UDP Ports |
A security enhancement that enables you to access the Simple Network Management Protocol (SNMP) UDP ports only after one of the requisite commands is configured. This design change secures and opens the ports only when required and prevents a device from listening to a port unnecessarily.
See Network Management → Configuring Simple Network Management Protocol.
(Network Essentials and Network Advantage) |
|
Per-Port MTU Configuration |
Introduces support for port level and port channel level maximum transmission unit (MTU) configuration. With Per-Port MTU configuration, you can configure different MTU values for different interfaces as well as for different port channel interfaces.
See Interface and Hardware Components → Configuring Per-Port MTU.
(Network Essentials and Network Advantage) |
|
Programmability |
The following programmability features are introduced in this release:
See Programmability.
(Network Essentials and Network Advantage) |
|
New on the Web UI |
|
|
Use the WebUI for:
|
Important Notes
Unsupported Features
-
Audio Video Bridging (including IEEE802.1AS, IEEE 802.1Qat, and IEEE 802.1Qav)
-
Border Gateway Protocol (BGP) including BGP EVPN VXLAN.
-
Cisco StackWise Virtual
-
Cisco TrustSec Network Device Admission Control (NDAC) on Uplinks
-
Converged Access for Branch Deployments
-
Fabric Enabled Wireless on C9200L SKUs
-
Gateway Load Balancing Protocol (GLBP)
-
Hot patching (for SMUs)
-
IPsec VPN
-
MACSec Encryption
-
MACsec configuration on EtherChannel
-
256-bit AES MACsec (IEEE 802.1AE) host link encryption with MACsec Key Agreement (MKA)
-
-
Multiprotocol Label Switching (MPLS)
-
Non Stop Forwarding (NSF)
-
Performance Monitoring (PerfMon)
-
Programmability (Cisco Plug-in for OpenFlow 1.3, Third-Party Application Hosting)
-
Virtual Routing and Forwarding (VRF)-Aware web authentication
-
Web Cache Communication Protocol (WCCP)
Complete List of Supported Features
For the complete list of features supported on a platform, see the Cisco Feature Navigator at https://www.cisco.com/go/cfn.
Default Behaviour
Beginning from Cisco IOS XE Gibraltar 16.12.5 and later, do not fragment bit (DF bit) in the IP packet is always set to 0 for all outgoing RADIUS packets (packets that originate from the device towards the RADIUS server).
Supported Hardware
Cisco Catalyst 9200 Series Switches—Model Numbers
The following table lists the supported hardware models and the default license levels they are delivered with. For information about the available license levels, see section License Levels.
|
Switch Model |
Default License Level |
Description |
|---|
Network Modules
The following table lists the optional uplink network modules with 1-GigabitEthernet and 10-GigabitEthernet slots. You should only operate the switch with either a network module or a blank module installed.
|
Network Module |
Description |
|---|---|
|
C9200-NM-4G 1 |
Four 1-GigabitEthernet SFP module slots |
|
C9200-NM-4X 1 |
Four 10-GigabitEthernet SFP+ module slots |
|
C9200-NM-2Y2 |
Two 25-GigabitEthernet SFP28 module slots |
|
C9200-NM-2Q2 |
Two 40-GigabitEthernet slots with a QSFP+ connector in each slot |
![]() Note |
These network modules are supported only on the C9200 SKUs of the Cisco Catalyst 9200 Series Switches. |
Optics Modules
Cisco Catalyst Series Switches support a wide range of optics and the list of supported optics is updated on a regular basis. Use the Transceiver Module Group (TMG) Compatibility Matrix tool, or consult the tables at this URL for the latest transceiver module compatibility information: https://www.cisco.com/en/US/products/hw/modules/ps5455/products_device_support_tables_list.html
Compatibility Matrix
To view the software compatibility information between Cisco Catalyst 9200 Series Switches, Cisco Identity Services Engine, and Cisco Prime Infrastructure, go to Cisco Catalyst 9000 Series Switches Software Version Compatibility Matrix.
Web UI System Requirements
The following subsections list the hardware and software required to access the Web UI:
Minimum Hardware Requirements
|
Processor Speed |
DRAM |
Number of Colors |
Resolution |
Font Size |
|---|---|---|---|---|
|
233 MHz minimum1 |
512 MB2 |
256 |
1280 x 800 or higher |
Small |
Software Requirements
Operating Systems
-
Windows 10 or later
-
Mac OS X 10.9.5 or later
Browsers
-
Google Chrome—Version 59 or later (On Windows and Mac)
-
Microsoft Edge
-
Mozilla Firefox—Version 54 or later (On Windows and Mac)
-
Safari—Version 10 or later (On Mac)
Boot Loader Versions
The following table provides boot loader version information for the Cisco Catalyst 9200 Series Switches.
|
Release |
ROMMON Version |
|---|---|
|
Amsterdam 17.1.1 |
17.1.1 [FC3] |
Upgrading the Switch Software
This section covers the various aspects of upgrading or downgrading the device software.
![]() Note |
You cannot use the Web UI to install, upgrade, or downgrade device software. |
Finding the Software Version
The package files for the Cisco IOS XE software are stored on the system board flash device (flash:).
You can use the show version privileged EXEC command to see the software version that is running on your switch.
![]() Note |
Although the show version output always shows the software image running on the switch, the model name shown at the end of this display is the factory configuration and does not change if you upgrade the software license. |
You can also use the dir filesystem: privileged EXEC command to see the directory names of other software images that you might have stored in flash memory.
Software Images
|
Release |
Image Type |
File Name |
|---|---|---|
|
Cisco IOS XE Amsterdam 17.1.1 |
CAT9K_LITE_IOSXE |
cat9k_lite_iosxe.17.01.01.SPA.bin |
Automatic Boot Loader Upgrade
When you upgrade from the existing release on your switch to a later or newer release for the first time, the boot loader may be automatically upgraded, based on the hardware version of the switch. If the boot loader is automatically upgraded, it will take effect on the next reload. If you go back to the older release after this, the boot loader is not downgraded. The updated boot loader supports all previous releases.
![]() Caution |
Do not power cycle your switch during the upgrade. |
Software Installation Commands
|
Summary of Software Installation Commands |
|
|---|---|
|
To install and activate the specified file, and to commit changes to be persistent across reloads:
To separately install, activate, commit, cancel, or remove the installation file: |
|
|
add file tftp: filename |
Copies the install file package from a remote location to the device and performs a compatibility check for the platform and image versions. |
|
activate [ auto-abort-timer] |
Activates the file, and reloads the device. The auto-abort-timer keyword automatically rolls back image activation. |
|
commit |
Makes changes persistent over reloads. |
|
rollback to committed |
Rolls back the update to the last committed version. |
|
abort |
Cancels file activation, and rolls back to the version that was running before the current installation procedure started. |
|
remove |
Deletes all unused and inactive software installation files. |
Upgrading in Install Mode
Follow these instructions to upgrade from one release to another, in install mode. To perform a software image upgrade, you must be booted into IOS through boot flash:packages.conf .
Before you begin
Note that you can use this procedure for the following upgrade scenarios:
|
When upgrading from ... |
To... |
|---|---|
|
Cisco IOS XE Gibraltar 16.12.1 and later |
Cisco IOS XE Amsterdam 17.1.1 |
The sample output in this section displays upgrade from Cisco IOS XE Gibraltar 16.12.1 to Cisco IOS XE Amsterdam 17.1.1 using install commands.
Procedure
|
Step 1 |
Clean Up |
|
Step 2 |
Copy new image to flash |
|
Step 3 |
Set boot variable |
|
Step 4 |
Software install image to flash |
|
Step 5 |
Reload |
Downgrading in Install Mode
Follow these instructions to downgrade from one release to another, in install mode. To perform a software image downgrade, you must be booted into IOS through boot flash:packages.conf .
Before you begin
Note that you can use this procedure for the following downgrade scenarios:
|
When downgrading from ... |
To ... |
|---|---|
|
Cisco IOS XE Amsterdam 17.1.1 |
Cisco IOS XE Gibraltar 16.12.1 or earlier releases. |
The sample output in this section shows downgrade from Cisco IOS XE Amsterdam 17.1.1 to Cisco IOS XE Gibraltar 16.12.1, using install commands.
![]() Important |
New switch models that are introduced in a release cannot be downgraded. The release in which a module is introduced is the minimum software version for that model. We recommend upgrading all existing hardware to the same release as the latest hardware. |
Procedure
|
Step 1 |
Clean Up |
||
|
Step 2 |
Copy new image to flash |
||
|
Step 3 |
Downgrade software image
The following example displays the installation of the Cisco IOS XE Gibraltar 16.12.1 software image to flash, by using the install add file activate commit command. You can point to the source image on your tftp server or in flash if you have it copied to flash.
|
||
|
Step 4 |
Reload |
Licensing
For information about licenses required for the features available on Cisco Catalyst 9000 Series Switches, see Configuring Licenses on Cisco Catalyst 9000 Series Switches.
All licensing information relating to Cisco Catalyst 9000 Series Switches are available on this collection page: Cisco Catalyst 9000 Switching Family Licensing.
Available Licensing Models and Configuration Information
-
Cisco IOS XE Fuji 16.9.2 to Cisco IOS XE Amsterdam 17.3.1: Smart Licensing is the default and the only supported method to manage licenses.
-
Cisco IOS XE Amsterdam 17.3.2a and later: Smart Licensing Using Policy, which is an enhanced version of Smart Licensing, is the default and the only supported method to manage licenses.
Scaling Guidelines
For information about feature scaling guidelines, see the Cisco Catalyst 9200 Series Switches datasheet at:
Limitations and Restrictions
-
Control Plane Policing (CoPP)—The show run command does not display information about classes configured under
system-cpp policy, when they are left at default values. Use the show policy-map system-cpp-policy or the show policy-map control-plane commands in privileged EXEC mode instead. -
Hardware limitations
-
Management Port—You cannot modify the configured port speed, duplex mode and flow control and disable auto-negotiation on the Ethernet Management port (GigabitEthernet0/0). Port speed and duplex mode can only be changed from a peer port.
-
Network Module — When the C9200-NM-4X network module is plugged into the C9200 SKUs of the Cisco Catalyst 9200 Series Switches, the downlink interface remains in down state until the network module is recognized by the switch. The time taken for the switch to recognize the network module is longer in comparison to the time taken by the switch to recognize other interconnected devices.
-
If the 1-meter and 1.5-meter 10-GBase-CX1 cables, which are connected on the 10-G ports of the Catalyst 9200L switches, are connected to the 10-G peer ports of the Catalyst 9200L or Catalyst 9200 switches, the peer device might go into the error-disabled state because of link flapping if the local device is restarted. As a workaround, run the shut and no shut commands on the error-disabled peer interfaces.
-
-
QoS restrictions
-
When configuring QoS queuing policy, the sum of the queuing buffer should not exceed 100%.
-
For QoS policies, only switched virtual interfaces (SVI) are supported for logical interfaces.
-
QoS policies are not supported for port-channel interfaces, tunnel interfaces, and other logical interfaces.
-
-
Secure Shell (SSH)
-
Use SSH Version 2. SSH Version 1 is not supported.
-
When the device is running SCP and SSH cryptographic operations, expect high CPU until the SCP read process is completed. SCP supports file transfers between hosts on a network and uses SSH for the transfer.
Since SCP and SSH operations are currently not supported on the hardware crypto engine, running encryption and decryption process in software causes high CPU. The SCP and SSH processes can show as much as 40 or 50 percent CPU usage, but they do not cause the device to shutdown.
-
-
Stacking
-
Stacking is supported on Cisco Catalyst 9200 Series Switches; A switch stack supports up to eight stack members. However, you cannot stack C9200 SKUs with C9200L SKUs
The supported stacking bandwidth on C9200L SKUs is up to 80Gbps; on C9200 SKUs, this is up to 160Gbps.
-
Auto upgrade for a new member switch is supported only in the install mode.
-
-
TACACS legacy command: Do not configure the legacy tacacs-server host command; this command is deprecated. If the software version running on your device is Cisco IOS XE Gibraltar 16.12.2 or a later release, using the legacy command can cause authentication failures. Use the tacacs server command in global configuration mode.
-
USB Authentication—When you connect a Cisco USB drive to the switch, the switch tries to authenticate the drive against an existing encrypted preshared key. Since the USB drive does not send a key for authentication, the following message is displayed on the console when you enter password encryption aes command:
Device(config)# password encryption aes Master key change notification called without new or old key -
VLAN Restriction—It is advisable to have well-defined segregation while defining data and voice domain during switch configuration and to maintain a data VLAN different from voice VLAN across the switch stack. If the same VLAN is configured for data and voice domains on an interface, the resulting high CPU utilization might affect the device.
-
YANG data modeling limitation—A maximum of 20 simultaneous NETCONF sessions are supported.
-
Embedded Event Manager—Identity event detector is not supported on Embedded Event Manager.
-
Upgrading the software image from Cisco IOS XE Gibraltar 16.12.x to any of the later releases can result in a persistent database operation failure and after which the persistent database cannot be restored.
To avoid the persistent database operation failure, use the dir bootflash:.dbpersist command to list all DB persist files and then use the delete bootflash:/.dbpersist/folder_name/file_name and bootflash:/.dbpersist/folder_name/file_name.meta command to delete individual database and meta files from each persistent database folder.
-
The File System Check (fsck) utility is not supported in install mode.
-
Switch Web UI allows configuration of data VLANs only and not voice VLANs. If you remove a voice VLAN configured to an interface using the Web UI, then all data VLANs associated with the interface are also removed by default.
Caveats
Caveats describe unexpected behavior in Cisco IOS-XE releases. Caveats listed as open in a prior release are carried forward to the next release as either open or resolved.
Open Caveats in Cisco IOS XE Amsterdam 17.1.x
|
Identifier |
Description |
|---|---|
|
Private-vlan mapping XXX configuration under SVI is lost from run config after switch reload |
|
|
C9200L kernel Oops jumbo packets |
|
|
Cat9300 crash on running show platform software fed switch 1 fss abstraction |
|
|
EPC with packet-len opt breaks CPU in-band path for bigger frames |
|
|
STP BPDUs not being sent from FED to IOSd |
|
|
After valid ip conflict, SVI admin down responds to GARP |
|
|
SPANed multicast packet reduced TTL |
|
|
802.1x-MultiAuth/MultiDomain: C9K - Traffic drop in egress direction for Data-Vlan on a Auth port |
Resolved Caveats in Cisco IOS XE Amsterdam 17.1.1
|
Identifier |
Description |
|---|---|
|
Enabling SPAN source of VLAN 1 affects LACP operations |
|
|
%CRB_EVENT-3-CRB_RT_ERROR: CRB Runtime Exception: attempted negative int -> ptr cast (0xCBE0D3A4) |
|
|
RX traffic get stuck on of interface phy ASIC |
|
|
SYS-2-BADSHARE: Bad refcount in datagram_done - messages seen during system churn |
|
|
Mac address not being learnt when "auth port-control auto" command is present |
|
|
C9200 stack member switches reset with reset reason as stack merge |
|
|
C9200 interface comes up in half-duplex mode even if interface is forced to "duplex full" |
|
|
input error of uplink ports are increasing slowly even if disconnecting cable and SFP. |
|
|
Multicast stream flickers on igmp join/leave |
|
|
system crash on execute "fed TCAM utilization" |
|
|
C9200 stack breaks and subsequent merge fails |
|
|
ports remain down/down object-manager (fed-ots-mo thread is stuck) |
|
|
17.1.1 c9200: FEW: access tunnel scale limitation |
Cisco Bug Search Tool
The Cisco Bug Search Tool (BST) allows partners and customers to search for software bugs based on product, release, and keyword, and aggregates key data such as bug details, product, and version. The BST is designed to improve the effectiveness in network risk management and device troubleshooting. The tool has a provision to filter bugs based on credentials to provide external and internal bug views for the search input.
To view the details of a caveat, click on the identifier.
Troubleshooting
For the most up-to-date, detailed troubleshooting information, see the Cisco TAC website at this URL:
https://www.cisco.com/en/US/support/index.html
Go to Product Support and select your product from the list or enter the name of your product. Look under Troubleshoot and Alerts, to find information for the problem that you are experiencing.
Related Documentation
Information about Cisco IOS XE at this URL: https://www.cisco.com/c/en/us/products/ios-nx-os-software/ios-xe/index.html
All support documentation for Cisco Catalyst 9200 Series Switches is at this URL: https://www.cisco.com/c/en/us/support/switches/catalyst-9200-r-series-switches/tsd-products-support-series-home.html
Cisco Validated Designs documents at this URL: https://www.cisco.com/go/designzone
To locate and download MIBs for selected platforms, Cisco IOS releases, and feature sets, use Cisco MIB Locator found at the following URL: https://cfnng.cisco.com/mibs
Communications, Services, and Additional Information
-
To receive timely, relevant information from Cisco, sign up at Cisco Profile Manager.
-
To get the business results you’re looking for with the technologies that matter, visit Cisco Services.
-
To submit a service request, visit Cisco Support.
-
To discover and browse secure, validated enterprise-class apps, products, solutions and services, visit Cisco DevNet.
-
To obtain general networking, training, and certification titles, visit Cisco Press.
-
To find warranty information for a specific product or product family, access Cisco Warranty Finder.
Cisco Bug Search Tool
Cisco Bug Search Tool (BST) is a web-based tool that acts as a gateway to the Cisco bug tracking system that maintains a comprehensive list of defects and vulnerabilities in Cisco products and software. BST provides you with detailed defect information about your products and software.


Feedback