
627
Caveats for Cisco IOS Release 12.2(33)SRD through 12.2(33)SRD8
OL-10394-05 Rev. R0
vpn id xxx
forward permit l2protocol all
Workaround: Reload the router. If this does not help, reduce the number of possible core-facing
MPLS interfaces that the VPLS pseudowire could possibly take.
• CSCsy01763
Symptoms: Packets leak from source to destination when PACL is configured and switchover is not
complete.
Conditions: During switchover, and until TCAM is programmed, packets are L3 switched even if
the PACL will drop them further. Also, when the PACL is changed, such as addition or removal of
ACEs, some packets which are supposed to be dropped will leak to the destination.
Workaround: There is no workaround.
• CSCsy04594
Symptoms: When a Cisco 7600 is connected to a different MST region and has a port with root guard
configured on the MST boundary port, all VLAN interfaces flap each time a superior BPDU is
received on this port. This behavior was observed with Cisco IOS Release 12.2(33)SRB4 and Cisco
IOS Release 12.2(18)SXF14.
Conditions: It was observed in the following context:
1) The switch is connected to a different MST region 2) It has a port configured as root guard on
MST region boundary
Workaround: Shut down blocked port or remove root guard configuration from the port and the
VLAN interfaces stop flapping.
• CSCsy07555
Cisco IOS devices that are configured for Internet Key Exchange (IKE) protocol and certificate
based authentication are vulnerable to a resource exhaustion attack. Successful exploitation of this
vulnerability may result in the allocation of all available Phase 1 security associations (SA) and
prevent the establishment of new IPsec sessions.
Cisco has released free software updates that address this vulnerability.
This advisory is posted at http://www.cisco.com/warp/public/707/cisco-sa-20090923-ipsec.shtml
• CSCsy07830
Symptoms: All traffic through ES line cards stops after a RSP failover. The line cards fail
diagnostics and never recover.
Conditions: Occurs periodically when a redundancy force-switchover is executed on a router
containing multiple RSPs and ES line cards.
Workaround: Reload the router.
• CSCsy08264
Symptoms: MQC policy applied on ES+ interface may not work as expected. Occurs if too many
unique bandwidth rates are configured and applied on same line card and on the interfaces belonging
to same Network Processor.
Conditions: If more than 32 unique bandwidth rates are (defined in policy maps applied on same
NP) configured, the policy map is accepted without error but may not work as intended.
Workaround: If multiple unique bandwidth rates are required, space the policy maps across
interfaces based on different network processors.
• CSCsy10610
Komentáře k této Příručce