Cisco Aci NX Os Release Notes 1608
Cisco Aci NX Os Release Notes 1608
This release works only on Cisco Nexus 9000 Series switches in ACI mode.
This document describes the features, issues, and limitations for the Cisco NX-OS software. For the features,
issues, and limitations for the Cisco Application Policy Infrastructure Controller (APIC), see the Cisco Application
Policy Infrastructure Controller Release Notes, Release 6.0(8).
Date Description
Supported Hardware
Table 1. Modular Spine Switches
Product ID Description
N9K-C9408 Cisco Nexus 9408 modular chassis switch with up to 128 200/100-Gigabit (256 100-Gigabit
by 200G-to-2x100G breakout) ports using N9K-X9400-16W or 64 400/200/100-Gigabit (256
100-Gigabit by 400G-to-4x100G breakout) ports using N9K-X9400-8D.
N9K-C9508-B1 Cisco Nexus 9508 chassis bundle with 1 supervisor module, 3 power supplies, 2 system
controllers, 3 fan trays, and 3 fabric modules
N9K-C9508-B2 Cisco Nexus 9508 chassis bundle with 1 supervisor module, 3 power supplies, 2 system
controllers, 3 fan trays, and 6 fabric modules
N9K-X9400-8D Cisco Nexus 9400 8-port 400 Gigabit QSFP- 8 N/A N/A N/A
DD linecard expansion module
N9K-X9400-16W Cisco Nexus 9400 16-port 200 Gigabit linecard 8 N/A N/A N/A
N9K-C9504-FM-G Cisco Nexus 9508 cloud scale fabric module (400G capable) 4 5
N9K-C9508-FM-G Cisco Nexus 9508 cloud scale fabric module (400G capable) 4 5
Product ID Description
Product ID Description
Product ID Description
N9K-C9364D-GX2A Cisco Nexus 9300 platform switch with 64 400/100-Gigabit QSFP-DD ports and 2 1/10 SFP+
ports.
N9K-C9348D-GX2A Cisco Nexus 9300 platform switch with 48 400/100-Gigabit QSFP-DD ports and 2 1/10 SFP+
ports.
N9K-C9332D-GX2B Cisco Nexus 9300 platform switch with 32p 400/100-Gigabit QSFP-DD ports and 2p 1/10
SFP+ ports.
N9K-C93600CD-GX Cisco Nexus 9300 platform switch with 28 10/40/100-Gigabit Ethernet QSFP28 ports (ports
1-28) and 8 10/40/100/400-Gigabit QSFP-DD ports (ports 29-36).
N9K-C9316D-GX Cisco Nexus 9300 platform switch with 16 10/40/100/400-Gigabit QSFP-DD ports (ports 1-
16).
N9K-C9332C Cisco Nexus 9300 platform switch with 32 40/100-Gigabit QSFP28 ports and 2 SFP ports.
Ports 25-32 offer hardware support for MACsec encryption.
N9K-C9364C-GX Cisco Nexus 9300 platform switch with 64 100-Gigabit Ethernet QSFP28 ports, two
management ports (one 10/100/1000BASE-T port and one SFP port), one console port (RS-
232), and one USB port.
N9K-C9364C Cisco Nexus 9300 platform switch with 64 40/100-Gigabit QSFP28 ports and two 1/10-
Gigabit SFP+ ports. The last 16 of the QSFP28 ports are colored green to indicate that they
support wire-rate MACsec encryption.
Product ID Description
NXA-PAC-1200W-PE 1200W AC power supply, port side exhaust pluggable, with higher fan speeds for NEBS
compliance
NXA-PAC-1200W-PI 1200W AC power supply, port side intake pluggable, with higher fan speeds for NEBS
compliance
NXA-PAC-750W-PE 750W AC power supply, port side exhaust pluggable, with higher fan speeds for NEBS
compliance
Note: This power supply is supported only on release 14.2(1) and later.
NXA-PAC-750W-PI 750W AC power supply, port side intake pluggable, with higher fan speeds for NEBS
compliance
Note: This power supply is supported only on release 14.2(1) and later.
Product ID Description
Product ID Description
N9K-C9408 Cisco Nexus 9408 modular chassis switch with up to 128 200/100-Gigabit (256 100-Gigabit
by 200G-to-2x100G breakout) ports using N9K-X9400-16W or 64 400/200/100-Gigabit
(256 100-Gigabit by 400G-to-4x100G breakout) ports using N9K-X9400-8D.
Table 11. Modular Leaf Switch Supervisor and System Controller Modules
Product ID Description
Product ID Description
N9K-C9364D-GX2A Cisco Nexus 9300 platform switch with 64 400/100-Gigabit QSFP-DD ports and 2 1/10 SFP+
ports.
N9K-C9348D-GX2A Cisco Nexus 9300 platform switch with 48 400/100-Gigabit QSFP-DD ports and 2 1/10 SFP+
ports.
N9K-C9332D-GX2B Cisco Nexus 9300 platform switch with 32p 400/100-Gigabit QSFP-DD ports and 2p 1/10
SFP+ ports.
N9K-C9316D-GX Cisco Nexus 9300 platform switch with 16 10/40/100/400-Gigabit QSFP-DD ports (ports 1-
16).
N9K-C9364C-GX Cisco Nexus 9300 platform switch with 64 100-Gigabit Ethernet QSFP28 ports, two
management ports (one 10/100/1000BASE-T port and one SFP port), one console port (RS-
N9K-C93600CD-GX Cisco Nexus 9300 platform switch with 28 10/40/100-Gigabit Ethernet QSFP28 ports (ports
1-28) and 8 10/40/100/400-Gigabit QSFP-DD ports (ports 29-36).
N9K-C93180YC-FX3 Cisco Nexus 9300 platform switch with 48 100M/1/10/25-Gigabit Ethernet SFP28 ports, 6
40/100-Gigabit QSFP28 ports, two management ports (one 10/100/1000BASE-T and one
SFP+), one console port (RS-232), and one USB port.
N9K-C93180YC-FX3H Cisco Nexus 9300 platform switch with 24 100M/1/10/25-Gigabit Ethernet SFP28 ports, 6
40/100-Gigabit QSFP28 ports, one management port (10/100/1000BASE-T), one console
port (RS-232), and one USB port.
N9K-C93108TC-FX3H Cisco Nexus 9300 platform switch with 24 100M/1/10-GBASE-T (copper) ports, 6 40/100-
Gigabit QSFP28 ports, two management ports (one 10/100/1000BASE-T and one SFP+), one
console port (RS-232), and one USB port.
N9K-C93108TC-FX3P Cisco Nexus 9300 platform switch with 48 100M/1/10-GBASE-T (copper) ports, 6 40/100-
Gigabit QSFP28 ports, two management ports (one 10/100/1000BASE-T and one SFP+), one
console port (RS-232), and one USB port.
N9K-C93108TC-FX3 Cisco Nexus 9300 platform switch with 48 100M/1/10-GBASE-T (copper) ports, 6 40/100-
Gigabit QSFP28 ports, two management ports (one 10/100/1000BASE-T and one SFP+), one
console port (RS-232), and one USB port.
N9K-C9348GC-FX3 Cisco Nexus 9300 platform switch with 48 100M/1-GBASE-T (copper) ports, 4 1/10/25-
Gigabit SFP28 ports, two 40/100G QSFP28 ports, two management ports (one
10/100/1000BASE-T and one SFP+), one console port (RS-232), and one USB port.
N9K-C93240YC-FX2 Cisco Nexus 9300 platform switch with 48 1/10/25-Gigabit Ethernet SFP28 ports and 12
40/100-Gigabit Ethernet QSFP28 ports. The N9K-C93240YC-FX2 is a 1.2-RU switch.
Note: 10/25G-LR-S with QSA is not supported.
N9K-C93216TC-FX2 Cisco Nexus 9300 platform switch with 96 1/10GBASE-T (copper) front panel ports and 12
40 /100-Gigabit Ethernet QSFP28 spine-facing ports
N9K-C93360YC-FX2 Cisco Nexus 9300 platform switch with 96 1/10/25-Gigabit front panel ports and 12 40 /100-
Gigabit Ethernet QSFP spine-facing ports.
Note: The supported total number of fabric ports and port profile converted fabric links is 64.
N9K-C9336C-FX2-E Cisco Nexus 9336C-FX2 Top-of-rack (ToR) switch with 36 fixed 40/100-Gigabit Ethernet
QSFP28 spine-facing ports.
Note: 1-Gigabit QSA is not supported on ports 1/1-6 and 1/33-36. The port profile feature
supports downlink conversion of ports 31 through 34. Ports 35 and 36 can only be used as
uplinks.
N9K-C9336C-FX2 Cisco Nexus 9336C-FX2 Top-of-rack (ToR) switch with 36 fixed 40/100-Gigabit Ethernet
QSFP28 spine-facing ports.
Note: 1-Gigabit QSA is not supported on ports 1/1-6 and 1/33-36. The port profile feature
supports downlink conversion of ports 31 through 34. Ports 35 and 36 can only be used as
uplinks.
N9K-C93108TC-FX Cisco Nexus 9300 platform switch with 48 1/10GBASE-T (copper) front panel ports and 6
fixed 40/100-Gigabit Ethernet QSFP28 spine-facing ports.
Note: Incoming FCOE packets are redirected by the supervisor module. The data plane-
forwarded packets are dropped and are counted as forward drops instead of as supervisor
N9K-C93108TC-FX-24 Cisco Nexus 9300 platform switch with 24 1/10GBASE-T (copper) front panel ports and 6
fixed 40/100-Gigabit Ethernet QSFP28 spine-facing ports.
Note: Incoming FCOE packets are redirected by the supervisor module. The data plane-
forwarded packets are dropped and are counted as forward drops instead of as supervisor
module drops.
N9K-C93180YC-FX Cisco Nexus 9300 platform switch with 48 1/10/25-Gigabit Ethernet SFP28 front panel ports
and 6 fixed 40/100-Gigabit Ethernet QSFP28 spine-facing ports. The SFP28 ports support 1-
, 10-, and 25-Gigabit Ethernet connections and 8-, 16-, and 32-Gigabit Fibre Channel
connections.
Note: Incoming FCOE packets are redirected by the supervisor module. The data plane-
forwarded packets are dropped and are counted as forward drops instead of as supervisor
module drops.
N9K-C93180YC-FX-24 Cisco Nexus 9300 platform switch with 24 1/10/25-Gigabit Ethernet SFP28 front panel ports
and 6 fixed 40/100-Gigabit Ethernet QSFP28 spine-facing ports. The SFP28 ports support 1-
, 10-, and 25-Gigabit Ethernet connections and 8-, 16-, and 32-Gigabit Fibre Channel
connections.
Note: Incoming FCOE packets are redirected by the supervisor module. The data plane-
forwarded packets are dropped and are counted as forward drops instead of as supervisor
module drops.
N9K-C9348GC-FXP Cisco Nexus 9348GC-FXP switch with 48 100/1000-Megabit 1GBASE-T downlink ports, 4
10-/25-Gigabit SFP28 downlink ports, and 2 40-/100-Gigabit QSFP28 uplink ports.
N9K-C93108TC-EX Cisco Nexus 9300 platform switch with 48 1/10GBASE-T (copper) front panel ports and 6
40/100-Gigabit QSFP28 spine facing ports.
N9K-C93108TC-EX-24 Cisco Nexus 9300 platform switch with 24 1/10GBASE-T (copper) front panel ports and 6
40/100-Gigabit QSFP28 spine facing ports.
N9K-C93180LC-EX Cisco Nexus 9300 platform switch with 24 40-Gigabit front panel ports and 6 40/100-Gigabit
QSFP28 spine-facing ports.
The switch can be used as either a 24 40G port switch or a 12 100G port switch. If 100G is
connected the Port1, Port 2 will be HW disabled.
N9K-C93180YC-EX Cisco Nexus 9300 platform switch with 48 1/10/25-Gigabit front panel ports and 6-port
40/100 Gigabit QSFP28 spine-facing ports.
N9K-C93180YC-EX-24 Cisco Nexus 9300 platform switch with 24 1/10/25-Gigabit front panel ports and 6-port
40/100 Gigabit QSFP28 spine-facing ports.
Product ID Description
NXA-PAC-1200W-PE 1200W AC power supply, port side exhaust pluggable, with higher fan speeds for NEBS
compliance
NXA-PAC-1200W-PI 1200W AC power supply, port side intake pluggable, with higher fan speeds for NEBS
compliance
NXA-PAC-750W-PE 750W AC power supply, port side exhaust pluggable, with higher fan speeds for NEBS
compliance
Note: This power supply is supported only on release 14.2(1) and later.
NXA-PAC-750W-PI 750W AC power supply, port side intake pluggable, with higher fan speeds for NEBS
compliance
Note: This power supply is supported only on release 14.2(1) and later.
NXA-PDC-440W-PE 440W DC power supply, port side exhaust pluggable, with higher fan speeds for NEBS
compliance
Note: This power supply is supported only by the Cisco Nexus 9348GC-FXP and 9348GC-
FX3 ACI-mode switches.
NXA-PDC-440W-PI 440W DC power supply, port side intake pluggable, with higher fan speeds for NEBS
compliance
Note: This power supply is supported only by the Cisco Nexus 9348GC-FXP and 9348GC-
FX3 ACI-mode switches.
UCSC-PSU-930WDC V01 Port side exhaust DC power supply compatible with all leaf switches
Product ID Description
N9K-C9332PQ
N9K-C9372PX
N9K-C9372PX-E
N9K-C9372TX
N9K-C9372TX-E
N9K-C9396PX
N9K-C9396TX
Prior to upgrading your fabric to release 15.0(1) or later, replace these hardware elements in your fabric
with other supported hardware. For modular spine switches, replace all unsupported modular line cards
and fabric modules because these old generation line cards and fabric modules cannot be operated with
newer line cards and fabric modules in the same chassis.
If you attempt to upgrade one of the unsupported hardware to the 15.0(1) release or later, the hardware
will unsuccessfully attempt to boot three times, after which the switch will be reverted to the release that
was previously installed on it. Therefore, the unsupported hardware will not upgrade to release 15.0(1) or
later and the Cisco ACI fabric will operate with inconsistent firmware releases in each switch, which is why
we recommend that you replace the unsupported hardware prior to performing the upgrade.
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/hw/interoperability/fexmatrix/fex
tables.html
For more information on the FEX models, see the Cisco Nexus 2000 Series Fabric Extenders Data Sheet at
the following location:
https://www.cisco.com/c/en/us/products/switches/nexus-2000-series-fabric-extenders/datasheet-
listing.html
Changes in Behavior
For the changes in behavior, see the Cisco ACI Releases Changes in Behavior document.
Open Issues
Click the bug ID to access the Bug Search tool and see additional information about the bug. The "Exists In"
column of the table specifies the 16.0(8) releases in which the bug exists. A bug might also exist in releases
other than the 16.0(8) releases.
CSCvg85886 When an ARP request is generated from one endpoint to another endpoint in an 16.0(8e) and
isolated EPG, an ARP glean request is generated for the first endpoint. later
CSCvw89840 Traffic originating from a vPC TEP is dropped for Layer 2 multicast and unknown 16.0(8e) and
unicast traffic when pod redundancy is triggered. later
CSCvy31805 The PBR destination group for bypass action is not properly programmed with PBR 16.0(8e) and
service graph for service devices behind l3out and with "bypass" action enabled to later
redirect to another service node in the graph. Now, on bypass switchover, the traffic
doesn't get redirected to the next service node in the chain.
CSCwc61780 N9K-C9408 ASIC SFP+ ports on N9K-C9400-SUP-A card are not supported. 16.0(8e) and
later
CSCwd89607 When endpoint rogue detection or endpoint loop control is enabled with first hop 16.0(8e) and
security, the fabric might flag incorrect endpoint moves. This might lead to loss of later
traffic or the disabling of bridge domain learning.
CSCwf45328 BGP generates a core after deleting and restoring an SR MPLS infra L3Out node 16.0(8e) and
profile. This issue occurred with a scale configuration (800 VRF instances). later
CSCwf74167 An endpoint does not receive a DHCP response when First-Hop Security (FHS) is 16.0(8e) and
enabled. later
CSCwf80004 Upon upgrade to the 16.0(3) release from an earlier release, using SSH to connect to 16.0(8e) and
the switch does not succeed. later
The SSH client end displays the "connection refused" message.
CSCwf87280 All the conditions for priority flow control (PFC) are met, such as consistent 16.0(8e) and
congestion or PFC frames received. But, PFC frames are not generated on the front later
panel interface to slow down the sender.
CSCwf93802 Traffic loss is observed because an endpoint is not synced from leaf1 to leaf2. 16.0(8e) and
later
CSCwh15088 4X25G-CU (<=3m) links do not come on certain ports of GX2 platforms with AN on- 16.0(8e) and
enforce. later
When auto-negotiation is enabled on 25G speed on GX2 retimer ports, the link does
not come up.
CSCwj94677 Auto-negotiation does not work on a Cisco N9K-C9408 switch that has one of the 16.0(8e) and
following line-card expansion modules (LEMs): later
● N9K-X9400-8D
● N9K-X9400-16W
CSCwk32573 Fault F1820 gets raised for switches that have a 60GB SSD due to there not being 16.0(8e) and
enough storage space. later
Resolved Issues
Click the bug ID to access the Bug Search tool and see additional information about the bug. The "Fixed In"
column of the table specifies whether the bug was resolved in the base release or a patch release.
CSCwi47148 When SPF module is inserted and its Tx/Rx power is 0.0 mW, Tx/Rx power is shown 16.0(8e)
as 0.0 dBm in "show interface transceiver details" command.
CSCwk29549 A Power over Ethernet (PoE) ACI switch can run into the following situations: 16.0(8e)
- A once working port unexpectedly stops working
- A ports never comes up
CSCwi98380 IP Move count not getting reset after 'Detection Interval' with continuous EP move 16.0(8e)
within the limit.
CSCwi75077 After a failover test, some endpoints can experience connectivity issue for an 16.0(8e)
extended period of time (+2min).
CSCwi75324 Multisite EVPN routes stopped being advertised to remote sites after GOLF label was 16.0(8e)
removed from the tenant.
CSCwi88865 In a vPC port-channel where vPC primary has a vPC member port in hot standby 16.0(8e)
status, it still sends IGMP proxy report out the port.
CSCwi93848 This issue is a result of a misconfig in the IPN leading to packet with wrong Vxlan 16.0(8e)
srcIP landing in some random MPOD node. The symptom incarnates as trying to
forward a packet that isn't supposed to land on this node and getting wrongly
accounted.
CSCwj07800 The statistics memory running into 2 bit ECC error conditions triggers a node reboot 16.0(8e)
for recovery on EX line card sug_bmx_int_tst_mem_stats_ecc_error- uncorrectable.
CSCwj16077 L3out outside device path MTU negotiation with aci leaf running version 6.0.2j causes 16.0(8e)
leafs model N9K-C93600CD-GX to hardcode the ipv6 process to use lower MTU and
fragments all ipv6 packets to the neighbor provided MTU including an ICMP to
himself. Issue can happen on any model with the same version.
CSCwj23094 Fault F3927 is raided when an NTP server is set with an auth key set as preferred. 16.0(8e)
CSCwj43276 - Remote-Mac will not be learnt on the leaf switches causing unicast traffic to be 16.0(8e)
flooded or sent for hardware proxy depending on the BD configuration, when the IP
Data Plane learning is disabled on the subnet.
CSCwj48264 In rare scenario, no egress traffic is seen across either a given slice or on ASIC level 16.0(8e)
against a particular class of traffic.
CSCwj69519 + Multicast (*,G) state is not synchronizing between vPC peers when receivers 16.0(8e)
attempt to join groups.
CSCwj73439 Monitoring policies are configured on vPC policies to raise faults when storm control 16.0(8e)
drops packets on vPC port. When storm control dropped packets on vPC port, any
faults didn't raise.
CSCwj78565 ACI fabric modules N9K-C9508-FM-E2 and fixed spine switches N9K-C9364C and 16.0(8e)
N9K-C9332C may report HAL process crash and reboot when a specific internal cli
(show platform internal bky table roc_bky_xbc_acc) was issued.
CSCwj91816 PSU-fail fault with code F0411 from nodes were observed intermittently on APIC. 16.0(8e)
The faults were raised and cleared in TCA lifecycle.
CSCwk04818 - This ACI Multi-Site deployment runs ACI version 5.3(1d) and NDO version 4.2(2e). 16.0(8e)
- The spines are connected in a full-mesh topology using back-to-back connections.
All four spines are Nexus 9504 switches using the N9K-X9736C-FX line card.
CSCwk15835 PBR node1 (a.b.c.11/24) attached via L3out to Pod1/Leaf1/2. PBR Node2 16.0(8e)
(a.b.c.12/24) cannot ping each other.
CSCwk23296 N9K-C93108TC-FX3P show environment power not showing PSU model information 16.0(8e)
,and also can't find reference information in GUI ,Led status display is green.
CSCwk25662 On bring-up of 100G ports not fully come up - (Link not connected). 16.0(8e)
CSCwk36249 An EPG is configured with shared services and microsegmentation and the 16.0(8e)
microsegmented traffic is misclassified with the pctag of the parent EPG.
CSCwk41796 All the traffic flows work on the destination leaf switch except an unknown unicast 16.0(8e)
packet (flood) received on the working vPC switch. An ELAM capture for the flood
packet shows that the vPC_df bit set as 0x0 instead of 0x1, which dropped the flood
traffic.
CSCwk44519 N9K-C93180YC-FX3 fabric interfaces are flapping on eth 1/51 and 52. 16.0(8e)
CSCwm01630 Msite Announce packet (Tracking used by IPSLA) from site 1 with modular spines are 16.0(8e)
not reaching site 2 spines due to TTL being expired on ISN.
CSCwm03066 On the Homewood-based switch, Infra VLAN Sup-redirected packets don't trigger 16.0(8e)
MAC learning.
CSCwm11567 When commissioning a spine, multicast traffic between normal leaves and nodes 16.0(8e)
beyond IPN drops.
CSCwm32541 When commissioning a spine, multicast traffic between remote leaves drops. 16.0(8e)
CSCwm58397 Stale MAC entry in Infra BD with constant CooP bounce updates in Fabric for the 16.0(8e)
given MAC
- MAC is present in two locations in Fabric for Infra BD:
1. Old Leafs (VPC pair, only 1x switch in the pair has the stale entry) has MAC only
local learn while MAC is no longer behind this leaf. This entry doesn't time out and
might refresh from any flooded frame in Infra BD though not updating the learn as Xr
learn.
2. New Leafs where MAC locally resides, i.e. correct location.
CSCwm62890 Opflex connection not established between Agent and directly connected leaf. No 16.0(8e)
communication from Inband/CPU to directly connect host in Infra VLAN, however
may affect other BDs.
CSCwm47508 ISIS process may core on switches running ACI 6.x code. The process reset caused 16.0(8e)
by logging subsystem misbehavior triggering segmentation fault.
CSCwm66473 When using a N9K-C93108TC-FX3 in ACI mode, a diagnostic failure is displayed for 16.0(8e)
RTC-TEST.
CSCwm70093 On -FX3 platform, link using Cisco-INNOLIGHT branded QSFP type QSFP-100G- 16.0(8e)
SM-SR are experiencing random link flaps.
CSCwi47148 When SPF module is inserted and its Tx/Rx power is 0.0 mW, Tx/Rx power is shown 16.0(8e)
as 0.0 dBm in "show interface transceiver details" command.
CSCuo37016 When configuring the output span on a FEX Hif interface, all the layer 3 switched 16.0(8e) and
packets going out of that FEX Hif interface are not spanned. Only layer 2 switched later
packets going out of that FEX Hif are spanned.
CSCwe33967 After deleting or adding a VRF instance, the BGP peer session picks up the default 16.0(8e) and
timer values instead of the configured values. This is evidenced by the holdIntvl and later
kaIntvl values in the bgpPeerEntry managed object in the policy engine. The issue
happens intermittently.
CSCwd64518 A virtual machine has connectivity loss when the destination virtual machine is 16.0(8e) and
migrated using vMotion. This issue happens only if microsegmentation is enabled on later
the EPG.
CSCwf90351 With the rogue endpoint feature, a MAC address gets flagged as rogue. A leaf switch 16.0(8e) and
ignores any further moves of the rogue endpoint for 15 minutes, which can cause an later
outage. Traffic coming from a FEX vPC carries the Physical Tunnel Endpoint (PTEP)
as the source IP address of the outer header (SIPo) instead of the FEX vPC Tunnel
Endpoint (TEP).
CSCup65586 The show interface command shows the tunnel's Rx/Tx counters as 0. 16.0(8e) and
later
CSCup82908 The show vpc brief command displays the wire-encap VLAN Ids and the show 16.0(8e) and
interface .. trunk command displays the internal/hardware VLAN IDs. Both VLAN IDs later
are allocated and used differently, so there is no correlation between them.
CSCup92534 Continuous "threshold exceeded" messages are generated from the fabric. 16.0(8e) and
later
CSCuq39829 Switch rescue user ("admin") can log into fabric switches even when TACACS is 16.0(8e) and
selected as the default login realm. later
CSCuq46369 An extra 4 bytes is added to the untagged packet with Egress local and remote 16.0(8e) and
SPAN. later
CSCuq77095 When the command show ip ospf vrf <vrf_name> is run from bash on the border 16.0(8e) and
leaf switch, the checksum field in the output always shows a zero value. later
CSCuq92447 When modifying the L2Unknown Unicast parameter on a Bridge Domain (BD), 16.0(8e) and
interfaces on externally connected devices may bounce. Additionally, the endpoint later
cache for the BD is flushed and all endpoints will have to be re-learned.
CSCus18541 An MSTP topology change notification (TCN) on a flood domain (FD) VLAN may not 16.0(8e) and
flush endpoints learned as remote where the FD is not deployed. later
CSCus43167 Any TCAM that is full, or nearly full, will raise the usage threshold fault. Because the 16.0(8e) and
faults for all TCAMs on leaf switches are grouped together, the fault will appear even later
on those with low usage.
Workaround: Review the leaf switch scale and reduce the TCAM usage. Contact
TAC to isolate further which TCAM is full.
CSCut59020 If Backbone and NSSA areas are on the same leaf switch, and default route leak is 16.0(8e) and
enabled, Type-5 LSAs cannot be redistributed to the Backbone area. later
CSCuu66310 If a bridge domain "Multi Destination Flood" mode is configured as "Drop", the ISIS 16.0(8e) and
PDU from the tenant space will get dropped in the fabric. later
CSCuv57302 Atomic counters on the border leaf switch do not increment for traffic from an 16.0(8e) and
endpoint group going to the Layer 3 out interface. later
CSCuv57315 Atomic counters on the border leaf switch do not increment for traffic from the Layer 16.0(8e) and
3 out interface to an internal remote endpoint group. later
CSCuv57316 TEP counters from the border leaf switch to remote leaf switch nodes do not 16.0(8e) and
increment. later
CSCux97329 With the common pervasive gateway, only the packet destination to the virtual MAC 16.0(8e) and
is being properly Layer 3 forwarded. The packet destination to the bridge domain later
custom MAC fails to be forwarded. This is causing issues with certain appliances that
rely on the incoming packets’ source MAC to set the return packet destination MAC.
CSCuy02543 Bidirectional Forwarding Detection (BFD) echo mode is not supported on IPv6 BFD 16.0(8e) and
sessions carrying link-local as the source and destination IP address. BFD echo later
mode also is not supported on IPv4 BFD sessions over multihop or VPC peer links.
CSCuy22288 The iping command’s replies get dropped by the QOS ingress policer. 16.0(8e) and
later
CSCuy61018 The default minimum bandwidth is used if the BW parameter is set to "0", and so 16.0(8e) and
traffic will still flow. later
CSCuz13529 With the N9K-C93180YC-EX switch, drop packets, such as MTU or storm control 16.0(8e) and
drops, are not accounted for in the input rate calculation. later
CSCuz47058 SAN boot over a virtual port channel or traditional port channel does not work. 16.0(8e) and
later
CSCvb39965 Slow drain is not supported on FEX Host Interface (HIF) ports. 16.0(8e) and
later
CSCvd11146 Bridge domain subnet routes advertised out of the Cisco ACI fabric through an OSPF 16.0(8e) and
L3Out can be relearned in another node belonging to another OSPF L3Out on a later
different area.
CSCvn94400 There is a traffic blackhole that lasts anywhere from a few seconds to a few mins 16.0(8e) and
after a border leaf switch is restored. later
CSCvp04772 During an upgrade on a dual-SUP system, the standby SUP may go into a failed 16.0(8e) and
state. later
CSCvq71034 There is a policy drop that occurs with L3Out transit cases. 16.0(8e) and
later
CSCvr12912 A switch reloads due to a sysmgr heartbeat failure and sysmgr HAP reset. 16.0(8e) and
later
CSCvr61096 In a port group that has ports of mixed speeds, the first port in the port group that 16.0(8e) and
has valid optics present and is not in the admin down state is processed. The ports later
that come up later are brought up if they are using the same speed; otherwise, they
are put in the hw-disabled state.
For example, if ports 14 and 15 are up and are using the 100G speed, then if ports
13 and 16 are using the 40G speed, these ports will be put in the hw-disabled state.
After reloading or upgrading, you might not have the same interfaces in the port
group in the UP state and in the hw-disabled state as you did before the reload or
upgrade.
CSCvt61851 When MPLS VRF stats (egress) is compared with Layer 2 interface egress stats, we 16.0(8e) and
can find that the packet count matches for both while there could be a discrepancy later
with the bytes count.
CSCvu02371 The DEI value in a Layer 2 header of spanned Tx packets from an MPLS interface 16.0(8e) and
might not have the same value as the actual data path packet. later
CSCvu42069 The event log shows VTEP tunnel down and up events. The down time and up time 16.0(8e) and
are the same, and there is no fault message. later
CSCvx62362 When a service device is connected behind an L3Out in 2-arm mode with both legs 16.0(8e) and
on the same leaf switch, tracking packets get dropped. later
CSCvy06135 The leaf switch techsupport with a specified time range fails when the space 16.0(8e) and
"/mnt/ifc/log" gets filled up by more than 80%. later
CSCvy71586 400G port is automatically broken out into 4 breakout ports. After performing online 16.0(8e) and
insertion and removal (OIR) of a 400G transceiver, one of the breakout ports has the later
"SFP not inserted" or "SFP missing" state.
CSCvz84284 Upon deletion of a VRF instance that has a micro-BFD port channel in the "up" state, 16.0(8e) and
all the member ports of the port channel that were in the "up" state prior to the VRF later
instance deletion go to the "down" state. The micro-BFD port channels never
transition back to the "up" state.
CSCwa78857 Cisco APIC allows you to configure any number of DHCP relay addresses. However, 16.0(8e) and
the maximum number of relay address that can be supported is 16 from a switch. If a later
17th DHCP provider is added to the DHCP label, it will not be used even if one of first
16 DHCP providers is removed.
CSCwd95467 With N9K-X9400-16W LEM, a pair of odd and even number ports such as port 1/1 16.0(8e) and
and 1/2 must work as the same link type: downlink or fabric link because of later
CSCwd95467. This consideration is not applicable to N9K-X9400-8D.
CSCwe08179 A peer vPC leg goes down after swapping a 16 port LEM with an 8 port LEM. The 16.0(8e) and
following error shows in the "show vpc" output: "Peer does not have corresponding later
vPC". The leg on the peer switch immediately comes up, but traffic is still disrupted.
CSCwe41508 As a result of new features, certain PIDs running ACI release 6.0(7) software in 32-bit 16.0(8e) and
architecture will see increase in memory consumption and their process virtual later
address space.
This particular issue is seen with a trigger of 500 bridge domain (BD) deletions and
addition in a scale configuration of 64k fvrspath scale, 1980 BDs along with 123k
policycam entries. In release 6.0(7) with a 32-bit image, process memory could run
close to the limit of 4GB.”
In this scenario, EPM is running at 3.9GB. During the vlan creation as part of the
above trigger, EPM attempts to retrieve sclass corresponding to the vlan through
DME and DME access is failing. Memory map failures are seen through the instance
of EPM.
The DME failure may be due to mmap failures.
CSCwf88389 After an SVI member port flap, ECMP hashing no longer uses the flapped SVI's path 16.0(8e) and
and instead uses other SVI paths. later
N/A Load balancers and servers must be Layer 2 adjacent. Layer 3 direct server return is 16.0(8e) and
not supported. If a load balancer and servers are Layer 3 adjacent, then they have to later
be placed behind the Layer 3 out, which works without a specific direct server return
virtual IP address configuration.
N/A IPN should preserve the CoS and DSCP values of a packet that enters IPN from the 16.0(8e) and
ACI spine switches. If there is a default policy on these nodes that change the CoS later
value based on the DSCP value or by any other mechanism, you must apply a policy
to prevent the CoS value from being changed. At the minimum, the remarked CoS
value should not be 4, 5, 6, or 7. If CoS is changed in the IPN, you must configure a
DSCP-CoS translation policy in the APIC for the pod that translates queuing class
information of the packet into the DSCP value in the outer header of the iVXLAN
packet. You can also embed CoS by enabling CoS preservation. For more
information, see the Cisco APIC and QoS KB article.
N/A The following properties within a QoS class under "Global QoS Class policies" 16.0(8e) and
should not be changed from their default value and is only used for debugging later
purposes:
MTU (default – 9216 bytes)
Queue Control Method (default – Dynamic)
Queue Limit (default – 1522 bytes)
Minimum Buffers (default – 0)
N/A The modular chassis Cisco ACI spine nodes, such as the Cisco Nexus 9508, support 16.0(8e) and
warm (stateless) standby where the state is not synched between the active and the later
standby supervisor modules. For an online insertion and removal (OIR) or reload of
the active supervisor module, the standby supervisor module becomes active, but all
modules in the switch are reset because the switchover is stateless. In the output of
the show system redundancy status command, warm standby indicates stateless
mode.
N/A When a recommissioned APIC controller rejoins the cluster, GUI and CLI commands 16.0(8e) and
can time out while the cluster expands to include the recommissioned APIC later
controller.
N/A If connectivity to the APIC cluster is lost while a switch is being decommissioned, the 16.0(8e) and
decommissioned switch may not complete a clean reboot. In this case, the fabric later
administrator should manually complete a clean reboot of the decommissioned
switch.
N/A Before expanding the APIC cluster with a recommissioned controller, remove any 16.0(8e) and
decommissioned switches from the fabric by powering down and disconnecting later
them. Doing so will ensure that the recommissioned APIC controller will not attempt
to discover and recommission the switch.
N/A Multicast router functionality is not supported when IGMP queries are received with 16.0(8e) and
VxLAN encapsulation. later
N/A IGMP Querier election across multiple Endpoint Groups (EPGs) or Layer 2 outsides 16.0(8e) and
(External Bridged Network) in a given bridge domain is not supported. Only one EPG later
or Layer 2 outside for a given bridge domain should be extended to multiple multicast
routers if any.
N/A The rate of the number of IGMP reports sent to a leaf switch should be limited to 16.0(8e) and
1000 reports per second. later
N/A Unknown IP multicast packets are flooded on ingress leaf switches and border leaf 16.0(8e) and
switches, unless "unknown multicast flooding" is set to "Optimized Flood" in a later
bridge domain. This knob can be set to "Optimized Flood" only for a maximum of 50
bridge domains per leaf switch.
If "Optimized Flood" is enabled for more than the supported number of bridge
domains on a leaf switch, follow these configuration steps to recover:
Set "unknown multicast flooding" to "Flood" for all bridge domains mapped to a leaf
switch.
Set "unknown multicast flooding" to "Optimized Flood" on needed bridge domains.
N/A Traffic destined to Static Route EP VIPs sourced from N9000 switches (switches with 16.0(8e) and
names that end in -EX) might not function properly because proxy route is not later
programmed.
N/A An iVXLAN header of 50 bytes is added for traffic ingressing into the fabric. A 16.0(8e) and
bandwidth allowance of (50/50 + ingress_packet_size) needs to be made to prevent later
oversubscription from happening. If the allowance is not made, oversubscription
might happen resulting in buffer drops.
N/A An IP/MAC Ckt endpoint configuration is not supported in combination with static 16.0(8e) and
endpoint configurations. later
N/A An IP/MAC Ckt endpoint configuration is not supported with Layer 2-only bridge 16.0(8e) and
domains. Such a configuration will not be blocked, but the configuration will not take later
effect as there is no Layer 3 learning in these bridge domains.
N/A An IP/MAC Ckt endpoint configuration is not supported with external and infra bridge 16.0(8e) and
domains because there is no Layer 3 learning in these bridge domains. later
N/A An IP/MAC Ckt endpoint configuration is not supported with a shared services 16.0(8e) and
provider configuration. The same or overlapping prefix cannot be used for a shared later
services provider and IP Ckt endpoint. However, this configuration can be applied in
bridge domains having shared services consumer endpoint groups.
N/A An IP/MAC Ckt endpoint configuration is not supported with dynamic endpoint 16.0(8e) and
groups. Only static endpoint groups are supported. later
N/A No fault will be raised if the IP/MAC Ckt endpoint prefix configured is outside of the 16.0(8e) and
bridge domain subnet range. This is because a user can configure bridge domain later
subnet and IP/MAC Ckt endpoint in any order and so this is not error condition. If the
final configuration is such that a configured IP/MAC Ckt endpoint prefix is outside all
bridge domain subnets, the configuration has no impact and is not an error condition.
N/A Dynamic deployment of contracts based on instrImmedcy set to onDemand/lazy not 16.0(8e) and
supported; only immediate mode is supported. later
N/A When a server and load balancer are on the same endpoint group, make sure that the 16.0(8e) and
Server does not generate ARP/GARP/ND request/response/solicits. This will lead to later
learning of LB virtual IP (VIP) towards the Server and defeat the purpose of DSR
support.
N/A Direct server return is not supported for shared services. Direct server return 16.0(8e) and
endpoints cannot be spread around different virtual routing and forwarding (VRF) later
contexts.
N/A Configurations for a virtual IP address can only be /32 or /128 prefix. 16.0(8e) and
later
N/A Client to virtual IP address (load balancer) traffic always will go through proxy-spine 16.0(8e) and
because fabric data-path learning of a virtual IP address does not occur. later
N/A GARP learning of a virtual IP address must be explicitly enabled. A load balancer can 16.0(8e) and
send GARP when it switches over from active-to-standby (MAC changes). later
N/A Learning through GARP will work only in ARP Flood Mode. 16.0(8e) and
later
Compatibility Information
● For the supported optics per device, see the Cisco Optics-to-Device Compatibility Matrix.
● 100mb optics, such as the GLC-TE, are supported in 100mb speed only on -EX, -FX, -FX2, and -
FX3 switches, such as the N9K-C93180YC-EX and N9K-C93180YC-FX, and only on front panel
ports 1/1-48. 100mb optics are not supported any other switches. 100mb optics cannot be used on
EX or FX leaf switches on port profile converted downlink ports (1/49-52) using QSA.
● This release supports the hardware and software listed on the ACI Ecosystem Compatibility List, and
supports the Cisco AVS, release 5.2(2)SV3(3.10).
● To connect the N2348UPQ to ACI leaf switches, the following options are available:
◦ Directly connect the 40G FEX ports on the N2348UPQ to the 40G switch ports on the ACI leaf
switches
◦ Break out the 40G FEX ports on the N2348UPQ to 4x10G ports and connect to the 10G ports on all
other ACI leaf switches
Note: A fabric uplink port cannot be used as a FEX fabric port.
● To connect the Cisco APIC (the controller cluster) to the Cisco ACI fabric, it is required to have a
10G interface on the ACI leaf switch.
N9K-X9716D-GX 4 4 No No 4 4
N9K-X9736C-FX 5 5 5 5 5 5
N9K-X9736Q-FX 5 5 5 5 5 5
N9K-X9732C-EX No No 4 4 4 4
N9K-X9716D-GX If you connect a Cisco N9K-X9716D-GX breakout port to a non-Cisco ACI peer, such as a
standalone switch capable of 100G, the link comes up and LLDP is detected. However, this is
an unsupported scenario, but no fault is generated.
N9K-C9364C You can deploy multipod or Cisco ACI Multi-Site separately (but not together) on the Cisco
N9K-9364C switch starting in the 3.1 release. You can deploy multipod and Cisco ACI Multi-
Site together on the Cisco N9K-9364C switch starting in the 3.2 release.
A 930W-DC PSU (NXA-PDC-930W-PE or NXA-PDC-930W-PI) is supported in redundancy
mode if 3.5W QSFP+ modules or passive QSFP cables are used and the system is used in
40C ambient temperature or less; for other optics or a higher ambient temperature, a 930W-
DC PSU is supported only with 2 PSUs in non-redundancy mode.
1-Gigabit QSA is not supported on ports 1/49-64.
This switch supports the following PSUs:
● NXA-PAC-1200W-PE
● NXA-PAC-1200W-PI
● N9K-PUV-1200W
● NXA-PDC-930W-PE
● NXA-PDC-930W-PI
● For ports 1 through 24, every 4 ports (1-4, 5-8, 9-12, and so on, referred to as a "quad") will operate
at a fixed speed. That is, all 4 ports will operate in 10G or 40/100G; you cannot mix the speeds.
● Mixed speeds of 10G and 40G or 10G and 100G in a quad is not supported. Based on the port bring
up sequence, the port in the quad where the speed mismatch is detected will be HW disabled.
● If there is a speed mismatch in a quad even though the ports are configured in the disabled state, the
working links in that quad might get into the HW disabled state upon upgrading or reloading, as the
mixed speed is brought up first before admin down config is pushed. To avoid this issue, you must
manually use the shut and no shut commands on the working ports to bring up the links. For more
information, see bug CSCvr61096.
● Ports 25-26 and ports 27-28 (port groups of 2 ports each) will operate in a fixed speed within the
respective group, and you cannot mismatch the speed.
● Uplink ports 29 to 36 do not have a mixed speed restriction; you can toggle the speed for the
bidirectional ports.
● For ports 1 to 28, even if you convert any ports to uplink with bidirectional optics, you cannot toggle
the speed, as it will introduce mixed speeds and will disturb the neighboring ports.
● For ports 1 to 28, if any of the ports are converted to uplink with bidirectional optics, the ports will stay
in the not connected state if the peer is a 40G link.
● 4x10 and 4x25 breakout is supported on ports 25-28 and 29-34 (port profile converted downlinks).
● Ports 25-26 and 27-28 form respective port pairs, and each pair can operate with 4x10, 10G, or
4x25G speed.
● The Hardware Abstraction Layer (HAL) will spike and the console can hang if a port channel or vPC
exists when overlying breakout ports are deleted. To avoid this issue, delete the PC or vPC before
deleting the overlying breakout policy.
● The maximum number of downlinks is 12 x 4 ports 10/25G (breakout) + 10 x 4 ports 10/25G
(breakout) = 88 ports. Ports 35 and 36 are reserved for fabric links and 12 ports are error-disabled.
● 1G and 100M speeds are not supported.
N9K-C9316D-GX Auto-negotiation and forward error correction are not supported when you use this switch is
as a leaf switch.
N9K-C93240YC-FX2 The following information applies when this switch is configured with port-side intake airflow:
● Ports 2, 6, 8, 12, 14, 18, 20, 24, 26, 30, 32, 36, 38, 42, 44, and 48 are capable of supporting the 10G
GLC-T optic. After you configure these ports to use 10G GLC-T, these ports will be the only ports on
the switch that can support 10G GLC-T. Without being configured for 10G GLC-T, these ports behave
as normal switch ports.
● If you configure port 12 for 10G GLC-T, then ports 9 and 15 must either be left empty or must deploy
only DACs.
● Ports 49 through 60 can be configured to use 10G GLC-T or can be normal ports, regardless of the
configuration of the other ports.
The following information applies when this switch is configured with port-side exhaust
airflow:
● Ports 6, 12, 18, 24, 30, 36, 42, and 48 are capable of supporting the 10G GLC-T optic. After you
configure these ports to use 10G GLC-T, these ports will be the only ports on the switch that can
support 10G GLC-T. Without being configured for 10G GLC-T, these ports behave as normal switch
ports.
● If you configure port 12 for 10G GLC-T, then ports 9, 11, and 15 must either be left empty or must
deploy only DACs.
● Ports 49 through 60 can be configured to use 10G GLC-T or can be normal ports, regardless of the
configuration of the other ports.
N9K-C93180YC-FX-24 This switch does not support the 10G GLC-T optic.
N9K-C93180YC-EX-24 This switch does not support the 10G GLC-T optic.
◦ CloudSec only works with spine switches in Cisco ACI and only works between sites managed by
Cisco ACI Multi-Site.
◦ For CloudSec to work properly, all of the spine switch links that participate in Cisco ACI Multi-Site
must have MACsec/CloudSec support.
Usage Guidelines
● The current list of protocols that are allowed (and cannot be blocked through contracts) include the
following. Some of the protocols have SrcPort/DstPort distinction. See the Cisco Application Policy
Infrastructure Controller Release Notes, Release 6.0(8) for policy information.
◦ UDP DestPort 161: SNMP. These cannot be blocked through contracts. Creating an SNMP
ClientGroup with a list of Client-IP Addresses restricts SNMP access to only those configured Client-
IP Addresses. If no Client-IP address is configured, SNMP packets are allowed from anywhere.
◦ OSPF
◦ IGMP
◦ PIM
◦ FIPS is supported on Cisco NX-OS release 15.2(2) or later. If you must downgrade the firmware from
a release that supports FIPS to a release that does not support FIPS, you must first disable FIPS on
the Cisco ACI fabric and reload all of the switches in the fabric.
● You cannot use the breakout feature on a port that has a port profile configured on a Cisco N9K-
C93180LC-EX switch. With a port profile on an access port, the port is converted to an uplink, and
breakout is not supported on an uplink. With a port profile on a fabric port, the port is converted to a
downlink. Breakout is currently supported only on ports 1 through 24.
● On Cisco 93180LC-EX Switches, ports 25 and 27 are the native uplink ports. Using a port profile, if
you convert ports 25 and 27 to downlink ports, ports 29, 30, 31, and 32 are still available as four
native uplink ports. Because of the threshold on the number of ports (which is maximum of 12 ports)
that can be converted, you can convert 8 more downlink ports to uplink ports. For example, ports 1,
3, 5, 7, 9, 13, 15, 17 are converted to uplink ports and ports 29, 30, 31 and 32 are the 4 native
uplink ports, which is the maximum uplink port limit on Cisco 93180LC-EX switches.
◦ When the switch is in this state and if the port profile configuration is deleted on ports 25 and 27,
ports 25 and 27 are converted back to uplink ports, but there are already 12 uplink ports on the
switch in the example. To accommodate ports 25 and 27 as uplink ports, 2 random ports from the
port range 1, 3, 5, 7, 9, 13, 15, 17 are denied the uplink conversion; the chosen ports cannot be
controlled by the user. Therefore, it is mandatory to clear all the faults before reloading the leaf node
to avoid any unexpected behavior regarding the port type. If a node is reloaded without clearing the
port profile faults, especially when there is a fault related to limit-exceed, the ports might be in an
unexpected mode.
● When using a 25G Mellanox cable that is connected to a Mellanox NIC, you can set the ACI leaf
switch port to run at a speed of 25G or 10G.
● You cannot enable auto-negotiation on the spine switch or leaf switch side with 40G or 100G CR4
optics. For 40G copper transceivers, you must disable auto-negotiation and set the speed to 40G.
Port 107.0 (Eth1/42) : Admin UP Link DOWN Cfg_Fec Disabled Fec Disabled Fcot Copper retimer
0x116c0100
Port 109.0 (Eth1/43) : Admin UP Link UP Cfg_Fec Disabled Fec Disabled Fcot Copper retimer
0x116c0100
Related Content
See the Cisco Application Policy Infrastructure Controller (APIC) page for the documentation.
Documentation Feedback
To provide technical feedback on this document, or to report an error or omission, send your comments to
[email protected]. We appreciate your feedback.
Legal Information
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S.
and other countries. To view a list of Cisco trademarks, go to this URL:
http://www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their
respective owners. The use of the word partner does not imply a partnership relationship between Cisco
and any other company. (1110R)
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be
actual addresses and phone numbers. Any examples, command display output, network topology