
611
Caveats for Cisco IOS Release 12.2(33)SRD through 12.2(33)SRD8
OL-10394-05 Rev. R0
Conditions: This symptom is observed if the frame-relay be 1 command is issued under “map-class
frame-relay <name>” configuration.
Workaround: There is no workaround.
• CSCsw35155
Symptoms: When using denies in ACLs in crypto maps, the VPN SPA or VPN SM crashes.
Conditions: Occurs when configuration uses denies in ACLs with crypto maps that causes too many
entries in the Ternary Content Addressable Memory (TCAM).
Workaround: Enter the crypto ipsec ipv4 deny clear command.
• CSCsw35638
Symptoms: When a Cisco router is the Merge Point (MP) for a protected TE tunnel, and FRR is
triggered, two things happen:
- The primary LSP goes down, and traffic is lost on the protected tunnel. - Any PLR that is
downstream of the failure will lose its backup.
Conditions: When a competitor’s router is a point of local repair (PLR) and a Cisco router is a merge
point, then when FRR is triggered, the Cisco router drops the backup tunnel (in some cases
immediately and in other cases after 3 minutes). This causes the primary tunnel that is protected by
this backup to go down. The issue has been identified as related to the fact that session attribute flags
(link/node protection desired) are being cleared by the competitor PLR when the Path is sent over
the backup tunnel.
Workaround: There is no workaround.
• CSCsw36285
Symptoms: The show policy-map interface command yields incorrect policer information.
Conditions: This problem affects only the reporting of policing statistics. It does not affect policer
functionality. When police action is configured in a service-policy, the conformed rate displayed in
show policy-map interface does not match with the class-map offered rate.
Workaround: There is no workaround.
• CSCsw36872
Symptoms: VPN-NUM in VLAN-RAM TCAM wrongly provisioned after reconfiguration of Layer
3 port-channel. This changes member link mapping, and VRF membership changes on Layer 3
port-channel. Also discrepancy in L3MGR info between RP and SP for affected
port-channel/internal vlan representation observed.
Conditions: When the command channel-group <number> mode active is configured on the
member link before the respective Port-channel is configured, this causes the member link interface
to go admin down. When the port-channel is configured, the port-channel first comes up and then
the member link. This may cause the port-channel to take up the same VLAN which was previously
assigned to the member link. If this happens, the symptom is seen.
Workaround: One workaround is to configure the port-channel first and then activate the
channel-group on the member link interface. Another workaround is to create a dummy interface so
that it takes up the member link’s previous VLAN and the port-channel will be assigned a new one,
in which case this problem is not seen.
• CSCsw37053
Symptoms: Traffic with aggregate label was forwarded in wrong VPN, causing the mis-forwarding,
as the IP prefix was not present in the VPN routing/forwarding (VRF) table.
Conditions: Occurs under the following scenario:
Comentarios a estos manuales