AWS S3 and CloudWatch Support
Software Features in Cisco IOS XE 17.15.1
AAA PAC-less Authentication
All Models
- In multi ISE node environment when the primary ISE node is unavailable, device can automatically switch to the secondary node without needing to re-establish a Provisioning Authentication Credential (PAC), ensuring minimal disruption.
- AAA PAC-less authentication simplifies the authentication process by eliminating the need for a PAC, improves scalability, enhances the user experience, and enables more modern authentication methods while aligning with Zero Trust security principles.
AWS S3 and CloudWatch Support
All Models
- Cisco Catalyst 9000 Series Switches support Amazon Web Services S3 and CloudWatch. With AWS S3, network administrators can mount an Amazon Simple Storage Service (S3) bucket to the bootflash. The S3 bucket enables easy distribution of software images, software maintenance upgrades (SMUs), and scripts to multiple devices without any disruptions. Network administrators can also create, edit, and delete the cloud storage instance using AWS S3 functionality, and make them accessible as part of the bootflash.
- The AWS CloudWatch is a monitoring and logging service that provides data that enables you to understand, optimize, and enhance the performance of your applications, systems, and services running on the Cloud platform and on-premise servers.
Global Link Debounce Timer
C9600X-SUP-2
- The Link Debounce Timer delays notification of a link up or down status change. Delayed notification of a link status change can decrease traffic loss due to network reconfiguration when network ethernet port experiences minor faults in the link. The Link Debounce Up Timer is a new enhancement of the feature which delays notification of a link from down to up status change.
- The feature is implemented on Cisco Catalyst 9600 Series Supervisor 2 Module at the global level only. Per port configuration is not supported.
- See Interface and Hardware Components → Configuring Link Debounce Timer.
(Network Essentials)
MACsec over Port Channel Subinterfaces
C9600X-SUP-2
- MACsec is supported over port channel subinterfaces.
- See Security → Configuring MACsec Encryption.
- (Network Advantage)
Port Settings Configuration for Interfaces
All Models
- The port-settings command is introduced. The port-settings command can simultaneously or separately configure the speed, duplex, and auto negotiation for an interface, an interface range, or a port channel interface.
- When using a single command to configure multiple parameters of the port-settings command, the order must be, speed, duplex, and autoneg. If you specify speed first, you can configure duplex and autoneg for the interface. If you specify duplex first, you can only configure autoneg. And, if you specify autoneg first, you cannot configure speed or duplex.
- See Interface and Hardware Components → Configuring Interface Characteristics.
(Network Essentials)
Programmability:
YANG Data Models
All Models
- The following programmability features are introduced in this release:
- YANG Data Models: For the list of Cisco IOS XE YANG models available with this release, navigate to: https://github.com/YangModels/yang/tree/main/vendor/cisco/xe/17151.
- See Programmability.
(Network Essentials and Network Advantage)
Serviceability: Embedded Packet Capture on Control-Plane Interface
C9600X-SUP-2
- Embedded Packet Capture is supported on control plane packets.
- See Network Management → Configuring Packet Capture.
- (Network Essentials)
Serviceability: Embedded Packet Capture on Layer 2 Interfaces
C9600X-SUP-2
- Embedded Packet Capture is supported on Layer 2 Interfaces.
- See Network Management → Configuring Packet Capture.
- (Network Essentials)
Serviceability: Enhanced Drop Detection
C9600X-SUP-2
- Enhanced Drop Detection allows you to determine where packets are being dropped in the processing path.
- See Network Management → Configuring Enhanced Drop Detection and Enhanced Packet Drop Analyzer.
- (Network Essentials)
Serviceability: Packet Drop Analyzer
C9600X-SUP-2
- Packet Drop Analyzer allows you to configure traps to punt dropped packets to a CPU based destination for the purpose of debugging.
- See Network Management → Configuring Enhanced Drop Detection and Enhanced Packet Drop Analyzer.
- (Network Essentials)
Unique BGP Identifier for BGP-4
All Models
- Enhancement to Border Gateway Protocol (BGP) IPv4 router-id, added support for RFC 6286, which allows configuring IPv4 multicast and local range addresses as BGP router-ID, in addition to allowing peers with the same BGP router-ID and different ASes to establish a BGP connection.
(Network Advantage)
WAN MACsec over Port Channel Subinterfaces
C9600X-SUP-2
- WAN MACsec is supported over port channel subinterfaces.
- See Security → Configuring MACsec Encryption.
- (Network Advantage)
Resolved Caveats in Cisco IOS XE 17.15.1
- CSCwi97513 : C9606R with PSU unit C9600-PWR-3KWAC Capacity shows na and modules in power deny state
- CSCwi91894 : C9600-BrentonLC: Link down with SFP GLC-LH-SMD on interop with 9300L
- CSCwi85562 : Default Power mode for Catalyst 9600 is combined, always showing PS Current Operating State as none
- CSCwj34178 : Shutdown 9600-Sup1 when "ASIC minor temp alarm + FAN failure"
- CSCwj56954 : C9600X Capacity shows 2000W when use C9600-PWR-2KWAC at 100V