These notes summarizes PICOS 2.11 new features, new hardware, known bugs, and bug fixes. Best practices recommend that you read all the content before upgrading to this release. For more detailed feature information, refer to the configuration guides.
New Software Features
Layer 2 and Layer 3
Bug ID | Release | Description |
---|---|---|
8008 | 2.11.0 | Disable/Enable IP Routing |
8127 | 2.11.0 | Limit Maximum Number of VRRP Interfaces |
8159 | 2.11.0 | Tagged/Untagged with Voice-VLAN |
8202 | 2.11.0 | PVST Manual-Forwarding |
8314 | 2.11.0 | TACACS+ Failover Enhancement |
8345 | 2.11.0 | MSH8920 - BPDU & LACP Tunneling on Static LAG |
8422 | 2.11.0 | Enhancement for PVST/MSTP information in tech_support |
8525 | 2.11.0 | Refreshing MAC Learning on MLAG Pair Switches |
8542 | 2.11.0 | Remove SSH/Telnet Connection Number Limiting |
8546 | 2.11.0 | PoE - Power Negotiation |
8605 | 2.11.0 | Show Entire Spanning-tree PVST Infomation |
8658 | 2.11.0 | DHCP Snooping over MLAG |
8755 | 2.11.1 | Kontron - CDP and LLDP Tunneling |
8826 | 2.11.1 | Boeing - Add new OIDs to UCB MIB |
8668 | 2.11.4 | OEM - Display timestamp in syslog Message in Millisecond |
8818 | 2.11.4 | OEM - Show System Date in Milliseconds |
8820 | 2.11.4 | Remark DSCP with ACL Rule |
8821 | 2.11.4 | Configure rate-limit on Egress Queues |
8947 | 2.11.4 | GE Interfaces on AG5628 and AS7312 |
8976 | 2.11.4 | Send Traps if CPU Utilization Thredhold is Exceeded |
8977 | 2.11.4 | Issue a SNMP Trap if L2 Table Threshold is Exceeded |
8989 | 2.11.4 | Allow Hyphen "-" in VLAN Name |
8990 | 2.11.4 | Add entPhysicalTable per RFC 6933 |
9665 | 2.11.4 2.11.7.5 | Support UPoE Support UPoE on N3048EP-ON and AS4610-54P and AS4610-30P. |
7654 | 2.11.7 | Configure Rate Limit by Reference of Percentage |
9024 | 2.11.7 | Add auto Mode to Voice VLAN |
9150 | 2.11.7 | Disable SNMP Traps Related to LLDP |
9166 | 2.11.7 | Enhancement on Displaying PoE Information |
9222 | 2.11.7 | IGMP Snooping over MLAG |
9284 | 2.11.7 | TACACS+ - Add New Command local-auth-fallback |
8590 | 2.11.7.2 | Press "Enter" key to stop the process of upgrade2 The process of upgrade2 can be aborted before reboot into the update version of PicOS with the prompt message "PRESS ANY KEY TO STOP REBOOT". |
9047 | 2.11.7.2 | Configure the rate-limit of filter rules by reference of kbps Allow to configure rate-limit of ACL filter rules by reference of kbps in addition to pps. |
9687 | 2.11.14 2.11.7.5 | Set Auto Negociation Speeds Allow user to configure the speeds which can be advertised to the connected device under auto-negotiation mode. |
9744 | 2.11.14 | Performance Refinement - ARP Handling Reduce the time to handle the packet-in ARPs. Allow larger number of protocol packets destined to CPU. |
9676 | 2.11.14 | Performance Refinement - Sync up ARP on Active-Active VRRP Devices The time used to syn up ARP on active-active VRRP devices is reduced drastically. |
9151 | 2.11.10 | Support VRRPv3 PicOS supports both VRRPv2 and VRRPv3. The advantage of VRRPv3 is that it supports both IPv4 and IPv6 address families. |
9614 | 2.11.11 | MLAG - Sync up MAC Addresses Learned on Orphan Ports the Peer Switch MAC addresses which are learned on the single-homed ports of one spine switch of MLAG should be synchronized to the peer-link port of the other spine switch. |
8952 | 2.11.9 | Add a Description Field after the Command "run request system reboot" Add a description field after the command "run request system reboot" and add this text to the log message. This help Operations track the reason for the reboot through log messages. |
9384 | 2.11.9 | MSH8920 - Extend L2-transparency to cover LLDP and CDP L2-transparency is enabled for LLDP and CDP. Namely, If "set protocols lldp||cdp message-in disable true", the frames of LLDP and CDP will be flooded out of the switch instead of being trapped to CPU. |
9747 | 2.11.9.5 | MSH8920 - xe-1/1/2.1 does not work after installing PICOS at its very first time; it needs an extra reboot to starts it This problem has been fixed in 2.11.9.5. |
10118 | 2.11.9.5 | MSH8920 - upgrade2 creates ext3 filesystem for new partition This problem has been fixed in 2.11.9.5. |
10060 | 2.11.16 | 802.1X - Support MAB Authentication, Dynamic VLAN and CoA Function Extend the 802.1X feature to support MAB authentication, dynamic VLAN and CoA function. |
9763 | 2.11.15 | Support 1G speed with DELTA 10G RJ45 Module Parameters of this module is as following: Leo Vendor Name : DELTA Vendor PartNr : LCP-10GRJ3SRT Serial Number : 183209100001 Cable Length : 300m |
9915 | 2.11.13 | Configure Rate-limit and Burst on Port Add commands to configure rate-limit and burst to the port on ingress side and egress side. Both L2/L3 and OVS support this new feature. |
9214 | 2.11.17 | Hashing with Sorted LAG Member In generic, specific traffic will be forwarded out of a LAG member port depending on hashing algorithm with the key configuration. Certain behavior is defined between 2 LAGs with same number of member ports. Assuming ae1 has 4 member ports (1, 2, 3, 4) and ae2 also has 4 member ports (5, 6, 7, 8), with lag_members_sorted enabled, if a traffic is hashed out of port 2 for ae1, the traffic will be hashed out of port 6 for ae2. |
10075 | 2.11.17 | Cable Diagnostics using TDR on RJ45 Interface Support cable diagnostic function using TDR on RJ45 ports. |
10200 | 2.11.17 | Add a New Command to Configure NAS-IP Add a CLI command to let the user configure the NAS-IP address: |
10457 | 2.11.21 | Update "run show bgp routes" Keep the existing “peer” column, but change the heading to “Router ID”. Add a column before the “Router ID” column above, with the heading “Peer”, listing the configured peer IP address of the received routes. |
10549 | 2.11.21 | Display all settings in the result of "show all" and "show all|display set" Display all settings including default settings in the result config tree of "show all" or result set commands of "show all|display set" respectively. |
10902 | 2.11.22 | New Additions to NAC NAC can operates under multi-domain mode or single-host mode with new features including dynamic/downloadable filter and central web authentication. |
11322 | 2.11.23 | [NAC] Server Fail VLAN and 802.1x fallback If RADIUS server is not reachable, the client will fall back to the server fail VLAN. If reject by 802.1x authentication, the client will try web authentication. |
11146 | 2.11.24 | Source Interface to TACACS+/RADIUS Server Allow user to configure an interface with IP address which is used to talk with TACACS+/RADIUS server. |
11395 | 2.11.24 | Present the Reason if Port Get Down by CoA Present the reason (CoA-Disable-Port) if a Port is Down caused by CoA when execute "run show interface gigabit-ethernet xxxx". |
11394 | 2.11.25 | Secure Keys in Configuration Present encripted code of share-key of RADIUS/TACAS+ and authentication-key and privacy-key of SNMP. |
11144 | 2.11.24 | VRRPv2 Authentication Secure VRRP session with MD5 authentication. That is only enabled for VRRPv2. |
11511 | 2.11.25 | Add New Columns to "run show lldp neighbor" |
11509 | 2.11.25 | NAC - Invalid Downloadable ACL |
11538 | 2.11.25 | Show "service-tag" |
11475 | 2.11.25 | Restore License and User Password Automatically |
11798 | 2.11.25.2 | Dynamical VLAN Overrides Voice VLAN If the returned RADIUS access accept message includes an extra Pica8 vendor-specific-attribute (VSA)“pica8-traffic-class=voice”, the dynamic VLAN will take precedence over the locally configured voice VLAN. |
10437 | 2.11.25.3 | RADIUS Accounting for 802.1x and MAB PICOS switch sends start/stop accounting message to RADIUS server for supplicant's 802.1x/MAB authenticaiton session. |
12132 | 2.11.25.3 | Response to session-timeout Attribute If the returned access-accept RADIUS message has attribute session-timeout after MAB/802.1x authentication, the authenticated session will be expired after a period of session-timeout and start a new authentication process. |
11976 | 2.11.25.3 | Show DACL Counters Allow user to show the counter of downloadable/dynamic NAC ACLs. |
12361 | 2.11.25.7 | Priority of Multiple NAC Servers Allow user to configure the priority of multiple NAC servers. The reachable NAC server with highest priority will be used for NAC authentication. |
12467 | 2.11.25.7 | Enhancements on Server-Fail Recovery Methods Three methods, namely auto, manual and timer, can be configured for the client to get out from the server failure. By default, manual comes into effective. |
OVS and OpenFlow
Bug ID | Release | Description |
---|---|---|
6867 | 2.11.0 | OVS 2.6 Upgrade |
7988 | 2.11.0 | Enable/Disable CoS with VLAN PCP |
8258 | 2.11.0 | Add New Match Modes |
8308 | 2.11.0 | VNTAG Support |
8346 | 2.11.0 | Configure Polling Interval on Interface/Flow Counter |
- | 2.11.3.vzsdn.5 | Buffer Management Goes Back to 2.7.1S1G in 2.11.3.vzsdn.5 When uprgade to 2.11.3.vzsdn.4 from 2.7.1S9 on AS5712_54X, customer reported that the capability of maximum burst absorption can not meet the requirement as in 2.7.1S19 in certain cases because we changed the behavior of buffer management in 2.8.x. For example, if multiple 1G traffics with continuous burst come in and go out of one port, there would have increasing number of packets dropped. By request from customer, the mode of buffer management is returned to the behavior of 2.7.1S9. |
9477 | 2.11.11 | Set Rate-limit on Port under OVS Mode Limit maxmum rate on specific port under OVS mode. |
9169 | 2.11.8 | Command "switch-to-ovs-2.6" Fails PicOS 2.11.x has 2 versions of OVS - 2.3 and 2.6. Command "switch-to-ovs-2.6" is used to switch to OVS 2.6 from OVS 2.3. |
6264 | 2.11.15 | Support L2GRE on AS4610 Enable L2GRE under OVS/OpenFLow mode on AS4610. |
11265 | 2.11.23 | Optimize Bootup Process of OVS By changing the way of initialization of ports added to the bridge, it only takes half long to boot up OVS. |
11438 | 2.11.24 | Maximum Number of Groups Allow to configure maximum 2k groups under OVS mode. |
Linux Platform
Bug ID | Release | Description |
---|---|---|
8395 | 2.11.0 | upgrade2 - New Way of Upgrade |
8721 | 2.11.1 | Kontron - Upgrade Linux Kernel to LTS Version |
8757 | 2.11.1 | Kontron - Dump Binary Data of FPGA |
8703 | 2.11.4 | Add New Option to upgrade2 |
8980 | 2.11.4 | Display Content of System EEPROM |
9662 | 2.11.4 | Enable OverlayFS on N3048EP-ON OverlayFS is a memory based file system, which can cache any write operation without write the data onto the underlying physical storage. OverlayFS is a different way to load PicOS on the switches which do not come with USB based NAND such as N3048EP-ON. |
9197 | 2.11.7 | Update Authentication Behavior of TACACS+/RADIUS |
9224 | 2.11.7 | Disable upgrade1 on MSH8920 |
9581 | 2.11.7.2 | convert the 2.11.7.2 pica_startup.boot to 2.7.2S1F Add a tool - convert-conf - which is used to remove the configuration items in 2.11.7.2 pica_startup.boot which are unknown for 2.7.2S1F. Add an option to upgrade2 to allow user to specify the startup configuration file which will be brought back to 2.7.2s1f. |
9441 | 2.11.7.2 | Add PoE checking to system-diag PoE checking is added system-diag which is executed before starting PicOS. |
9406 | 2.11.14 | Keep Specified Backup Files when Upgrade to New Version Add an option to upgrade/upgrade2 to allow user to specify a file list which will be kept when upgrade to new version.After add and delete multicast route |
9309 | 2.11.9.1 | MSH8920 - Upgrade2 is Broken by Watch Dog Resetting The watch dog is started in uboot on MSH8920. It takes so long to prepare the backup partition due to upgrade2 that watch dog resets the CPU and then reboots the system. So a watch dog refreshing demon is added to send keeping alive messages to the watch dog immediately after Linux platform boots up. |
9634 | 2.11.9.2 | MSH8920 - Add Wtmp Rotation to Crontab By default, CRON will check the size of /tmp/log/wtmp every 5 minutes. If its size is larger than 5M, rotation will be executed. User can adjust the interval and the size for /tmp/log/wtmp by modifying /etc/crontab and /etc/logrotate2.conf. |
9777 | 2.11.15 | Secure Password Secure the password by importing tally2 and cracklib into rootfs. |
12129 | 2.11.25.3 | Use Space Key to Terminate Countdown Due to upgrade2 process, will enter 10 seconds countdown before rebooting the system. User can only press space key instead of any key to end the countdown and abort the upgrade process. |
Hardware
Bug ID | Release | Description |
---|---|---|
9251 | 2.11.14 | Port to Dell N3048EP-ON Please refer to the document N3048EP-ON Switch Port Name Description. |
10181 | 2.11.18 | Support DELL S4148F-ON The S4148F-ON supports 48 x 10G SFP+, and 4 x 100G / 6 x 40G QSFP physical layer interfaces with PICOS. |
10830 | 2.11.21 | Port PICOS to N3048ET-ON N3048ET-ON is one model of LEEDS N30xx platforms of Dell. It has 48 1Gbps ports for copper with 2 comb Cu ports, one 20Gbps expansion slots for SFP+, 2 10G Base-T modules, and 2 mini-SAS type stacking ports. |
10905 | 2.11.21 | Support N3024ET-ON Powered by BCM56342, N3024ET-ON can have 24x1G Cu ports and and 4x10G ports. |
Fixed Issues
Linux Platform
Bug ID | Release | Description |
---|---|---|
10812 | 2.11.21 | Licensing Policy is Updated |
10737 | 2.11.21 | Reboot Fails to Bring up PICOS L2/L3 Processes It only happens on S4048-ON and S4148F-ON. After reboot, the console keeps displaying the following messages: |
10974 | 2.11.22 | User operator is not Allowed to Login by Default User operator is not allowed to login with default password "pica8". That would be a security concern. User operator can be given a password explicitly by admin. |
10972 | 2.11.22 | Disable TCP SACK Several TCP networking vulnerabilities associated with TCP SACK are identified (https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md). As a work around, TCP SACK is disabled in rootfs of PICOS. |
10968 | 2.11.22 | Raise kernel:__div64_32 Exception Under OVS Mode on PPC Platforms This issue is raised by overflow of tick based cputime. As a work around, it can be mitigated if enable kernal CONFIG_HZ_250 and set CONFIG_HZ to 250 instead to 1000. With this fix, in theory, the issue will not happen within 6 years. |
10064 | 2.11.22 | Host Name is Truncated in rsyslog Messages Full host name is not included in the rsyslog messages. |
11426 | 2.11.24 | Fan Speed Changes too Fastly on Certain Unit of N3132 It's possible that the fan speed changes too fastly on some units of N3132. From our test, it doesn't heppen on all units of N3132. |
System Management
Bug ID | Release | Description |
---|---|---|
7803 | 2.11.0 | Support AG7648 |
8285 | 2.11.0 | Clean up the Data when Remove an User |
8559 | 2.11.0 | MSH8920 - Configure FEC on 10G Febric |
8604 | 2.11.0 | Indicate That the Interface is Down Due to BPDU Guard |
8754 | 2.11.1 | Kontron - Present portmap Running Configuration |
8784 | 2.11.1 | Kontron - keep executing the rest of the commands in the execution file even if encounter the "same value" |
8916 | 2.11.1 | Power Outages Cause Corruption of pica_start.conf |
8923 | 2.11.1 | Clean up Associated ACL Rules When Delete MLAG |
8927 | 2.11.4 | DHCP Request are Send When ZTP is Disabled and IP is Configured Statically |
8962 | 2.11.4 | Boot Failure Caused by Configuration File Corrupted |
8975 | 2.11.4 | More Than 2 wtmp Files |
8979 | 2.11.4 | Do not Remark Voice Traffic DSCP by Default |
9025 | 2.11.4 | Management Interface eth0 is Up even if No cable Plugged in |
9034 | 2.11.4 | Voice VLAN - Remove Default OUIs |
7686 | 2.11.7 | Kernel Log-Level is Decoupled from the XorPlus Log-Leve |
9087 | 2.11.7 | PoE - threshold-mode Setting Does not Work |
9107 | 2.11.7 | Corruption of Startup Configuration File |
9582 | 2.11.7.2 | Remove Date Checking of the License if Downgrade to Previous Version It does not make sense to check the date of end support of license when downgrade to previous version. |
9505 | 2.11.7.2 | upgrade2 is Broken if There is a Large File in /home/admin If there is a large file in /home/admin, upgrade2 might be broken by an error of out of memory when tar and compress the file and copy to the second partition. To fix this issue, on the one hand, copy the backup files to the target partition directly instead of tar & gzip & untar; on the other hand, clean up cache memory with /proc/sys/vm/drop_caches. |
10460 | 2.11.19 | [N3132] Management Interface is Changed to eth0 The management interface on N3132 is changed to eth0 from eth1. The startup configuration will be lost if upgrade to 2.11.19. To restore the startup configuration, customer should replace "eth1" with "eth0" in a seperate copy of pica_startup.boot and then put it to /pica/config after upgrade. |
10486 | 2.11.19 | AS5600/2.11.16 ONIE Installation Failure AS5600/2.11.16 PICOS ONIE Installer fails. Fixed in 2.11.19. |
10516 | 2.11.19 | Upgrade to 3.1.0+ on EFI Platform We have one version of S4148 which boots into EFI (Extensible Firmware Interface) mode. Upgrade to 3.1.0 from 2.11.19 will work on EFI platforms or non-EFI platforms. |
10546 | 2.11.19 | Disable Weak Ciphers for SSHD Enterprise customers prefer to have the weak ciphers disabled by default for ssh server. So, disable the following ciphers in PICOS: arcfour256,arcfour128,aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc, aes256-cbc,arcfour. |
10970 | 2.11.22 | CPU Utilization is Reported to Reach 100% It indicates that CPU utilization reaches 100% by checking "/tmp/system/cpuusage". In fact, it's a false alarm from pica_monitor. |
Layer 2 and Layer 3 Features
Bug ID | Release | Description |
---|---|---|
7566 | 2.11.0 | Mac Leaning Command Does Not Work at Once |
8344 | 2.11.0 | MSH8920 - Add option to allow BPDU & LACP to Bypass CPU |
8796 | 2.11.0 | PICOS stops host load balance if VRRP is configured PICOS used to trap all of the VRRP packets to CPU even if they are the host VRRP Keepalive packets for load balance. The fix is to add source MAC address matching field to the VRRP filter. |
8858 | 2.11.1 | IGMP Snooping Does NOT Work |
8925 | 2.11.4 | Duplicate SNMP Traps of LLDP Update |
8926 | 2.11.4 | Dropping LLDP frames with unknown TLVs |
9003 | 2.11.7 | Status of Voice VLAN is Not Correct |
9139 | 2.11.7 | Ignore VRRP Authentication Packets |
9153 | 2.11.7 | LLDP Frames Dropped by LLDP Module |
9199 | 2.11.7 | IGMP Snooping - Source MAC Address of IGMP Leave Message |
9207 | 2.11.7 | PIM neighbor can not be Established Between two PIM Router |
6647 | 2.11.7.2 | Configure IP address to management interface before starting PicOS If the static IP address is confiured to management interface, the static IP address will be activated on eth0 before starting PicOS. Ensure that user can access the hardware model even if PicOS is failed to boot up. |
8530 | 2.11.7.2 | Migrate UDLD fix of 2.7.2S1G to 2.11.7.2 This version (2.11.7.2) of PICOS release will always send out UDLD PDU with Pica8 OUI (0x486E73). But it needs to use the OUI in the UDLD PDU to figure out if the peer device is PICOS 2.7.2S1F (OUI=0x486E73) or Cisco (OUI=0x00000C), and use the corresponding method to calculate the checksum. Anyway, 2.11.7.2 can talk to both 2.7.2S1F (backward compatible) and the future release (forward compatible) via UDLD. |
9335 | 2.11.7.2 | Enable and disable a port when STP is turned on interrupts the traffic When disable the port with traffic, it switches to the other port after ~550-600ms. But when enable it again, it interrupts the whole traffic.The mac entries are messed up. |
9657 | 2.11.12 | Buffer Management - Refine Headroom and Flow Control The maximum size of headroom is increased. If enable flow control and configure speed of the port, the size of headroom is 0. |
9336 | 2.11.10 | MLAG - Traffic is Broken when Bring Up One Down MLAG Link Initially one link of a MLAG is down. And then bring it up, the traffic from upstream device is broken for 5 - 6 seconds. |
9399 | 2.11.10 | MLAG - Traffic is Broken when Master Spine Shuts Down With reload delay configured, the traffic from downstream device is broken for 12 seconds when the master spine shuts down. |
9314 | 2.11.11 | Root Guard If enble root guard on a port, the port will be blocked if received a BPDU with high bridge priority. That can deny devices behind such ports from participation in STP. The blocking is removed as soon as the device ceases to send superior BPDUs. |
9470 | 2.11.11 | VLAN Membership Issue with DHCP Discovery Packets If enable DHCP snooping, DHCP DISCOVERY packets with unexpected VLAN ID can be received on a port and flooded out of the ports configured with different VLAN memberships. For example, an DHCP DISCOVERY packet tagged with VLAN 608 can ingress ge-1/1/2 and then egress on te-1/1/49 even thought the VLAN608 is only configured for te-1/1/49. e expected only tagged packets on VLAN 19 and VLAN 20 to be allowed to ingress on ge-1/1/2. |
9313 | 2.11.11 | CLI Session Hangs Due to PoE Display CLI hangs when execute command "show poe interface all". |
9492 | 2.11.5.cloudistics1 | STP Process Crashes on 2.11.5.cloudistics.0/as5812_54x Cloudistics reports problems related to STP process (pica_mstp) crash. User can restart STP feature from CLI, but the CLI show the protocol is MSTP instead of the configured STP. User has to delete the current force-version and set it back. Then, the show and configuration are consistent. |
9311 | 2.11.9 | Don't Allow to Configure Different Filters to the Same VLAN Interface Add the configuraiton checking which does not allow to configure different firewall filters to the same VLAN interface on ingress side or egress side. |
9246 | 2.11.9 | "set system hostname" Does not Update /etc/hostname Boeing reported that the hostname in /etc/hostname file is not updated with “set system hostname” command, this causes DHCP requests sent on eth0 to advertise as “xorplus.chs.sc.boeing.com” since the hostname in /etc/hostname is "xorplus" |
8921 | 2.11.9 | RR Scheduler Does not Work The RR (Round Robin) scheduler configured to the egress queues behaviors as the mode of SP (Strict Priority) scheduler. |
9383 | 2.11.9 | MSH8920 - Fail to activate LACP and BPDU L2-transparency If "set protocols lacp||stp message-in disable true", the frames of BPDU and LACP are not flooded out of the switch instead of being trapped to CPU. |
4415 | 2.11.16 | Xorp_policy Crash If configure static routes, xorp_policy will crash and generate coredump file when it shuts down. |
9953 | 2.11.7.5 | Maximum Power Setting on UPoE Ports The Maximum power that can be provided by an UPoE power of AS4610-54P is 51 watts instead of 64 watts. So the range of max-power of a specific port is changed to [1..51]. |
9961 | 2.11.7.5 | The Default Value of lldp-negotiation is TRUE To symplify the PoE configurtion, the default value of lldp-negotiation for the setting of global/all and local/per-port is changed to true. |
9873 | 2.11.7.4 | Phone classified as CDP If LLDP Enabled Capabilities are not Set Correctly Customer has phones which do not set LLDP Enabled Capabilities:Telephone correctly (Not Enabled), but the LLDPDU includes Network Policy TLV requesting policy for Voice application. PICOS LLDP/CDP would classify these phones as CDP phones and send untagged voice related traffic to these phones, which is not expected by the phones because of the LLDP-MED negotiation. PICOS should classify the device as a LLDP-MED phone, if the switch receives LLDPDUs from the phone with LLDP-MED Network Policy TLVs for Voice, EVEN IF the base LLDP has “Enabled Capabilities::Telephone=NO”. The logic is that if the device is requesting LLDP-MED Network Policy for Voice, then it must be a phone, and this overrides the fact that Enabled-Capability::Telephone=NO. |
9922 | 2.11.7.4 | PoE Power Provision Error If the Phone Has Different Chassis IDs with Different IP Addresses The attached phone sends LLDPDUs with 2 different Chassis IDs which are the values of the IP addresses. Initially, the Chassis ID/IP address is 0.0.0.0 and then becomes such as 104..255.99.11 when the phone gets an actual IP address from the DHCP sever. The initial LLDPDU with 0.0.0.0 requests 12.1 watt. And the following LLDPDU with 104..255.99.11 requests 15.1 watt. Unfortunately, the LLDPDU with 104..255.99.11 is ignored. PicOS switch should continuously check the the TLV of Power Via MDI and provide the power requested by the TLV from the incoming LLDPDU. |
9884 | 2.11.16 | Add ifSpeed and ifHighSpeed for Port with 25G and 100G Speed ifspeed/ifhighspeed MIB value for port with 25G and 100G is not the value as expected, so we add ifSpeed and ifHighSpeed for port with 25G and 100G speed to make the MIB value correct. |
10020 | 2.11.17 | Add VLAN Display in Dot1x MAB Table Present dynamic VLAN of the connected deviced authenticated by MAB. |
10026 | 2.11.17 | 802.1x Precedes MAB To follow the behavior of Cisco, 802.1x will precede MAB if both 802.1x and MAB are available. |
10255 | 2.11.17 | Add the Service Type Attribute in Access Request Message Add Service Type attribute in the access request messages sent out to RADIUS to differentiate MAB and 802.1x. |
9964 | 2.11.17 | [AS4610-54P]Phone won't power up randomly after disabling & reenabling PoE on UPOE ports. Cisco 8845 IP Phone was powered up and working properly on a UPoE ports (ports ge-1/1/44, ge-1/1/48). After disabling and reenabling PoE, somehow it's possible the phone will no longer power up. |
10313 | 2.11.18 | Don't Allow to Configure 802.1X to LAG Member Port Add config checking to prevent LAG member port from being enabled 802.1X. |
10152 | 2.11.18 | ECMP max Path Should not Be Changed When Disable Symmetric Hashing After commit "delete interface ecmp hash-mapping symmetric" successfully, CLI will prompt message "ECMP max path has been changed, please reboot the system for changes to take effect!". It should not change the ECMP max path if disable symmetric hashing. |
10346 | 2.11.18 | Port is not Deleted when Change the User Status A port is secured by 802.1X and configured with a dynamic VLAN such as VLAN 8. And then the dynamic VLAN is changed to VLAN 9 on the side of RADIUS server such as PacketFence. The re-authentication doesn't change the dynamic VLAN of the port to VLAN 9 on the side of Pica8 switch. |
10692 | 2.11.21 | L2/L3 Protocol Packets cannot Be Trapped to CPU on Delta Models L2 BPDU and L3 protocol packets cannot be trapped to CPU occasionally on Delta models including AG9032 and AG548. |
10983 | 2.11.22 | SNMP Trap is not Send out if RPSU Powered On/Off SNMP trap - rpsuStatusChangePowerOff or rpsuStatusChangePowerOn - is not sent out if RPSU powed on or off. |
8591 | 2.11.22 | Traffic Failed to Be Mapped to Correct Queue For TD+ models, if set a forwarding-class with local-priority such as 2 and associate the specific traffic with this forwarding-class, by counter of BCM shell, the traffic goes to egress queue 0 instead 2. |
8460 | 2.11.22 | [PVST]Wrong Port Role In a network topology, Pica8 switch is connected to a Cisco switch. PVST is enabled on the both switch. When get a port on the Pica8 switch down and then up, somehow the role of another port of the Pica8 switch is not correct. |
11251 | 2.11.22 | Fail to Query ipNetToMediaPhysAddress and atPhysAddress on AG5648 Fail to query out SNMP OID - RFC1213-MIB::atPhysAddress and IP-MIB::ipNetToMediaPhysAddress. |
11281 | 2.11.23 | [Lenovo PVST compatibility] “Organization Code” field in 802.2 LLC packet PICOS sets “Organization Code” field in 802.2 LLC packet to 00:00:00. Lenovo only recognize PVST+ packets if the “Organization Code” is 00:00:0C (Cisco systems, inc.). |
11292 | 2.11.23 | The Length of the Dynamic VLAN Name The maximum length of the dynamic VLAN name should be 32 as the same maximum length of local VLAN name. |
11349 | 2.11.23 | DHCP Vendor-Class Option on N3132 DHCP Vendor-Class option is corrected as "PICOS n3132". |
11407 | 2.11.24 | NAC Enhancement CoA for a specific client will not affect other clients connected to the same port of the switch. If returned CoA has re-authentication action, the switch will start new authentication immediately. |
11427 | 2.11.24 | Print Too Much VRRP Log Messages It's not necessary to issue a warning log message if receive an invalid VRRP packet. |
11560 | 2.11.25 | Include "#" in Shared Key of TACACS+ Session |
11718 | 2.11.25.1 | Crash Caused by DHCP/ICMP Enable DHCP snooping/relay. If received an DHCP OFFER and then immediately an ICMP, it is possible the process pica_sif would crash. |
11738 | 2.11.25.2 | Port Hangs after dot1x CoA-terminate and CoA bounce-port for MAB Authenticated Phone If the configured voice VLAN is equal to the dynamic VLAN for a specific port and connected client device, the port is somehow stuck when receive a CoA terminate message. |
12015 | 2.11.25.3 | DHCP Discovery Packets are Discarded When it Fails to Reach NAC Server The client will fall back to server-fail-vlan when the NAC server is not reachable. In this case, it should allow the client to reach the DHCP server even if DHCP snooping is enabled. |
11920 | 2.11.25.3 | Send out LLDP with Power-Via-MDI TLV for Power Negotiation if PoE is Enabled It's not all PDs (Powered Device) that send out LLDP with power-Via-MDI TLV initially when they request extra power via power negotiation. So the PICOS switch will send out LLDP with power-Via-MDI TLV initially if PoE is enabled on the specific port. |
12257 | 2.11.25.6 | Aruba AP-515 Fails to Receive Power Somehow Aruba AP-515 can not receive power from N3048 UPoE ports (ge-1/1/1 to ge-1/1/12). |
12248 | 2.11.25.7 | DACL Counter Should Be in Packets To keep consistent with the locally configured ACL, the number of counter of downloadable/dynamic ACL should be in packets. |
12329 | 2.11.25.7 | DOT1X Authentication Failed when Configure Two Reachable Servers The client will fail to be authenticated if multiple configured RADIUS servers are reachable. |
12436 | 2.11.25.7 | Switch still Do MAB Auth when Client Send EAP Packet If enable MAB and 802.1x on a specific port, and EAP is reaceived from the client on this port, the client can only be authenticated by 802.1x which has higher priority than MAB. |
12508 | 2.11.25.7 | Lower the Level of a LOG Message Lower the level of the log message, such as "The mac address 00:24:14:b3:68:3a is NAC session, ignore it", to "TRACE". |
Routing Protocols
Bug ID | Release | Description |
---|---|---|
7978 | 2.11.0 | Error BGP Statistics |
Open vSwitch and OpenFlow
Bug ID | Release | Description |
---|---|---|
8301 | 2.11.0 | Statistics Error on Tunnel Packets |
8467 | 2.11.0 | Command ovs-pica-save/ovs-pica-load does not Work Occasionally |
8596 | 2.11.0 | DHCP Cycle in CrossFlow Mode |
8978 | 2.11.4 | Install the Flow Entry to ASIC Even If User Try to Set DSCP to 0 |
9171 | 2.11.7 | Linux is in Panic |
9757 | 2.11.1.npb/2.11.14 | ARP Proxy Does not Work on Tunnel Port If enable ARP proxy enable on tunnel's network port, it will send out arp reply packet which has a tunnel header. |
6641 | 2.11.11 | Support 6k Flow Entries for AS5812 and AS6812 Allow to configure maximum 6k flow entries on AS5812_54T and AS5812_54X and AS6812. |
9211 | 2.11.8 | AS5812 OVS Sflow Function Fails to Generate Flow Samples In OVS 2.6, sflow only generates counter samples (CNTR) but not flow samples (FLOW). |
9256 | 2.11.8 | Refine the Performance by Adding Large Amount of Flow Entries In case of same priority, the time to add 4k flow entries is reduced dramatically on AS5812. |
8943 | 2.11.8 | It Takes Too Long to Deletes 6k Flows on AS5812 and AS6812 It takes 20 minutes to delete 6k flow entries. It's too long. |
9609 | Convert OVSDB to Match New Schema in Upgrade2 PicOS OVS uses OVSDB to restore the configurations. It's possible that the schema of the OVSDB would be changed because new cofinguation commands might be added to the new version of PicOS. To bring the OVSDB into the new version of PicOS by upgrade2, the OVSDB should be converted to adapt the the new schema of the new version of PicOS. | |
10038 | 2.11.17 | Enable In-band under Match Mode OpenFlow in-band controller connection is enabled under match mode. |
9054 | 2.11.17 | Update Action in the Hardware Flows if Delete/Add Port to the Bridge Delete a port from the bridge, the action of the hardware flows with the specific port as output should be updated as "drop". If the port is added back to the bridge, the hardware flows should come back to the original ones. |
10725 | 2.11.21 | Delete L2GRE Ports If add and then delete a L2GRE port, the configuration associated with this L2GRE port in MPLS_ENTRY is not be removed. |
10701 | 2.11.21 | OVS Web automatically logout after specific time with no activity After login the OVS Web UI, if don't access to it, the WebUI should be disconnected automatically after specified timeout (60 seconds). |
11231 | 2.11.23 | Issue Error Log messages If Insert Too Many 1000BASE-T SFP Modules to AS7312-54X If inserted too many (>25) 1000BASE-T SFP modules to AS7312-54X, somehow the OVS threads could be blocked and some actions such as flow modification will take much longer. |
11266 | 2.11.23 | "Permission Error" is Returned by Adding Flow When repeat adding/deleting 900 flow entries on AS7312-54X, it's possible to return "permissions error" by adding new flows. |
11382 | 2.11.24 | OVS Crash This crash can be reproduced when sflow is enabled meanwhile a flow entry is added as following: ovs-ofctl add-flow br0 priority=10,actions=drop |
Security
Bug ID | Release | Description |
---|---|---|
9031 | 2.11.4 | Apply Policer to Aggregate Traffic |
Miscellaneous
Bug ID | Release | Description |
---|---|---|
9196 | 2.11.7 | Issue SNMP Trap if LAG Member Port Links Up/Down |
9232 | 2.11.7 | Protocol Packets are Counted to Discarded |
9252 | 2.11.7 | SNMP - Value of ifLastChange is Always 0 |
9265 | 2.11.7 | SNMP - Value of sysUpTime is not in Timetick |
7882 | 2.11.17 | [AG9032] PICOS Can't Boot up PICOS 2.11.16 cannot boot up on AG9032. Certain Delta switches such as AG9032 request to reset MAC via CPLD from software when reboot system by "reboot -f". |