Release Notes

47
Release Notes for the Catalyst 4500E Series Switch, Cisco IOS XE Release 3.3.xSG
OL-26675-02
Caveats
Open Caveats for Cisco IOS XE Release 3.3.0SG
This section lists the open caveats for Cisco IOS XE Release 3.3.0SG:
When an SNMP query includes the cpmCPUProcessHistoryTable, the query time is very slow, and
CPU utilization of the os_info_p process (OS Info provider) increases substantially. The time
required for a full walk of an almost fully populated table is 68 minutes.
Workaround: None. CSCth42248
The show ipv6 access-list command displays incorrect match counts when multicast traffic is
matched to an IPv6 access list that is attached to an SVI.
Workaround: None. CSCth65129
When either the RADIUS-server test feature is enabled or RADIUS-server dead-criteria is
configured, and either RADIUS-server deadtime is set to 0 or not configured, the RADIUS-server
status is not properly relayed to AAA.
Workaround: Configure both dead-criteria and deadtime.
radius-server dead-criteria
radius-server deadtime
CSCtl06706
When you configure open authentication and perform SSO, the spanning tree state and MAC address
are not synchronized to the new standby supervisor engine. This behavior interrupts traffic only after
the second switchover because the new standby supervisor engine possesses the wrong state after
the initial switchover and the second switchover starts the port in the blocking state.
Workaround: Enter shut and no shut on the port to synchronize the STP state. CSCtf52437
If you reboot a switch, the configured value of the interface MTU size for the elements of the port
channel interface does not work for IPv6 traffic.
Workaround: After the switch reloads, enter shut and no shut on the port-channel interface.
CSCto27085
Dynamic buffer limiting might not function at queue limits less than or equal to 128.
Workaround: Increase the queue limit to at least 256. CSCto57602
If you use the quick option in the issu changeversion command, the following might occur:
Links flap for various Layer 3 protocols.
A traffic loss of several seconds is observed during the upgrade process.
Workaround: Do not use the quick option with the issu changeversion command. CSCto51562
A device in a guest VLAN that is connected behind a phone that is capable of 2nd-port-notification
experiences packet loss following a SSO failover. The device experiences an authentication restart
after the first CDP frame arrives from the phone.
Workaround: None. CSCto46018
Dynamic ACLs do not function correctly if they have advanced operators, including dscp/ipp/tos,
log/log-input, fragments, and TCP flag operators.
Workaround: Remove these operators from any dynamic ACLs. CSCts05302
If you perform an OIR on a line card, several %C4K_RKNOVA-4-INVALIDTOKENEXPIRED
messages appear in the logs.
Workaround: None. CSCtu37959