Release Notes

Cisco NX-OS Release 11.0(3k) Release Notes for Cisco Nexus 9000 Series ACI-Mode Switches
Compatibility Information
6
2. After all APICs in the cluster are successfully downgraded, downgrade all the switches in the fabric.
Note: Switch models N9K-C9372PX, N9K-C9332PQ, and N9K-C9372TX are not supported for downgrading in the APIC
1.0(2x) or the Cisco Nexus 9000 11.0(2x) releases. If your fabric has those models, do not downgrade.
Compatibility Information
Cisco NX-OS Release 11.0(3k) supports the hardware and software listed on the ACI Ecosystem Compatibility
List and the Cisco AVS, Release 4.2(1)SV2(2.3).
The breakout of 40G ports to 4x10G on the N9332PQ switch is not supported in ACI-Mode
To connect the APIC (the controller cluster) to the ACI fabric, it is required to have a 10G interface on the ACI
leaf. You cannot connect the APIC directly to the N9332PQ ACI spine.
Usage Guidelines
The current list of protocols that are allowed (and cannot be blocked through contracts) include the following.
Some of the protocols have SrcPort/DstPort distinction.
Note: Also see the APIC release notes for policy information: http://www.cisco.com/c/en/us/support/cloud-
systems-management/application-policy-infrastructure-controller-apic/tsd-products-support-series-home.html
UDP DestPort 161: SNMP. These cannot be blocked through contracts. Creating an SNMP ClientGroup
with a list of Client-IP Addresses restricts SNMP access to only those configured Client-IP Addresses.
If no Client-IP address is configured, SNMP packets are allowed from anywhere.
TCP SrcPort 179: BGP
TCP DstPort 179: BGP
OSPF
UDP DstPort 67: BOOTP/DHCP
UDP DstPort 68: BOOTP/DHCP
IGMP
PIM
UDP SrcPort 53: DNS replies
TCP SrcPort 25: SMTP replies
TCP DstPort 443: HTTPS
UDP SrcPort 123: NTP
UDP DstPort 123: NTP
Caveats
This section contains lists of open and resolved caveats and known behaviors.