User guide

29
Release Notes for Cisco Router and Security Device Manager 2.5
OL-5009-20
Caveats
If you prefer to use the Cisco IOS CLI, enter the following commands to remove the loopback
interface and NAT rule that were added to allow Cisco SDM access. In these steps, Loopback 0
with an IP address of 192.168.1.1, and FastEthernet 0/0 with an IP address of 10.20.30.40 are
used as examples.
Router# config t
Router(config)# no interface Loopback0
Router(config)# interface FastEthernet0/0
Router(config-if)# no ip nat outside
Router(config-if)# exit
Router(config)# no ip nat inside source static tcp 192.168.1.1 443 10.20.30.40
4443
Router(config)# exit
Note Do not enter the no ip nat inside command if other NAT translation rules are using it. If no
other rules use this command, remove it.
CSCsd28755
When you import signatures from a large Signature Definition File (SDF) more than 4 or 5 times
during the same session, Cisco SDM may close. This problem has not been observed consistently.
This problem has no workaround.
CSCek33306
Cisco SDM may not launch from an interface with a CLI-configured SSL VPN if the CLI commands
necessary for Cisco SDM access have not been added. This includes SSL VPNs configured with the
command webvpn enable SSLVPNname IP-address SSLVPN.
For more information about this caveat, see the “Cisco SDM May not Launch Using IP Address of
SSL VPN Gateway” section on page 17.
CSCsd33430
Cisco SDM Express browser windows do not close if the Secure Device Provisioning application is
launched from Cisco SDM Express. If you choose Secure Device Provision in the Router
Provisioning screen, the SDP application is launched after you complete the Cisco SDM Express
wizard and deliver the commands to the router. After the commands are delivered,
Cisco SDM Express closes, but the two browser windows associated with Cisco SDM Express do
not close automatically. This behavior has been observed in all browsers.
Workaround: Close these windows manually. However, note that closing these windows manually
also closes the SDP application. Therefore, do not close these windows until you have completed
configuring the router using the SDP application.
CSCei33081
When Cisco SDM is run on the PC, the Load File from PC function available from the File
Management window may not work properly.
Workaround: With a TFTP server application on the PC, copy files to the router using the copy tftp
flash command.
CSCej01054
The SDM_HIGH security policy may not block Instant Messaging (IM) applications. The
application security feature blocks IM applications using the server deny name command. New
servers may become available, and if they do, IM applications may connect to them.
Workaround: Complete the following steps: