Release Notes for Cisco Catalyst Blade Switch 3120 for HP Cisco IOS Release 12.2(40)EX

12
Release Notes for Cisco Catalyst Blade Switch 3120 for HP, Cisco IOS Release 12.2(40)EX1
OL-12250-01
Limitations and Restrictions
EtherChannel for the new set of active physical ports and can happen when the cross-stack
EtherChannel is configured with either mode ON or LACP. This problem might not occur with all
link-up or link-down events.
No workaround is necessary. The problem corrects itself after the link-up or link-down event.
(CSCse75508)
IEEE 802.1x Authentication
These are the IEEE 802.1x authentication limitations:
If a supplicant using a Marvel Yukon network interface card (NIC) is connected to an
IEEE
802.1x-authorized port in multihost mode, the extra MAC address of 0c00.0000.0000 appears
in the MAC address table.
Use one of these workarounds (CSCsd90495):
Configure the port for single-host mode to prevent the extra MAC address from appearing in the
MAC address table.
Replace the NIC with a new card.
When MAC authentication bypass is configured to use Extensible Authentication Protocol (EAP)
for authorization and critical authentication is configured to assign a critical port to an access
VLAN:
If the connected device is supposed to be unauthorized, the connected device might be
authorized on the VLAN that is assigned to the critical port instead of to a guest VLAN.
If the device is supposed to be authorized, it is authorized on the VLAN that is assigned to the
critical port.
Use one of these workarounds (CSCse04534):
Configure MAC authentication bypass to not use EAP.
Define your network access profiles to not use MAC authentication bypass. For more
information, see the Cisco Access Control Server (ACS) documentation.
When IEEE 802.1x authentication with VLAN assignment is enabled, a CPUHOG message might
appear if the switch is authenticating supplicants in a switch stack.
The workaround is not use the VLAN assignment option. (CSCse22791)
Multicasting
These are the multicasting limitations:
Multicast packets with a time-to-live (TTL) value of 0 or 1 are flooded in the incoming VLAN when
all of these conditions are met:
Multicast routing is enabled in the VLAN.
The source IP address of the packet belongs to the directly connected network.
The TTL value is either 0 or 1.
The workaround is to not generate multicast packets with a TTL value of 0 or 1, or disable multicast
routing in the VLAN. (CSCeh21660)