TNSR 26.02.1 Release Notes¶
About the TNSR 26.02.1 Release¶
This is a maintenance release for TNSR software version 26.02 with bug fixes.
General¶
Changes¶
Changes in TNSR software version 26.02.1
Host¶
Fixed: Crash in
clixondue to unexpected empty tag in host interface configuration [22318]
VPF Filter/NAT¶
Fixed: Potential VPF crash if the same connection-creating packets belonging to an endpoint-independent NAT rule land on different workers [22421]
Fixed: Dataplane crash from VPF with a stateful rule and static NAT for ICMP [22909]
Known Issues¶
Known Issues in TNSR software version 26.02.1
ACLs¶
ACL with deny rule partially drops fragmented packets [12664]
MACIP ACL requires
ip-versionwhen not specifying an IP address on the ACL [16764]
Authentication¶
Timeout option in LDAP configuration does not work as expected [13420]
Specifying a source IPv6 address in RADIUS configuration does not work correctly [15900]
Unable to retrieve LDAP configuration via RESTCONF [16018]
Cannot delete LDAP transport options using RESTCONF [16244]
RADIUS does not support servers located in custom VRFs [16642]
Incorrect ownership on user SSH keys prevents successful authentication [16722]
BFD¶
IPv6 session is not restored when virtual direct link gets disabled/enabled [4916]
TNSR cannot commit configuration candidate database loaded from a file if it contains a BFD session for an interface that does not exist [7150]
BFD configuration inconsistently displayed [9425]
No ping response from peer when BFD session is down [9447]
IPv6 BFD sessions are intolerant of dataplane restart [9475]
Incorrect message in logs when upgrading BFD model [22509]
Backup¶
Configuration changes not being committed in Git [20459]
Bridge¶
Bridging fails with virtual interfaces as members [7762]
TNSR does not retransmit ARP replies if
arp entryoption is enabled in a bridge domain [10880]Bridge domain
shgandbvioptions cannot be removed alone without bridge domain in interface configuration [10926]Options
floodanduu-floodinconfig-bridgemode look the same in VPP DPDK trace [11113]
CLI¶
Deleting the startup configuration database does not fully remove the active configuration [3723]
Specifying interface to traceroute requires root privileges [5376]
Input validation of unbound
message cache slabsvalue does not work as expected [5472]CLI and RESTCONF behavior are different for
no bgp default ipv4-unicast[6303]RIP information does not contain a legend for kernel routes [7230]
CLI shows incorrect routing table attached to an interface in cloud environments [10589]
VRRP prints empty interface definitions in
show config running clioutput [11072]Update “reflect” action description under ACL config [11093]
CLI expansion works incorrectly for OSPF/OSPF6 area configuration [11152]
Incorrect CLI expansion for VLAN tags configured on a sub-interface [11508]
CLI commands are not generated for RESTCONF coredump configuration [11650]
It is impossible to remove RESTCONF certificates and key via CLI [11685]
RESTCONF status does not show information about multiple sockets [11691]
CLI commands containing RX queue configuration fail to apply on a clean TNSR instance [11737]
Excess newlines are added to
user-keycontent when adding an SSH key from the CLI [12369]Unable to delete password from authentication user entry via CLI [12482]
CLI expansion and verification do not work for
next-hop-tablefield when creating a static route [12494]Attempting to set a description on a BGP
prefix-listfails [13073]show ipsec tunnelexits with an error when TNSR has no IPsec configuration [13463]Attempting to remove a single NAT pool address results in “Unspecified Error” message [16150]
CLI expansion help text is unclear when entering
matchas-pathin route map configuration [16242]TNSR does not validate
networkaddress location within BGPaddress-familyconfiguration [16407]Values for
after-timeandbefore-timeoptions forshow loggingcommand are not validated [16578]CLI freezes when trying to run
show route | match <text>command with a large routing table [16625]| countand| tailoptions in CLI work very slowly for large command output [17145]Configuring host interface static address does not persist, reverts to DHCP [17922]
Contradictive CLI error messages of allowed values for unsigned integer parameters [19043]
CLI expansion failure when configuring DHCP Relay in autocli [20057]
Cannot set interface description via AutoCLI if any interface configuration already exists [20121]
AutoCLI does not fully validate partial MAC address input for existing neighbors [20122]
Within the LDAP configuration process, it is not possible to configure an IPv4 address [20151]
Within the RADIUS configuration process, it is not possible to configure an IPv4 address [20152]
Unable to filter output of
show route dynamiccommand for OSPF and OSPF6 [20279]help commandsshowsdebugcommand, which was removed from CLI expansion [22463]Incomplete configuration if applying a CLI format configuration file containing
system bannercommands [22665]Incorrect CLI commands are generated if a
route-map-filterconfiguration exists for both directions on same interface [22798]CLI expansion fails when trying to remove RIP
route-map-filterconfiguration [22799]Forced logout when exiting
show interface X counters rolling interval Nusing Ctrl-c [22928]AutoCLI expansion for IS-IS interface
area-tagfails when interface name contains/[22937]RIP
auth-lengthoption cannot be removed separately [23026]Unable to delete VPF HA exporter/importer using AutoCLI [23112]
Clixon¶
clixon_backendexhausts memory while displaying a large volume of routes [5226]Configuration upgrade does not run when loading configuration via history [6968]
Unable to set up a password that starts and finishes with a double quotation mark [7571]
Unable to set up a password that contains a backslash symbol [7572]
clixon_backendfails when configured interfaces are not present in hardware [11518]clixon_backendfails if any PKI entries referenced in the RESTCONF configuration are missing [11988]RIP interface
key-chainvalue is not validated when configured via RESTCONF [17396]Error when explicitly restarting
clixon-backendwith an ACL applied to an interface [20754]Clixon backend stops with
SIGABRTerror and fails to restart [21253]Remote syslog server does not function without explicitly configured namespace [22439]
service dataplane restartcommand reports RPC failure when restart exceeds backend timeout [22517]Contradictive CLI error messages of allowed values for uint8 parameters [23121]
DHCP Client¶
Host OS
systemd-networkdservice defaults toDHCPv4/RoutesToDNS=trueeven when the DNS server is non-adjacent [11444]DHCP client in dataplane namespace cannot generate
resolv.conf[19970]
DHCP Server¶
CLI offers to delete mandatory variable in DHCP server subnet configuration [5240]
DHCP4 Kea
config-fileoutput shows VPP TAP interface names in its configuration instead of TNSR interface names [5264]Unable to setup a custom DHCP option with certain data types in the record [5299]
The command
no authoritativein global DHCP server configuration does not work as expected [12388]TNSR incorrectly allows configuring a DHCP pool outside the subnet on an interface, which prevents the DHCP daemon from starting [12470]
DHCP relay proxies DHCPv6 packets other than
SOLICITto first server only [17815]DHCP option
boot-file-nameis terminated with0xff[20049]
DNS¶
show systemoutput does not contain DNS resolver parameters [5397]Unbound fails to start with one or more values set to zero [11773]
Unbound cannot be configured to bind on IPv6 address [11854]
RESTCONF allows configuring a port for the system DNS resolver but it is not used or supported by the host OS [12307]
Dataplane¶
Cannot create
rx-queuesfor interfaces on KVM and VirtualBox [3674]TNSR on AWS does not pass traffic when using the
igb_uiooruio_pci_genericdriver [7015]SEGV in VPP [9312]
Dataplane fails to start up after system reboot if it is configured to use number of huge pages that exceeds the default number [10848]
Interrupt mode does not work on
mlx5driver NICs [11222]VPP fails to start after configuring DPDK network device
defaultin TNSR [11949]Inconsistent behavior of CLI and RESTCONF when
dataplane dpdk outer-checksum-offloadis enabled [12585]Dataplane does not prevent adding the same interface to whitelist and blacklist on Azure [12595]
VPP debug console
show errorsoutput includes info/error counts for graph nodes which are not in use [13035]vHost User interfaces cannot be placed in adaptive mode when not linked to virtual machine [13233]
Configuring a vHost User interface with Interrupt or adaptive mode causes loss of connectivity [13237]
Interrupt
rx-modefails with Ethernet Controller I226-V (rev 04) [15756]2MB hugepages improperly allocated on multi-NUMA systems [15987]
Adaptive mode on virtio interfaces caues loss of connectivity [17098]
Dataplane
uio-driver igb_uiois non-functional in Noble builds with default kernel options [19285]Requesting CPU state in TNSR may lead to XML error [20249]
Maximum OSPF adjacency count is constrained by Linux IGMP group membership limit [20447]
Packets with IPv4
Timestampoption are not passed through TNSR [21614]Dataplane crash during arp-reply [22869]
General¶
Non-root users cannot access the FRR log file [4826]
Unable to specify TNSR interface as a source in
pingandtraceroutecommands via REST [5605]Startup entry is not created in configuration history log [7400]
Cannot commit a candidate configuration database if a
tapinterface is present [7458]system-pingcall via REST does not return any data if it is called withtimeoutflag and no response from the server [10608]tnsr-backuputility does not back up or restore file ownership data [11270]Service control operations for a specific FRR service affect all FRR services [11592]
Remote logging does not support servers located in custom VRFs [16650]
TNSR does not update the address of a remote logging server configured with an FQDN if the server IP address changes [16654]
Unnecessary attempts are made to stop services which are not running during
clixon_backendstartup [19973]Enabling NETCONF does not work without a reboot [21597]
System timezone is not restored from
startup_dbafter TNSR restart [21615]show systemunevenly displays output for system banner [21618]Error expanding remote syslog
no namespacecommand [22815]tnsrshcannot be launched if upgrade fails and required libraries are missing [23053]
Host¶
Cannot configure the default gateway for host namespace via TNSR CLI [3702]
VRF interface for a custom route table persists in the operating system after restarting services [4866]
dns-resolverconfigured for host namespace remains in system after removing from TNSR [7830]dns-resolverconfiguration values forhostnamespace remain inresolv.confafter restarting TNSR [7975]Some host route options configured in TNSR are not applied correctly by the Linux network subsystem [10827]
Some types of host static routes are not displayed by
show host routecommand [10905]Option
scopefor IPv6 host static routes does not apply in the Linux network subsystem [11011]DNS issues can occur with netplan configurations containing static interface addresses [11017]
TNSR shows incorrect Link MTU for host OS loopback (
lo) interface [11596]Host ACLs created in TNSR are not removed when restarting with a clean startup configuration database [16400]
Host ACL descriptions are not displayed anywhere [16453]
Host ACL rule pointing to a missing host interface gets applied anyway [16612]
show systemCLI command output includes inaccurate hardcoded product values [19402]Incorrect CLI output for
system timezonecommands, output contains trailing.[22645]
Host Netfilter¶
TNSR incorrectly creates host ACL rules with only IP version configured [16208]
IPsec¶
IPsec daemon does not support using non-default VRF entries [7266]
Cannot disable IPsec
dpd-intervaloption [8012]Cannot configure IPsec with
manualkey type [8396]IPsec tunnel without a child SA does not appear in IPsec state data [8433]
IPsec tunnel with initially unresolvable FQDN destination does not pass traffic after remote address gets resolved if there is another IPsec tunnel using the same source [10798]
IPsec EAP RADIUS configuration is not restored after TNSR restarts [21675]
IPsec may install a dummy security association during rekey [22701]
Installation¶
TNSR installer fails if interfaces are configured with IP addresses but have no Internet connectivity [7807]
Clean installation doesn’t have input validation for multiple gateways [17133]
Interfaces¶
Invalid routes remain in table when next-hop IP address is no longer directly connected [3161]
Reassembly timeout is not working when full IP reassembly is configured [3269]
Shallow virtual reassembly cannot be disabled when it is implicitly enabled by other features [3361]
Unable to delete a MAC address explicitly set for the TNSR side of a TAP interface [4433]
Netgate 1541 link speed auto-negotiation incorrect with direct connected interfaces [5323]
Errors indicate TNSR is attempting to add a MAC address to IPsec
ipipXinterfaces [6285]L3 packets can be sent from bridged interfaces [6975]
Unable to setup DPDK
uio_pci_genericdriver on Netgate 1541 [6981]TAP instance
tcpdumpmethod only captures received packets [7137]Pings between IPIP interfaces become intermittent when BGP is applied to them [7392]
Interface IP address is shown in IPv4 route table instead of associated subnet [7511]
Setting a new MTU value does not affect the MRU for IPv6 packets [8245]
Unable to delete link MTU from an interface when default MTU is set less than
1280[8837]Evaluate presence of interface configuration items for loopback interfaces [9380]
show interface tapdoes not print IPv4 and IPv6 gateway information [10849]show interface <name> subifcommand does not produce any output [10879]Unable to configure interrupt mode with driver set to
uio_pci_generic[11279]It is possible to configure a multicast or broadcast MAC address on an interface [11454]
VPP can push unlimited number of VLAN tags to a packet [11509]
IPv6 ping from TNSR through a vhost-user interface stops working after down/up of
eth0interface in guest VM [11847]Unable to create a guest VM when a vhost-user interface configured as
server-mode[11864]Restarting the dataplane service when a vhost-user interface is in
server-modecauses theVirtualEthernetinterface to shut down [11885]no enable event-indexcommand disables avhost-userinterface [11890]Removing vhost-user options
disable merge-rx-buffersordisable indirect-descriptorsdoes not affect the vhost-user interface state [11896]Removing vhost-user options
disable merge-rx-buffers,disable indirect-descriptorsdisables a vhost-user interface inserver-mode[11929]Configuring MAC address on bond interface causes its subinterface to disappear [12139]
Configuring the same VLAN tag on multiple subinterfaces causes an existing subinterface to disappear [12394]
Bond interfaces take longer than expected to pass traffic on hardware installations [12615]
Adaptive mode on vhost-user interfaces does not place the interface in adaptive mode [13232]
Users are unable to authenticate against any LDAP server after a failed member of a server group recovers [15781]
The
show ldapcommand does not provide correct information which LDAP server is used for authentication [15787]The
show radius serverscommand does not provide correct information about which RADIUS server is used for authentication [15788]IPsec ignores RADIUS
source-addressconfiguration [15810]Error applying one configuration over another when loading candidate configuration databases from files [15816]
TNSR does not display the value of
vhost-userinterfacepacked-ringoption [15879]A disabled bond LACP interface continues to send LACPDUs [16857]
Interfaces with enabled MAP don’t accept Neighbor Advertisement packets [17087]
Bond interface MTU is not configured on slave interfaces [18616]
Cannot make an interface unnumbered if it is attached to a custom VRF [19666]
Interface state stays untouched when applying a candidate containing unnumbered interface with missing master [19804]
Unattached interfaces are not handled properly when changing their children nodes [19861]
Cannot configure
rx-modeonlinux-cpTAP for bond interfaces [19911]Cannot change link MTU on some hardware interfaces [21706]
tapinterface creation in VPP with duplicated host interface name causes SIGABRT [22219]Impossible to create a sub-interface with very large ID value [22311]
Possible inconsistent state when deleting sub-interfaces [22634]
VPP converts unsigned sub-interface ID values to signed [22635]
LACP¶
Packet capture on bond interface only sees outbound packets [21594]
LLDP¶
no lldp enablecommand shows CLI error [10925]LLDP interface configuration parameters cannot be removed via CLI [10982]
TNSR sends incorrect LLDP management address if only
lldp port-nameis configured on an interface [11047]TNSR continues sending LLDP frames after
lldp port-nameis removed from an interface using RESTCONF [11048]LLDP router configuration cannot be removed [11049]
Unable to configure LLDP on bond interface members [22931]
Memif¶
Unable to connect to
memifinterface using default socket [4448]It is possible to have a memif interface pointing to a nonexistent socket [11201]
Incorrect state data is shown for memif interfaces [11202]
Dataplane restart required to change memif interface configuration [11220]
VPP crashes when sending some commands to its memif socket [11293]
Its possible to create memif socket with incorrect filename [11295]
Memif socket file still exists in Host OS filesystem after being deleted from TNSR [11365]
Link status of the memif interface can be
upeven if admin status isdown[11474]Value for
memifinterfacering-sizecannot be set higher than14[20339]Value of
memifoptionsring-sizeandbuffer-sizecan be configured regardless ofmemifinterface role [20475]
NACM¶
It is possible to remove an NACM group used in a rule list [10115]
NAT¶
Full IP reassembly does not work with MAP [3386]
MAP-T adds bogus zeroes when translating short IPv4 to IPv6 [3460]
NAT pool route table option only available when specifying a range [3628]
Packets larger than
2034bytes are dropped when performing IPv4 to IPv6 MAP translation [3742]MAP-T domain usage causes IPv6 traffic class value to always be copied from IPv4 ToS value [3774]
TCP MSS value is not applied to IPv4 packets when IPv6 to IPv4 decapsulation is performed on MAP-E BR [3783]
MAP does not relay IPv6 ICMP error messages to IPv4 [3809]
NAT static mappings assume external port
0when port is omitted [4432]Dataplane SIGSEGV crash and backtrace when exceeding NAT session limit [6551]
Unable to establish NAT hairpin connection [8014]
Traffic from TNSR itself sourced from inside NAT interface does not get NAT applied when egressing via NAT outside interface [9706]
clixon-backendfails to start due to leftover Dataplane NAT configuration [18670]
NTP¶
NTP does not properly handle IPv6 restrictions [4626]
Delay in CLI display of NTP configuration when NTP has
noqueryset [6818]Interfaces in the TNSR NTP configuration are not validated when generating the NTP daemon configuration [7153]
NTP daemon does not collect statistics [13483]
NTP does not switch to orphan mode even if all UTC reference peers below this stratum are unreachable [13511]
NTP does not take
tinker panicvalue into account when synchronizing the clock with a remote peer [15741]No CLI expansion when configuring NTP interface binding [20881]
Neighbor / ARP / NDP¶
Packet loss during ARP transactions [2868]
The MAC address of a static IPv6 neighbor cannot be changed [4454]
Neighbor cache value for
max-numberis not honored if current neighbor count is larger than the configured value [12389]Neighbor option
no-adj-route-table-entrydoes not function as expected [12614]Static neighbor entries disappear from the state table after interface is disabled and enabled [23057]
Operating System¶
Errors at boot from enabled but unpopulated Universal Flash Storage Host Controller Driver (
ufshcd) storage [11633]Poor read/write performance when installed to eMMC (15GB Ultra HS-COMBO) [11688]
systemd timer update-notifier-download.serviceruns every 24 hours but does not appear to do anything [15950]systemd timer motd-news.timerruns twice a day and logs a failure message [16026]
PKI¶
PKCS#12 archives are not generated correctly when the
ca-nameis not specified [10320]PKI private key algorithm
ec-p256does not work properly when configured via RESTCONF/GUI [16130]
RESTCONF¶
Adding a user via RESTCONF requires a password even when providing an ssh key [2875]
RESTCONF “pretty-printed” JSON contains incorrect indentation [3521]
OSPF interfaces are not validated when configured via RESTCONF [3528]
Cannot change GRE tunnel type to or from ERSPAN via RESTCONF [4353]
Response of
/restconf/data/and/restconf/data/netgate-interface:interfaces-state/does not include any of*-table[5399]RESTCONF allows configuring dataplane options for non-existent devices [5748]
RESTCONF
route-stateresponse does not contain actual state data [7115]RESTCONF dataplane service does not work on interfaces in a non-default VRF [7265]
History version count does not match the count of REST configuration requests if they are sent without a delay [7440]
Unable to clear trace filters over RESTCONF [9476]
RESTCONF does not validate payload body to prevent invalid arguments in certain cases [10413]
Non-working RPC left in TNSR after removal of NGINX [11603]
Incorrect status can be shown for RESTCONF service [11657]
service restconf coredumpparameters inconsistent with all otherservice <name> coredumpcommands [18277]
Routing¶
BGP updates for new prefixes ignore the advertisement-interval value and are sent every 60 seconds [2757]
BGP network backdoor feature isn’t working without service restart [2873]
BGP next-hop attribute aren’t being sent unmodified to the eBGP peer when route-server-client option is configured [2940]
Unable to verify dynamic BGP peer information from TNSR CLI [3044]
Unable to delete OSPF3 config for an interface [3481]
TNSR does not prevent creating static routes for directly connected networks [3813]
Unable to verify received routes when high number of routes received via BGP [3918]
TNSR allows OSPF network type for a loopback interface, which is rejected by FRR [4800]
Reverting to the startup configuration doesn’t restore packet forwarding for BGP over IPsec prefixes [5321]
RIP
route-map-filteroption does not filter routes [5910]Unable to disable IPv4 AF without BGP service restart [6393]
BGP failover logs “Failed to delete neighbor” error from
linux-cp[6400]Unable to remove OSPF
virtual-linkconfiguration [6962]Cannot add a static recursive route [7010]
VPP crashes on applying custom VRF to loopback interface used in OSPF [7056]
Creating
route-map,prefix-list, oraccess-listentries takes longer than expected [7068]Cannot disable logging of adjacency changes for OSPF6 if
detailoption is set [7097]Routes that exactly overlap an interface link route are accepted by CLI but are problematic [7101]
Interfaces in the TNSR RIP configuration are not validated when generating the FRR RIP daemon configuration [7155]
Interfaces in TNSR
route-mapentries are not validated when generating the FRR daemon configurations [7156]Interfaces in the TNSR OSPF configuration are not validated when generating the FRR OSPF daemon configuration [7177]
Interfaces in the TNSR BGP configuration are not validated when generating the FRR BGP daemon configuration [7218]
OSPF logging for some options does not work if logging level is set explicitly [7411]
BGP address family neighbor option
maximum-prefix restartdoes not work correctly [7709]Malfunction of BGP process after entering
maximum-prefix restartwithout the basicmaximum-prefix limitcommand [7748]OSPF6 does not advertise loopback address to another area if the loopback is configured first [7757]
Routes remain in table after interface with VRRP configured is marked down until dataplane is restarted [7790]
Routes do not match by
route-mapif match criteria is set toip next-hop ...[8148]Output of show conf differs for route-map [8375]
Route map
source-protocolmatch condition matches routes from any source [8381]Forwarding address from OSPF6 LSA5 is not installed as the next hop for the route [8732]
BGP
bestpath med missing-as-worstcommand does not function correctly [8805]Route Map with IPv6 Access List does not filter redistributed OSPF6 routes [8857]
Route-Map
set srcoption does not function correctly [9045]show routedisplays no routes for a VRF until it is placed on an interface [9073]FRR cannot connect to RPKI cache server if a route to it does not exist in default VRF [9146]
The
redistribute kernelandimport vrfBGP options do not work at the same time if the static route is redistributed with an output interface in a third-party VRF [9147]Applying a subsequent route map with
import vrfcancels a previous applied route map [9156]A route map applied to the
import vrfoption using a prefix list does not work correctly [9235]Changing BGP
as-numberin default VRF leads to the termination of the import of routes to another VRF [9244]Cannot change an interface to a new VRF when BGP is configured to import the current VRF [9259]
Changing an interface VRF does not stop importing routes from the previous VRF [9298]
Route maps with
match rpki *conditions do not get re-applied when RPKI status of routes changes [9439]set communitycommand disappears from FRR configuration without warning after setting an invalid community [9508]BGP
soft-reconfiguration inboundoption does not work for IPv6 peers [10086]BGP selects incorrect path to a network when changing
bestpathrules [10210]zebracauses out-of-memory error on AWS when restarting TNSR after receiving 1.5-2 million prefixes via BGP [10273]FRR fails to reload configuration if
set as-path prependvalues are incorrectly enclosed in quotes [10309]OSPF6 conditional default route injection does not work correctly [10311]
BGP
route-reflector-clientoption does not work on neighbor configurations using IP addresses instead of peer groups [10356]Cannot remove BGP
unsuppress-mapoption by route-map name for IPv6 neighbor [10409]Unexpected delay in distribution of route information between OSPF database and RIB during propagation of OSPF default route [10721]
Static route with next-hop IP address located on a DHCP client interface causes
clixon_backendto fail [11765]Routes with a
via localdestination are not available to FRR as kernel routes [11887]CLI expansion does not work for
prefix-listconfiguration in BGPaddress-family/neighborsection [11888]A
prefix-listcan be configured with an invalid sequence number (0) [11889]TNSR fails to show routes if there are IPv4 routes with IPv6 next-hops [12060]
TNSR cannot commit configuration candidate database loaded from a file if it contains changed ABF policy attached to interface [12248]
BFD in a non-default VRF takes longer than expected to act on peer state changes [12500]
RIP outgoing
offset-listdoes not function when configured together with incomingoffset-liston the same interface [12718]Cannot configure an administrative distance for a static route which is respected by dynamic routing [12761]
RIP
distribution-listentries do not work correctly [12762]BGP
graceful-restartoptionselect-defer-timedoes not function as expected [12946]BGP
graceful-restartstatus includes duplicate IPv6 neighbor information [12979]BGP peer with
graceful-restartenabled does not retain routes while BGP service is stopped [13039]BGP
peer-groupcan be removed even if it is in use by peer [13205]BGP peer does not change ORF received
prefix-listwhen BGP speaker replacesprefix-listby another [13213]CLI does not expand VRF names for dynamic routing protocols BGP/OSPF/RIP [15828]
Dynamic routing protocols BGP/OSPF/RIP allow configuring non-existent VRF with
server vrf <name>[15829]Connected interface routes not withdrawn from routing table when link is down [15832]
Adding or removing
route-mapwithatomic-aggregateattribute set requires BGP restart [16039]Unable to specify more than one community without quoting when configuring
setin route-map section [16102]Route map
set communitycommand allows community values which are not well-known communities, but those values are not used in FRR [16165]BGP extended community is removed when routes are handled by
import vrfoption [16176]Adding the
forceparameter to thenext-hop-selfoption creates two separate lines in BGP configuration [16369]Prefix list
leandgeparameters are always present in theshow running-configurationoutput, even if they have not been configured [16425]Route map parameter
on-match gotovalue is not validated and can point to itself [16576]Route map parameter
call <rt-map-name>is not validated and can point to its own route map [16577]FRR failing with
has not made any SendQ progresserror message in logs [16592]Zebra continues advertising kernel routes resolved via interface with link down state [16684]
Some routes are not installed from FRR RIB to VPP FIB [16686]
VPP logs warning messages when running the
show routecommand with large route tables [16793]OSPF pce parameters are not displayed in vtysh config [16985]
OSPF ‘refresh timer <time>’ parameter can be removed only with ‘no refresh’ command [17064]
Configuration OSPF ‘distance (external|inter-area|intra-area) <dist>’ causes FRR config error [17086]
OSPF6 interface configuration may be missing from FRR state after TNSR reboot [17576]
Dataplane stops processing static routes when it fails to resolve a route [18005]
RESTCONF allows assigning a nonexistent peer group to a BGP neighbor [18238]
Attaching a BGP peer-group to another peer-group fails silently in CLI [18433]
FRR Not Counting Prefixes Learned from Route Server at IX (internet exchange) [18501]
Cannot create blackhole discard routes via BGP [19543]
IS-IS L1/2 router cannot advertise L1 routes received from L1 neighbor into L2 [19599]
show route dynamic rip configcommand does not show full FRR RIP configuration [20062]show route dynamic bgp configcommand does not show full FRR BGP configuration [20082]IS-IS stops advertising high metrics after service restart [20185]
Changing or removing IS-IS
hello padding during-adjacency-formationcauses configuration mismatch between FRR and TNSR [20203]IS-IS conditional default route injection does not work [20315]
IS-IS SNP area/domain authentication can be configured without area/domain password [20351]
BGP community lists accept invalid community indexes [20364]
IS-IS LFA interface exclusion does not work as expected [20407]
IS-IS LFA
fast-reroutebackup path is displayed with wrong metric [20412]IS-IS LFA
disable-load-sharingoption does not work as expected [20442]IS-IS SPF interval behaves differently for level 1 and level 2 [20473]
TNSR occasionally does not output a specific IS-IS neighbor if several IS-IS processes are configured in different VRFs [20478]
Changing IS-IS
spf backoff-delayparameters via TNSR causes SPF delay timers to run [20504]Cannot enable IS-IS
spf backoff-delaywith default parameters [20524]Configuring IS-IS LFA tie-breakers does not affect backup route selection [20599]
FRR fails when configuring IS-IS LSP MTU [20610]
IS-IS option
debug packet-dumpdoes not capture any data [20622]IS-IS restart is required when changing the route-map used in IS-IS redistribution [20927]
BGP restart is required to change administrative distance of locally originated routes [21379]
BGP CLI does not expand prefix names [21384]
Incorrect CLI expansion when removing previously configured distance value in BGP [21390]
CLI output of BGP IPv6 networks is not aligned [21394]
IS-IS IPv6 routes are not installed to routing table if
metric-style narrowis configured [21468]Incorrect CLI commands are generated for
route dynamic managerdebug settings [21595]RIP
allow-ecmpoption does not get passed correctly to FRR [22262]RIP
split-horizonoption implementation does not match FRR [22276]RIP ‘auth-length’ option breaks authentication process if it is configured with text mode [22285]
RIP
receive version bothandsend version bothoption implementations do not match FRR [22601]Cannot remove BGP option
debug updates out[22627]Some OSPF6 debug options cannot be configured simultaneously via TNSR, and an incorrect error is displayed, but they can be configured via FRR directly without errors [22642]
Incorrect FRR command is generated for
route-mapoptionmatch ip next-hop[22755]Route with unresolvable next-hop remains multipath after disabling
nht resolve-via-default[22777]TNSR uses unsupported source protocol
systemfor route maps [22783]RIP route-map-filter configuration for outgoing routes does not appear in FRR config [22797]
Cannot configure administrative distances for multiple prefixes in BGP [22847]
Removing interface from RIP configuration causes FRR configuration error [22889]
Removing the BGP
always-compare-medoption does not affect route selection [22892]Cannot configure OSPF
distribution-listfor IS-IS [22965]Configuration of OSPF non-multicast neighbor
poll-intervalorprioritycauses FRR configuration error [23143]RIP
distribution-listdoes not work if configured on*interface [23206]BGP
community-listaccepts invalid community values [23229]OSPF static neighbor priority value does not affect DR election in NBMA networks [23299]
Cannot show information about BGP peer-group neighbor via CLI [23329]
consistency for general
show route dynamic <proto>commands [23395]
SNMP / IPFIX / Prometheus¶
Prometheus filters with non-alphanumeric characters can cause HTTP requests to fail [5467]
Prometheus filters containing spaces cannot be removed [5470]
SNMP does not work on interfaces in a non-default VRF [7261]
SNMP view configured with source address
defaultdoes not accept queries from IPv6 addresses [12053]VPP shows incorrect values for configured IPFIX cache timeout settings if they are greater than 2^31 [12094]
Unable to remove SNMP access group entry with specific
security-model[12668]Prometheus response contains double definitions of some metrics [17173]
IPFIX exports only Data-Template packets for VLAN subinterfaces [19706]
Prometheus crashes when run in host namespace [20368]
snmpdandsnmpd-dataplaneservices are enabled by default [23068]
SPAN¶
Incorrect error message when requesting SPAN info from a missing interface [7209]
SPAN does not work correctly for outbound packets on VLAN subinterface [7801]
Security - IDS/IPS¶
Snort service will not restart after being stopped [21576]
Static Routes¶
Static route description is not showing up in show commands or REST state data [5478]
Static route overwrites kernel route in the operating system routing table [7215]
Transit traffic goes to an interface with inactive link when there is another (active) path [8041]
RESTCONF query does not return VRF entry descriptions [13490]
Static routes configured with
next-hop-tableoption are not removed when they can no longer be resolved [17416]VPP FIB shows incorrect IPv6 routes after failed transactions when adding incorrect IPv6 addresses [22821]
Tunnel Protocols¶
VxLAN with multicast destination does not pass traffic [6491]
GRE interface configuration remains in running config after changing GRE tunnel ID [7050]
VPP processes packets received on disabled tunnel interfaces [8111]
Tunnel next-hop entries do not function in non-default VRFs [8653]
IPIP interface loses attached ACLs when DNS resolution of the remote endpoint changes [10171]
IPIP interface loses TCP MSS setting when DNS resolution of the remote endpoint changes [10312]
IPv6 VxLAN does not pass traffic if it is configured over IPv6 IPsec [10592]
Lower than expected throughput over VXLAN interfaces terminated on a loopback BVI [10643]
VXLAN configuration commands are not validated while the dataplane is stopped, invalid configurations created in this state cannot be deleted [16812]
Configurations commands of ‘interface vxlan_tunnel’ mode allow to set unsupported parameters [16926]
GRE
tunnel-typeattributesession-idis not removed when changing type fromerspantol3orteb[21245]
Updates¶
Router upgraded to 22.10-2 will not start without an IKE
prfentry [9368]Upgrade takes longer than expected to complete with a large
main-heapsize [21195]
VPF Filter/NAT¶
Outbound NAT applied to inbound connections [20882]
Cannot delete VPF NAT translation port-range via RESTCONF [21382]
VPF option
runtime generic timeout closeddoes not have any effect [21499]VPF NAT only translates the first TCP fragment when fragmented packets pass through TNSR [21557]
VPF NAT NPTv6 is modifying the wrong hextet when the prefix length is longer than /64 [21717]
VPF filter does not apply TCP flag mask changes without TCP flag value configuration [21768]
VPF connection filter negation for all parameters [22154]
show vpf connectionsshows a route table index that does not match the created route-table ID [22287]Filtering VPF sessions by route table is not working properly [22320]
IPv6 NAT configuration shows incorrect error message about NAT type when the type is not yet configured [22462]
show vpf connection-statisticsoutput contains incorrect category for ICMPv6 [22773]VPF TCP states “closing” and “last-ack” have too small default expiration time [22973]
VRRP¶
IPv6 VRRP configuration fails to commit when using
priority 255[22416]
WireGuard¶
Configuring option
route-tablein a WireGuard peer does not affectnext-hoplookup of the endpoint address [8070]WireGuard tunnel cannot pass traffic with underlying dataplane interface type
virtio[17213]