Loading...
Loading...
Upon a Catalyst 9000 series switches system reload, configurations such as 'no cts role-based enforcement' will be removed from physical interfaces that are bundled into a Port-channel. This issue occurs without any user intervention.
Symptom observed when a Catalyst 9200 or Catalyst 9300 running 17.12.5 has at least one interface with 'no cts role-based enforcement' configured while this interface is part of a Port-channel. Upon bootup with 17.12.05, the "no cts role-based enforcement" line will be removed from any interface that is member of a Port-channel. This is mostly seen when upgrading from 17.12.04 (where the "no cts role-based enforcement" command was present) to 17.12.05. This issue is not seen if the physical interface with 'no cts role-based enforcement' configured IS NOT part of a Port-channel.
Re-enter the configuration -OR- Downgrade to 17.12.4 -OR- implement EEM script that automatically adds the needed configuration back upon bootup -OR- Upgrade to 17.15.3 or later where the "no cts role-based enforcement" command can be configured under the logical Port-channel interface instead of the physical ethercnanel member interfaces
This issue potentially affects all Catalyst 9000 series switches, not just the Catalyst 9200 and Catalyst 9300 models where it was initially observed. Network operations will be affected due to the reconfiguration requirement on each system reload.
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.