AXOS R24.3.0 Release Notes for E9-2
AXOS R24.3.0 Release Notes for E9-2
For installation, configuration, and software upgrade practices, refer to AXOS R24.x user documentation,
available online from the My Calix Documentation Library.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 2 of 33
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 3 of 33
Upgrade considerations
AXOS reload command options (for upgrading to R24.3.0)
Supported reload options
Upgrading
Use cases “reload all
from release “reload all”
sequenced”
* For scale information, refer to page 141 in the AXOS R24.1 Software Module Product Planning Guide
(CAB-24-004).
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 4 of 33
Issue
Area Description
Number
BNG AXOS-69917 During the software upgrade process with BNG persistence enabled, to
persistence prevent BNG persistence from failing, you must execute the "copy running-
config startup-config" command prior to executing the "reload all" command.
BNG AXOS-63292 While performing a reload or upgrade on E9 systems with BNG subscriber
persistence services, the minimum recommended DHCP lease time is 30 minutes.
Downgrades AXOS-56106 Following a downgrade to a lower release, the standby card may enter the
degraded state due to configs not getting applied. Workaround: To recover
from this condition, use replay card-config or reload all.
Redistribution AXOS-69033 During upgrades to R24.2 and higher with RAS, the default action for an empty
map redistribution map will be changed from DENY (24.1 and lower) to PERMIT
(24.2 and higher).
Redistribution AXOS-67445 In R24.2 and higher, redistribution map (redist-map) match and set tags can
map no longer be configured as strings; they must be configured as integers.
During an upgrade to R24.2 and higher, if a previously configured match or set
tag uses a string, it will be converted to an integer as follows: If it contains all
digits, it will be converted into the corresponding integers. If it contains non-
numeric characters or a mix of non-numeric and digit characters, it will be
converted into integers using CRC32 algorithm.
Subscriber AXOS-60250 Recovering from duplicate IPv6 subscribers: Prior to upgrading, if the ASM has
Management active duplicate IPv6 PD prefixes, affected subscribers may experience loss of
service following an upgrade. Workaround: To recover from this issue,
perform a switchover.
QoS AXOS-74407 Prior to upgrading to release 24.3 or higher, ensure that the factory
default class maps (INITIAL_CLASS_MAP and FALLBACK_CLASS_MAP)
and policy maps (INITIAL_POLICY_MAP and FALLBACK_POLICY_MAP)
are present in the system. If they have been deleted, they must be re-
added prior to upgrading.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 5 of 33
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 6 of 33
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 7 of 33
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 8 of 33
MPLS-based L3 VPN
• Up to 8 instances (up to 8 VRFs)
• DHCP relay support (MPLS L3 VPN-based DHCP relay support)
• L3VPN towards CPE supported with static, BGP, or OSPF (not with RIP or IS-IS)
• 2-byte ASNs supported
MPLS-based L2 VPN
• Supported with BGP auto-discovery (with BGP or LDP signaling) or manual configuration
- 2-byte ASNs supported
• Supported with load-balancing (balanced PWE setup across ECMP interface)
• VPWS (point-to-point) with support for backup PW
- Up to 512 instances (sum of PWs and backup PWs)
• VPLS (point-to-multipoint)
- Up to 128 instances
• INNI model support
- Point-to-point: Single port and LAG (up to 4 ports)
- G.8032 rings (port-based) [1] [2]
• UNI model support
• Point-to-point: Single port
• (VPLS) The same PWE ID may be used on different bridge domains
• (VPLS) Flexibility for PWE IDs in a given bridge domain
- Single neighbor on single PWE or multiple PWEs
- Multiple neighbors on single PWE or multiple PWEs
- Maximum MACs per bridge domain: 1024 (default setting), configurable up to 40k;
must not exceed 130k across all bridge domains
• Automated L2 VPN Ping (VCCV)
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 9 of 33
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 10 of 33
Infrastructure
• VLAN ID 999 reserved
• Support for host name resolution (static or DNS based) for service elements in named VRFs
• Up to 32 LATNs supported per ASM
• Up to 8 multicast VLANs supported per ASM
• Up to 388 VLANs associated with service-interfaces (across multiple LATNs) are supported. (AXOS-59035)
• Maximum MTU of 9216 bytes supported for ASM applications
• IPFIX support, including Layer 2, Layer 3, and MPLS services statistics
• Support for ingress untagged L2 traffic
• Support for tagged and untagged traffic simultaneously on the same port
• Support for RFC2544 & RFC6346 testing
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 11 of 33
*Note: In DHCPv4 relay configurations, simplified multinetting via automated access network gateway
(AANG) may be used.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 12 of 33
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 13 of 33
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 14 of 33
Behavior Changes
This section provides information on behavior changes from release 24.2.0 to 24.3.0. (Note: If upgrading
from a release lower than 24.2.0, see previous release notes for behavior changes per release.)
Issue
Area Description
Number
AAA AXOS-70986 Prior to AXOS-R24.3, in E9 BNG RADIUS deployments the NAS-Port AVP
included in the "Access-Request" packets containing incorrect information.
With AXOS-R24.3 and later, the NAS-Port AVP is no longer be included in the
"Access-Request" packets.
AAA AXOS-69051 Prior to AXOS-R24.3, when the session-timeout feature is enabled and
reauthorization failed due to Radius server reachability, the session was
deactivated. With AXOS-R24.3 and later, the session will not be deactivated if
the reauthorization fails due to network congestion.
AAA AXOS-65396 In R24.3, the 'revert-timeout' parameter (in the radius-client-instance
profile) has been changed as follows:
Before (R24.2 and lower): 180-3600 (default = 300)
After (R24.3): 60 to 3600 (default = 180)
Deprecated AXOS-73868 With AXOS-R24.3, the "show subscribers sub-state ACTIVE-DEFAULT
summary" command is deprecated and will be removed in AXOS-R25.1.
Deprecated AXOS-73638 With AXOS-R24.3, the previously deprecated commands "clear ip to mac
address mapping" and "clear ipv6 to mac address mapping" are removed from
CLI.
Deprecated AXOS-72911 In R23.4, the "shutdown" command under l2vpn vfi has been
deprecated.
Deprecated AXOS-61389 With AXOS-R24.3 the previously deprecated "control-policy" option is no
longer visible under the "interface ethernet <name> vlan <VLAN ID> cvlan
<CVLAN ID>" command.
Monitoring AXOS-72191 Prior to AXOS-R24.3 the alarms/events listed below did not function properly
due to the name length. With AXOS-R24.3, the following alarm/event names
lengths have been shortened as follows:
* Previous name: radius-client-rmon-session-stopped / New name: radius-
client-rmon-sess-stopped
* Previous name: dhcpv6-pool-rmon-session-stopped / New name:
dhcpv6pool-rmon-sess-stopped
* Previous name: dhcp-server-internal-rmon-session-stopped / New name:
v4server-rmon-sess-stopped
* Previous name: dhcp-server-internal-rmon-session-tca / New name:
v4server-rmon-sess-tca
* Previous name: dhcp-server-internal-rmon-pmdata-cleared / New name:
v4server-pmdata-cleared
Monitoring AXOS-71989 With AXOS-R24.3, the output of the command "show sensors voltage" no
longer includes system internal power supply voltage information, and for
cards that reported "pluggable-module-voltage,” the label has changed to
"optical-module-voltage.”
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 15 of 33
Issue
Area Description
Number
Monitoring AXOS-70152 Prior to AXOS-R24.3, an alarm was not raised if ISIS neighborship went down.
With AXOS-R24.3, a new alarm "isis-alarm-neighbor-adj-down" is raised when
ISIS neighborship goes down.
Monitoring AXOS-70053 Prior to AXOS-R24.3, an alarm was not raised if an OSPFv3 neighbor session
went down. With AXOS-R24.3, a new alarm "ospf-neighbor-session-down" is
raised when an OSPFv3 neighbor session goes down.
Monitoring AXOS-69800 In R24.3, the "show mpls forwarding action" command has the
capability to correctly display "implicit null" or "explicit null" for the
remote label as in the "show mpls forwarding all" command.
QoS AXOS-72718 Prior to AXOS-R24.3, it was possible to delete the factory default class maps
(INITIAL_CLASS_MAP and FALLBACK_CLASS_MAP) and policy maps
(INITIAL_POLICY_MAP and FALLBACK_POLICY_MAP). With AXOS-R24.3 and
later, it is no longer possible to delete them.
Routing AXOS-73840 Prior to AXOS-R24.3, it was possible to clear a VRF subscriber with the
command "clear subscriber ip address" where the VRF was not specified. With
AXOS-R24.3 and later, if the VRF is not specified, the "clear subscriber"
command is only applied on the default VRF.
Routing AXOS-72876 In R24.3, the system rejects the configuration of unsupported address
families. For details on supported and unsupported address families in
various configurations, see AXOS user documentation.
Routing AXOS-72583 With AXOS-R24.3 and later, it is no longer possible to configure an IPv4 static
route and an IPv4 static subscriber route with same destination prefix and next
hop.
Routing AXOS-72481 In R24.3, the address family configuration under router bgp/neighbor
can be removed using the "no" form of the command. In previous
releases, this capability was not present.
Routing AXOS-71774 In R24.3, under the BGP neighbor configuration, "send-community [extended]"
was replaced with "send-ext-community {enable|disable}" with the following
upgrade considerations (during an upgrade to R24.3 or higher):
* "send-community extended" will convert to "send-ext-community enable"
* "send-community" with any string other than "extended" will convert to
"send-ext-community disable"
* If there is no prior "send-community" configuration, the default configuration
of "send-ext-community enable" will be applied.
Routing AXOS-70220 Prior to AXOS-R24.3, user configured IPv6 subscriber static routes were
installed in the routing table with type "dhcp." With AXOS-24.3, user
configured IPv6 subscriber static routes are installed in the routing table with
the type "static." With the change of route-type, the Static IPv6 subscriber-
routes need to be redistributed with "redistribute static" in the routing protocol
for the route map used to filter the configured static routes.
Routing AXOS-64789 In R24.3, the max limit of BFD sessions increased from 16 to 32.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 16 of 33
Issue
Area Description
Number
Subscriber AXOS-73239 Prior to AXOS-R24.3, the abate-utilization rate could be set higher than high-
Management utilization rate under the dhcp-v4-server-pool, the dhcp-v6-server-pool, the
dhcp-v4-server-profile, and the dhcp-v6-server-profile. With AXOS-R24.3 and
later, the abate-utilization rate cannot be larger than the high-utilization rate.
Subscriber AXOS-71423 In R24.3, it is no longer possible for IPv6 static subscribers to get
Management activated without an IPv6 gateway configuration under the subscriber-
service-template. The IPv6 gateway configuration must be present. If
coming from a previous release with active IPv6 subscribers with this
misconfiguration, the configuration must be corrected following the
upgrade to R24.3; otherwise, the subscribers will not activate in R24.3.
System AXOS-73681 Prior to AXOS-R24.3, after an auto-switchover is triggered on an AXOS system
due to multiple crashes of an internal process, the suspended process was
restarted. With AXOS-R24.3 and later, the suspended process is not restarted
on the affected card after the switchover.
System AXOS-72378 With AXOS-R24.3.0, the MTU range is expanded for interface craft <craft-aid>.
In previous releases, the MTU range was 1500-9216, the new range is 1280-
9216.
System AXOS-70186 In R24.3, the max limit of multibind interfaces increased from 128 to 512.
System AXOS-59001 With AXOS-R24.3 and later, a TSP with a VLAN provisioned for "switch-mode
CROSS-CONNECT" can no longer be bound to a G.8023 per-vlan ring. If this
provisioning exists "switch-mode CROSS-CONNECT" will be removed during
an upgrade to AXOS-R24.3.
User Interface AXOS-71457 Prior to AXOS-R24.3, the status message displayed after executing the
"redundancy switchover" command displayed "status Controller Switch-over
triggered successfully" indicating success prior to the completion of the
switchover. With AXOS-R24.3 and later, the status message is updated to
"status Controller Switch-over initiated."
User Interface AXOS-69622 In R24.2, the show command "show ip ospf database external" external route
tag result changed from IP to integer format. For example, from "[Link]" to
"25".
Video Service AXOS-68397 Prior to AXOS-R24.3, if an "igmp-profile" provisioned with "igmp-version-V2 is
applied to a VLAN, V3 query packets received from the uplink were dropped.
With AXOS-R24.3, the V3 query packets are no longer dropped.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 17 of 33
General Notes
CLI commands
CLI commands may be visible in AXOS that are not necessarily applicable to every AXOS system or release
version. To avoid unexpected results or error messages, do not execute inapplicable commands. For the
supported features for a given AXOS system and release, see the corresponding product planning guide.
When Calix issues an AXOS always-on software patch, that release will be available in two formats:
o Patch only: A small-sized software image with only the patch code; for use on systems already
running the full AXOS release (ex: “PatchRelease_AXOS_<System>_R24.[Link]”)
o Full release: A complete AXOS software release that includes the patch; for use on systems not yet
running the full AXOS release, requiring a full upgrade (ex:
“FullRelease_AXOS_<System>_R24.[Link]”)
Command alias
User interface changes that occur between AXOS software releases could potentially affect the functionality
of existing command aliases carried over from a previous release. Following an upgrade, review the UI diffs
in the new release to verify and update your command aliases accordingly. A summary of all changes to the
AXOS CLI and NETCONF user interfaces can be found on the Calix Intelligent Access Resources site.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 18 of 33
Issue
Area Description
Number
AAA AXOS-52593 On rare occasions, after a reload, you may be unable to delete an RBAC aaa
user.
L2VPN AXOS-72623 In show command results, auto-VCCV interval will be visible only if auto-
vccv is enabled.
L2VPN AXOS-62702 In L2VPN configurations with AD-LDP VPLS, if the bridge domain is
administratively disabled/enabled (shut, no shut) in quick succession, the PW
will not function and L2VPN traffic will be impacted. Workaround: To prevent
this issue, allow some time (40 seconds or more) between the disable and re-
enable of a BD. To recover from this issue, clear the specific BGP neighbor for
which the PW is not functional (this should allow the PW to recover).
Monitoring AXOS-75891 To delete an IPFIX sampling point from a slot, do not include the sampling point
name. For example, for “sampling-point current current-sensor-sp,” use the
command “no sampling-point current” (without the name “current-sensor-
sp”).
Monitoring AXOS-73699 In a scaled system provisioned with IPFIX, after modifying the export interval
configuration, the IPFIX data sampling export intervals may be inconsistent
with the configured export interval value (for example 300 seconds or 900
seconds). Other activities on a system can cause the sampling duration to vary,
however over time the average duration of provided samples will be as
configured, with no functional impact on IPFIX reporting.
Monitoring AXOS-61618 The show subscribers command for context id flow-counters (for example,
“show subscribers context 2 flow-counters”) does not display any packet
details.
Monitoring AXOS-49788 Some BNG and BFD-related statistics/counters may not be available or
accurate.
Monitoring AXOS-47930 Static redistributed Gateway subscriber routes are listed as DHCP routes.
Monitoring AXOS-45353 Via the "show bridge" command, it may take up to 5 minutes to display new
learned MACs.
Monitoring AXOS-45281 Following an upgrade, Netconf queries sent with invalid namespaces to an
AXOS system will return all objects, including the configuration and alarm/
event history, which can cause delays and timeouts. Workaround: To avoid this
issue, only send Netconf queries for namespaces that are applicable to the
AXOS product.
Monitoring AXOS-36679 When using the "show ipv6 ospfv3 database router" command, the LSID shows
as [Link].
Monitoring AXOS-29868 When using non-default DSCP values in LI admin, the setting does not take
effect. Workaround: Set the value via the "dscp-map" profile or "host
application-qos."
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 19 of 33
Issue
Area Description
Number
MPLS AXOS-32568 On some occasions following configuration changes, the explicit null label is
not advertised as expected (for example, not seen via the "show mpls ldp
bindings" command).
QoS AXOS-73886 For traffic coming from two cards (for example, from a LAG), the egress
subscriber shaper BW is doubled.
QoS AXOS-56036 In large deployments, do not apply an egress shaper for LATNs; instead, rely on
the shapers for physical interfaces and aggregate services.
QoS On ASM3001 systems, IP class-maps containing ethertype match criteria (e.g.
"ethertype ARP") are not supported. Trying to attach a policy-map/class-map
that matches on ethertype will not work.
QoS IPv6 ACLs are not supported on interface VLANs used for subscriber
management applications (in LATNs) on the ASM3001; the CLI may allow this
configuration, but it has no effect.
QoS For details, see the “E9-2 ASM3001 QoS Behavior” topic in the AXOS R24.x
Access and Services Aggregation Guide.
Routing AXOS-64789 Up to 16 IPv4 or IPv6 BFD sessions are supported simultaneously.
Routing AXOS-62088 In a router use case (sub-management disabled) with DHCP relay and
multinetting, show results for subscribers on a G.8032 ring show subscribers
on specific ring interfaces (such as a LAG).
Routing AXOS-57736 IP subscriber routes are supported with subscriber IPs statically defined in the
ASM.
Routing AXOS-44604 On rare occasions, after a redundancy switchover failure, OSPF re-
convergence may occur on all neighbors.
Routing AXOS-43166 For BFD over LAG, the BFD minimum-interval must be 100 ms or greater.
Routing AXOS-38717 A VLAN interface cannot be used as a mroute outgoing interface.
Routing MPLS graceful restart disable/enable: MPLS graceful restart (GR) support was
introduced in AXOS-R22.1.0 (under “mpls ldp graceful-restart” in the CLI).
Disabling and enabling MPLS GR (even momentarily) is service affecting and
should only be done during initial setup or during a maintenance window.
Software AXOS-67177 Following an upgrade with BNG persistence enabled, any subscribers with an
Upgrades invalid gateway configuration will be deactivated. However, in deactivation
events details, the cause may be erroneously listed as "Multibind not found" or
"Admin Initiated Clear." Workaround: Correct the invalid configuration.
Software AXOS-60250 Prior to upgrading, if the ASM has active duplicate IPv6 PD prefixes, affected
Upgrades subscribers may experience loss of service following an upgrade. Workaround:
To recover from this issue, perform a switchover.
Subscriber AXOS-72587 The DHCP packet rate upper limit in the device data plane is 300 packets
Management per second. If the DHCP packet traffic rate exceeds this upper limit,
DHCP packets will be dropped, which impacts new subscribers
activation and activated subscribers lease renewal.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 20 of 33
Issue
Area Description
Number
Subscriber AXOS-71807 For the E9-2 ASM Router Use Case with L3 DHCP Relay: If multinetting is used,
Management the source IP of the relay requests sent from the ASM to the upstream DHCP
servers is determined as follows:
* Following the configuration & following a reload with "BNG persistence"
enabled: The first assigned IP address on the multinetted VLAN interface.
* Following a reload with "BNG persistence" disabled: The lowest-numbered IP
address on the multinetted VLAN interface.
Best practice: To prevent any issues arising from unexpected changes to the
source IP, Calix recommends configuring the first IP address as the lowest-
numbered IP address on the multinetted VLAN interface (to use as the source
IP of the relay agent).
Subscriber AXOS-70476 For dual-stack sessions, when a re-authentication triggered by
Management renew/reboot/replace for one address-family fails, only that address family is
released (the other address-family is not released). For example, if triggered by
an IPv4 subscriber, IPv4 subscribers may subsequently appear deactivated
while IPv6 subscribers are not.
Subscriber AXOS-69846 The same VLAN cannot be associated with an LATN and TSP.
Management
Subscriber AXOS-69635 Adding a LAG member port to an LATN is not supported.
Management
Subscriber AXOS-69565 IPv6 operational notes:IPv6 operational notes:
Management *For IPv6 non-relay subscribers, if a Solicit message is sent by client with
options (NA/PD/NAPD) different from the ones already active for the
subscriber, then only the session(s) corresponding to the sent option(s)
(NA/PD) will be released from server and a new IP/Prefix is requested.
* For IPv6 relay subscribers, all existing sessions (NA/PD) will be released from
server irrespective of the option sent in new Solicit message from client and
lease for the new requested option (NA/PD) only will be activated in server.
Subscriber AXOS-68606 For all DHCPv6 profiles, Calix recommends configuring the DHCPv6 NA pool(s)
Management to be larger than the total number of possible activations. [In the rare event that
simultaneous subscriber activations lead to the complete utilization of
DHCPv6 NA pools in a server-profile, some IP addresses may be left out by the
server and never allocated even on reattempts. If not prevented, to recover
from this condition, you may try the following: Deactivate all subscribers using
the DHCPv6 pool or add a new DHCPv6 pool (with the required number of IPs).]
Subscriber AXOS-68573 In "show subscriber" results for DHCPv6 subscribers, an option 82 field is
Management present even though it is not applicable.
Subscriber AXOS-68093 After a system reload, if a subscriber is deactivated by the system due to
Management reasons such as RADIUS Session-Timeout expiry, a deactivation event may not
be issued or captured in the event archive history:
Subscriber AXOS-66615 If reloading a card while a subscriber deactivation operation is in progress, the
Management card may remain in the "connected" state for an extended time (up to 20
minutes).
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 21 of 33
Issue
Area Description
Number
Subscriber AXOS-66230 Initiating a switchover may fail while a subscriber deactivation operation is in
Management progress. Workaround: Wait until the operation is complete, and then attempt
the switchover again.
Subscriber AXOS-62921 The aggregated-service must be configured AFTER the multibind and VLAN
Management interfaces in a configuration.
Subscriber AXOS-62089 In a dhcp-v4-relay-profile, the CLI erroneously accepts any random value for
Management the "dscp" parameter. Workaround: For the “dscp” parameter, only enter one
of the valid possible completions listed in user documentation or command
line help.
Subscriber AXOS-60721 Before modifying DHCP option 82 settings (via the l2-dhcp-profile associated
Management with a VLAN) or ONT subscriber-id settings, existing sessions (including any
new duplicate sessions) must be manually cleared.
Subscriber AXOS-53516 If moving an ONT/RG from one PON to another PON, the DHCP client may be
Management unable to route if the move was not performed properly. Workaround: Follow
these steps for the ONT/RG move: 1) disconnect the ONT/RG from original
PON; 2) clear subscriber context; 3) make sure the subscriber is actually
deleted (using show subscriber context), and then 4) move the ONT/RG to
another PON. At this point, the client should get a new IP address.
Subscriber AXOS-51862 The internal DHCP server does not send syslog messages when leases are
Management renewed, only for session activation/deactivation.
Subscriber AXOS-49674 A LAG interface cannot be configured with both an IP addresses and added to
Management an LATN
Subscriber AXOS-48311 If an eth-port is already added to an LATN interface, it cannot be added to a LAG
Management (or vice versa)
Subscriber AXOS-41581 Upon attempting to properly delete the service-interface under an aggregated
Management service (while no existing services are associated), the system may erroneously
reject the deletion with an error message that existing services are associated.
Subscriber Changes to DHCP client option 82 strings – impact on subscriber management:
Management When "dhcp-option-82" is enabled under an aggregated-service, the subscriber
records on the ASM are tied to the option 82 string within the incoming DHCP
packets. If the option 82 string of live DHCP clients is subsequently changed
(for example, modified by remote OLTs), it could result in duplicate subscriber
records in the ASM with a mix of old and new IP allocations. The stale
subscriber records will be flushed from the ASM when their lease time expires.
Best practice: Before enforcing any changes to option 82 settings in the access
network, Calix recommends lowering the lease time of your DHCP server.
Subscriber You must use unique cvlans per aggregated-cvlan-service (you cannot reuse
Management the same cvlan-list for multiple aggregated-cvlan-service objects).
System AXOS-59394 On an AXOS E9 BNG system where multiple Multibind interfaces are shared in a
named VRF, ICMPv6 pings to Prefix-Delegation (PD) subscribers will fail.
Services are not impacted for those subscribers. Workaround: Provision a
single multibind gateway interface in the named VRF for ICMPv6 pings to work
against PD subscribers.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 22 of 33
Issue
Area Description
Number
System AXOS-59394 On an AXOS E9 BNG system where multiple Multibind interfaces are shared in a
named VRF, ICMPv6 pings to Prefix-Delegation (PD) subscribers will fail.
Services are not impacted for those subscribers. Workaround: Provision a
single multibind gateway interface in the named VRF for ICMPv6 pings to work
against PD subscribers.
System AXOS-56391 For RFC 6349 TCP throughput testing, if egress shaping and ingress metering
are configured on the AXOS system, please note the following:
* For both shaping and metering, some buffer (such as 10%) over the tested
BW tier is recommended.
* For ingress metering, the excess burst size (EBS) in bytes should be
calculated as follows: (<max CIR or EIR BW in bytes> * <round trip delay in
ms>) / 8000
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 23 of 33
Issue
Area Description
Number
System Configuration modifications:
For supported AXOS configurations, Calix recommends that configured
parameters NOT be modified; instead, they should be deleted and recreated
with new values whenever possible (for example, if a “no form” of the
command is supported). Failure to follow this guideline may result in system
errors. For example, DO NOT modify a router ID or a password (for example, an
ISIS password). Instead, delete and re-create these parameters.
System Configuration via copy/paste – general guideline: To prevent configuration
errors (due to configuration order mismatches), DO NOT copy/paste large
amounts of show results to configure an ASM3001 system.
System Supported configurations and command sequences: For supported AXOS
configurations, follow Calix configuration guidance and examples, and ensure
that configuration steps and command sequences are executed in the order
specified by Calix. Failure to follow this guideline may result in system errors.
System Switchovers for error recovery: If the active card becomes non-responsive,
switchovers from the active to inactive card are supported.
User Interface AXOS-46334 The auto-completion help for the "show system" command incorrectly displays
<cr> as a possible completion option. Issuing the command "show system
<cr>" results in a syntax error message.
Video AXOS-72918 Multicast RTM is used instead of unicast RTM.
Video AXOS-52008 Configuration via copy/paste – specific issue: An igmp-ssm-map config applied
via copy and paste of a running config will fail. Configure 'router pim 1' before
igmp-ssm-map.
Video AXOS-31462 With multiple ASMs in a solution (where one is an LSR, and one is an LER), the
LSR may not delete mroute entries upon receiving PIM leaves from the LER;
thereby continuing to forward unwanted traffic to the LER.
Video To migrate a VLAN from Layer 2 multicast to Layer 3 multicast, you must delete
and recreate the VLAN.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 24 of 33
Resolved Issues
The following tables list the issues that have been resolved in this release.
Issue
Area Description
Number
L2VPN AXOS-74864 For some L2VPN topologies, rebooting one ASM node may cause
L2VPN service to drop briefly for all other ASMs.
L2VPN AXOS-69684 After the disable/enable of MPLS GR, some AC UP events may be missing for
some manual BD instances. This has no effect on service.
Monitoring AXOS-43624 The tcpdump/remote mirror feature does NOT currently support all protocols
for IPv6. Protocol matching for MPLS encapsulated packets using IPv4 or IPv6
is also NOT currently supported.
Monitoring AXOS-35065 GRE tunnels (used for remote mirroring) will not survive a SWO or active card
reboot.
MPLS AXOS-67211 On rare occasions, adjacencies to upstream IPv6 neighbors may not get
resolved and programmed into HW, resulting in upstream traffic from
subscriber to core getting dropped.
Routing AXOS-73094 Upon removing an IPv6 BFD profile, the IPv6 protocol (ISIS, OSPFv3,
BGPv6) will briefly go down followed by a recovery by itself.
Routing AXOS-71013 Under some circumstances, the ospf-neighbor-session-down alarm may not
clear as expected (if the configuration was removed when the alarm was
active). Workaround: Until this issue is resolved, use the "manual shelve"
command.
Routing AXOS-71013 Under some circumstances, the ospf-neighbor-session-down alarm may not
clear as expected (if the configuration was removed when the alarm was
active).
Subscriber AXOS-77693 If DHCP offers/acks are received from a subscriber device (an unsupported
Management configuration), system resources may become exhausted. Workaround: To
prevent this issue, use a class-map with an ingress flow deny rule for DHCP
offers/acks.
Subscriber AXOS-74747 For deployments with a large number of subscribers that are allocated
Management multiple IP addresses, following an upgrade, the ASM3001 card may
continuously reboot due to excessive internal logging.
Subscriber AXOS-72696 With low threshold values configured (<10%), the "bng-v4-pool-abate-
Management utilization" and "bng-dhcpv4-pool-utilization" alarms may not be raised
correctly
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 25 of 33
Issue
Area Description
Number
Subscriber AXOS-72364 For static IPv6 subscribers, the PD route is not programmed, impacting
Management downstream PD hosts.
Subscriber AXOS-71909 In an E9-2 BNG node using an internal DHCP server, BNG subscriber
Management activation may fail with the cause “Pool selection failure. No free IP or
Internal error” due incorrect reporting of the IP pool availability data such as
"Total IPs available" and "Total IPs assigned". Workaround: Engage TAC for
assistance.
Subscriber AXOS-71385 In an E9-2 BNG node with an internal DHCPv4/v6 server, shortly following an
Management aggregation card reload or a redundancy switchover, CLI 'show' commands
may result in an error message under the following conditions:
1. Multiple 'dhcp-v4-server-pool' or 'dhcp-v6-server-pool' profiles are
configured, with at least one having more than 20 'ip-to-mac-mapping' or
'ipv6-to-mac-mapping' entries.
2. The configured IP range between pools is wide. For example, a pool
configured with 'ip-to-mac-bindings' has a lower IP range ([Link]-
[Link]), and the next pool has a much higher IP range ([Link]-
[Link]).
Subscriber AXOS-71102 On rare occasions, deleting a service-interface after deactivating the
Management subscribers may fail with errors.
Subscriber AXOS-71102 On rare occasions, deleting a service-interface after deactivating the
Management subscribers may fail with errors.
Subscriber AXOS-70975 Under rare circumstances*, unauthorized SSH sessions may be
Management allowed to an IP. (*Following a Linux route deletion from the system
after BNG session was deactivated for the same IP on another VLAN.)
Subscriber AXOS-69873 Under rare circumstances*, unauthorized SSH sessions may be allowed to
Management an IP. (*Following a Linux route deletion from the system after BNG session
was deactivated for the same IP on another VLAN.)
Subscriber AXOS-67955 Deleting a dual-stack N:1 configuration, followed by creating at dual-stack
Management 1:1 configuration with the same SVLAN is not supported.
Subscriber AXOS-69916 HTTPR (url-redirect) does not work as expected with matching on a
Management destination IP.
Subscriber AXOS-69846 An aggregated service VLAN (associated with an LATN) should not be
Management associated with any other type of interface via TSPs, etc.; if this occurs, the
aggregated service may go down. However, the ASM system may erroneously
allow this unsupported configuration in some cases.
Subscriber AXOS-68519 Following a redundancy switchover on an ASM that has a history of
Management application restarts on the standby card, a multibind interface may go
missing (from an internal database), resulting in loss of service for remote
subscribers tied to that interface.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 26 of 33
Issue
Area Description
Number
Subscriber AXOS-49456 For clients still holding an IP (cleared from the ASM, but not released), the
Management ASM may continue to forward traffic without an IPoE session present.
System AXOS-75026 An AXOS system running AXOS-R24.2 software with IPFIX can experience an
issue where an external collector may see large gaps in the IPFIX data being
sent by the AXOS node. This issue is caused by the AXOS node sending the
data at an incorrect time interval. Workaround: Engage TAC for assistance.
System AXOS-74581 In an E9-2 node if the NTP server address is provisioned with a FQDN and a
named VRF, after upgrading to AXOS-R24.2, "ntp-server-reachability" alarms
are raised due to the E9 being unable to communicate with the NTP server(s)
through VRF.
System AXOS-74361 If a "l2-dhcp-profile" is provisioned with single-lease-overwrite enabled, and
with a "lease-limit 1," AXOS systems may incorrectly generate dhcp-lease-
termination and dhcp-lease-establishment events during the renewal of
DHCPv6 sessions by clients.
System AXOS-73169 On rare occasions, standby E7-2 or E9-2 controller cards may raise a "disk-
space-tca" alarm due to the creation of invalid files that result in high disk
space utilization under the /mnt/rw directory partition.
System AXOS-72299 On rare occasions, an AXOS node provisioned with a LAG with LACP
enabled may encounter an issue with LACP packet processing, resulting in
the system raising a "lag-group-down" alarm. The alarm clears within a
second without user intervention. Note: If the LAG carries protocols such as
G.8032/ERPS, routing protocols, etc., the system may also raise/clear alarms
for those protocols.
System AXOS-70462 In an AXOS node, if an interface with a mirror role is configured with multiple
source interfaces, subsequent switchover or Reload All Sequence operations
can prevent a change of role on the mirror interface.
System AXOS-66498 After issuing a "reload shelf/slot" command, a "reload-card" event may not
get raised; however, other events related to card reload will be raised.
User Interface AXOS-71617 On occasion, an E9-2 CLX/ASM node may encounter errors during the
execution of the following CLI commands:
• customer-support verify subscriber context <id>
• customer-support reapply control-policy subscriber-context <id>
• customer-support reapply control-policy interface <name>
Video AXOS-73766 On rare occasions, video channels may not pass through an ASM node
(and require "clear ip mroute <channel-IP>" to recover video).
Video AXOS-72353 The system erroneously allows an IGMP profile to be configured under a
Layer 2 VLAN (unsupported configuration).
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 27 of 33
Issue
Area Description
Number
Video AXOS-72159 In the E9-2 node with LAG interfaces, if the role of the associated Ethernet
interface is changed to INNI, IGMP multicast joins may fail to establish
through the uplink, new IGMP requests fail to join, and no new streams can
be added.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 28 of 33
Open Issues
The following table lists the open issues that are applicable to this release.
Issue
Area Description
Number
AAA AXOS-73366 When the primary radius server is down and the secondary radius server is
activated, the “using-backup-radius-server” event may not be generated
under some circumstance.
AAA AXOS-63149 If an aggregated-service in N:1 mode is provisioned with radius username type
as svlan+cvlan, all the subscribers under the same svlan will have the same
username (svlan) and CoA requests with username svlan will fail.
Workaround: Do not provision the radius username type as svlan+cvlan for
N:1 service mode.
L2VPN AXOS-75487 In an L2VPN topology, after an upstream port toggle on an LER node, an LSR
node may experience an application restart followed by an automatic
recovery. However, if GR is enabled (recommended), there is no traffic drop.
L2VPN AXOS-74909 If an L2VPN bridge domain is configured with AD-BGP without binding
any attachment circuit, attempting to delete the bridge domain may
return an error. Workaround: Retry the deletion until successful.
L2VPN AXOS-71755 If the l2vpn address family is updated on one of the BGP neighbors, BGP
sessions on other neighbors will also get re-established once (one flap).
L3VPN AXOS-74056 On rare occasions, during an OSPF and MPLS flap, refreshed VPN
routes may not get installed to the VRF, resulting in upstream traffic
loss. Workaround: Execute the “clear bgp neighbor <ip>” command.
Monitoring AXOS-75304 If an AXOS system has high latency with northbound NETCONF clients (SMx/
Ops Cloud) and generates a high rate of alarm/event notifications in a short
time, some of these notifications may be dropped.
Monitoring AXOS-75300 For control-plane access-group statistics, MPLS traffic is not counted. (Note:
Non-MPLS traffic is properly counted.)
Monitoring AXOS-74416 In performance monitoring statistics, the DHCP pool active leases may falsely
be displayed as higher than the configured DHCP pool size.
Monitoring AXOS-73699 In a scaled system provisioned with IPFIX, after modifying the export interval
configuration, the IPFIX data sampling export intervals may be inconsistent
with the configured export interval value (for example 300 seconds or 900
seconds). Other activities on a system can cause the sampling duration to
vary, however over time the average duration of provided samples will be as
configured, with no functional impact on IPFIX reporting.
Monitoring AXOS-72957 In an E9-2 node, following the execution of an upgrade, a redundancy
switchover, or a reload all sequenced, the "bng-dhcp-abate-utilization" and
"bng-v4-pool-abate-utilization" events are raised multiple times.
Monitoring AXOS-71936 In an AXOS node with IPFIX configurations, when the system-craft interface is
shutdown, IPFIX status remains active. But data does not export. After 18
minutes, an IPFIX write failure occurs, changing the IPFIX status to inactive.
Monitoring AXOS-62282 When flow sampling is on a port, tcpdump or remote-mirror on the same port
will ignore direction requests and always supply “both.”
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 29 of 33
Issue
Area Description
Number
Monitoring AXOS-55231 Show command results for vlan-l3transport sub-interfaces (via "show ip ospf
int") use an invalid UA address format. Example invalid format: 1/1/x32.100 1
[Link] [Link]... Example valid format: 1/1/x32 100 1 [Link] [Link]...
MPLS AXOS-55711 In MPLS ECMP configurations with GR, if card 2 (1/2) is the active card and
reloaded, traffic loss may occur for over 200 seconds.
Not AXOS-57111 IPv6 micro BFD is not supported.
supported,
Routing
Not AXOS-59035 More than 388 VLANs associated with service-interfaces (across multiple
supported, LATNs) are not supported.
Subscriber
Management
Routing AXOS-74546 The "show ipv6 bgp neighbor … received-routes …" command does not
display the MED (or Metric) attribute correctly (displayed as zero). (Note:
This is only a show command issues; there is no impact to
functionality.)
Routing AXOS-74345 When a bgp-policy map is configured on a BGP neighbor, and a peer-group
(that does not have that bgp-policy-map) is applied on the same neighbor, the
bgp-policy does not work as expected. Workaround: Configure the bgp-policy
on the peer-group or disassociate the peer-group on the neighbor if the bgp-
policy is required.
Routing AXOS-73905 For multi-hop BFD sessions, up to 16 different source addresses (IPv4
or IPv6) are supported. If more than 16 different source addresses are
created, the BFD sessions will fail to create. Workaround: To avoid
exceeding this limit (16), use the same source address for different
multi-hop BFD sessions when possible.
Routing AXOS-71784 If a BFD neighbor is enabled first in BGP followed by enabling BFD in
OSPF/ISIS, the BFD neighbor will not appear in show results (although
there is no impact to BFD functionality). Workaround: After disabling
the BFD neighbor in BGP, disable and enable the neighbor in OSPF/ISIS.
Routing AXOS-71317 In large-scale deployments of dual-stack subscribers (40k), a small traffic
drop may be observed during ISIS GR (some IPv6/v4 routes may refresh).
Routing AXOS-70835 In route reflector server configurations, update-src is not getting
reflected when configured on a neighbor with a peer-group attached
that has update-src config present. (Note: This issue is not seen if upd-
src is configured on the neighbor itself first). Workaround: Detach peer-
group and configure upd-src, or attach a different peer-group without
upd-src.
Routing AXOS-64210 If multiple routing protocols (with unique BDF profiles) are configured on the
same interface, the last applied BDF profile will be used for all of them.
Workaround: Use the same BDF profile for all routing protocols configured on
any specific interface.
Routing AXOS-63122 Routes that fail to get installed in hardware still appear in "show ip/ipv6 route"
results.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 30 of 33
Issue
Area Description
Number
Routing AXOS-49201 In large-scale deployments of DS subscribers (40k), a small traffic drop may
be observed during ISIS GR (some IPv6/v4 routes may refresh).
Routing AXOS-46338 After configuring a default route (original), adding another (new) default route,
and then deleting the original, the new default route does not work.
Workaround: Delete and re-add the new default route.
Subscriber AXOS-75585 When a new N:1 VLAN is provisioned and associated with an aggregated
Management service, the discard route for inactive DHCP subscribers is not set.
Workaround: Perform shut/no shut on the interface VLAN to install the
discard route.
Subscriber AXOS-75116 During a bulk policy application, some subscribers may get deactivated due to
Management a policy application failure. Workaround: Reactivate affected subscribers
using ont shut/no shut.
Subscriber AXOS-75104 Static subscribers are not pruned after they are no longer active.
Management Workaround: For static subscribers to be cleared, you must issue a
clear subscriber command with the IP address.
Subscriber AXOS-75090 On rare occasions, in the Layer 3 router-only use case, after a reload all with
Management bng-persist enabled, some DS traffic loss may be experienced for some
subscribers. Workaround: For affected subscribers, perform "clear arp
address <subscriber_ip>" and "ping <subscriber_ip>."
Subscriber AXOS-74751 In DHCPv6 relay configurations, if the relay-agent-address is different
Management from the gateway address (for example, the WAN address), system
errors may result. Workaround: Ensure that the relay-agent-address is
the same as the gateway address.
Subscriber AXOS-74681 In an E9-2 BNG node, the DHCPv4 release packet currently does not include
Management opt82 when a BHR is replaced (MAC change).
Subscriber AXOS-74680 In an E9-2 BNG node, after a Residential Gateway replacement (new MAC),
Management DHCPv4/DHCPv6 release packets are sent as expected, however the DHCPv6
release packet does not include opt37(remote id) information.
Subscriber AXOS-72482 On rare occasions, an attempt to modify or delete a DHCPv4 server profile
Management may be rejected if an associated DHCPv4 pool contains a stale lease that is
incorrectly reported as active.
Subscriber AXOS-72210 In DHCP relay configurations, the system appends some key
Management information to option 82, which may not be expected.
Subscriber AXOS-68772 If option 82 is enabled, hybrid dual-stack (static + dynamic) with 1:1 and N:1
Management subscribers is not supported. Workaround: Disable option 82 in this
configuration.
Subscriber AXOS-68385 If activating and deactivating a large number of subscribers in a short time,
Management "show restoration-status" may remain "In progress" for some subscribers until
the next switchover.
Subscriber AXOS-63070 On rare occasions, BNG subscribers may experience transient activation or
Management deactivation delays.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 31 of 33
Issue
Area Description
Number
An AXOS node running AXOS-R24.2-AXOS-24.4 may encounter an issue with
the log rotate function, where log files are not compressed as expected,
resulting in increased disk usage. This triggers a “disk-space-tca” alarm with
System AXOS-79091
primary-element "media-sda2." Workaround: When a "disk-space-tca" alarm
with primary-element "media-sda2" is triggered, engage Calix TAC for
assistance.
System AXOS-61178 Updating ring member ports while associated with an LATN is not supported. If
this is attempted, traffic will not move to the new ring port, it will continue to
forward on the original ring port. Workaround: Prior to changing G.8032 or
ERPS ring port binding, you must unbind the LATN from the ring instance.
System AXOS-45260 For 1:1 subscribers, traceroute does not work.
System AXOS-41927 The syslog timestamp does not include time zone.
System AXOS-37352 In some cases, the copy/paste configuration of "ip name-server source-
interface" may fail. Workaround: Configure "ip name-server source-interface"
manually.
System AXOS-29642 After a system reload, operators may log in and begin provisioning prior to the
system being ready, resulting in provisioning not taking effect and a longer
wait time until the system is ready for provisioning. Workaround: After a
system reload, wait some time before provisioning. To confirm the wait time is
over, you can check active alarms for the "config-req-queue-tca" alarm. If this
is alarm is present, wait until it has cleared before provisioning the system.”
System AXOS-23204 G.8032 ring convergence exceeds 50 ms.
User Interface AXOS-8705 Auto completion of some CLI clear commands is not working as expected.
Workaround: Consult user documentation for the full commands to enter.
User Interface AXOS-74749 While a techlog generation is in progress, the system erroneously allows you
to modify the "auto-upload" value (for example, from the default "no" to "yes").
While a techlog generation is in progress, modifying the auto-upload value is
not supported.
User Interface AXOS-73487 In an AXOS node, the output of the command "show file 1/2 contents techlog
filename ?" displays a list of filenames contained on the active card 1/1, not
the standby card 1/2. Workaround: To obtain the filenames on the standby
card use the command "show file contents techlog," and then use the
command "show file 1/2 contents techlog filename."
User Interface AXOS-73114 In an AXOS node, the output of the command "show dhcpv6 statistics"
incorrectly displays the "RELAY-FORW" value in logical port (lag port/ethernet
port). The "RELAY-FORW" displayed by "show dhcpv6 statistics" is twice the
actual number of RELAY-FORW packets received. This is a display only issue
with no functional impact.
User Interface AXOS-49401 The "show ip route fib" and "show ipv6 route fib" commands show Linux routes
(OS management routes in Linux), not FIB routes, and are not for use with
Layer 3 services. In addition, executing this command in a large system can
result in the CLI becoming unresponsive or timing out.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 32 of 33
Issue
Area Description
Number
User Interface AXOS-48335 The command "show running-config g8032-ring vlan-l2transport <vlan-id>"
with specific VLAN ID does work. Workaround: Execute the command on the
complete AC (example: show running-config g8032-ring vlan-l2transport).
Video AXOS-54650 Enabling PIM on interface VLANs is not supported (multicast traffic will not
flow in this configuration).
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12
Page 33 of 33
Technical Support
Create and manage technical support cases online from the Calix Service Station. To access the Calix Service
Station, log in to My Calix and then click the Calix Service Station tile.
Proprietary Information. Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Part # 240-02070-12