Known Behaviors

The following table lists limitations in system architecture that have yet to be resolved.

Table 1. Known Issues, Platform-Specific, and Feature Change Requests (CRs) in 33.5.1
Defect NumberDescription
EXOS-37941

On platforms with limited IFP slice support, hardware installation of policy access-lists may fail depending on the configured slice mode, processor type, and match criteria. In ipv4-ipv6-double-shared mode, only basic match fields (e.g., destination IP, L4 destination port, Ethernet type) are reliably supported. For extended match criteria (e.g., source IP, L4 source port, TTL, TOS), use ipv4-ipv6-double-separate mode.

Similarly, in ipv4-single-ipv6-double mode, IPv6 access-lists may be constrained if the platform does not support double-wide slices.

Affected platforms include:

X435, X440-G2, X450-G2, X460-G2

EXOS-37972IPv6 destination address cannot be combined with L4 source port (or range) or ethernet type in the same DACL for role-based users.
EXOS-38279Changing the authentication protocol order does not affect the web-redirect URL received using RADIUS. The web-redirect URL received via the protocol client that was authenticated first will be used irrespective of the precedence configured. This may result in unexpected redirect behavior regardless of protocol prioritization