Known Behaviors

The following are limitations in ExtremeXOS system architecture that have yet to be resolved.

Table 1. Known Issues, Platform-Specific, and Feature Change Requests (CRs)
Defect Number Description
General
EXOS-30041 A 'V' flag is displayed in the output after running the show dns cache command with dnssec disabled.
ExtremeSwitching 5420 Series Switches
EXOS-29777 On a stacked 5420, ingress mirroring MACsec-encrypted traffic to a port on a different slot will result in an extra 4 byte zero-value header inserted in the position of the VLAN tag.

Workaround:

Mirroring such traffic to a port on the same slot (where the MACsec source is located) does not have this limitation.

ExtremeSwitching 5520 Series Switches
EXOS-30172 In an Extended Edge Switching stack, an error occurs on slot 2 while loading the structure <ports> after unconfiguring and then restarting the switch.
EXOS-30419 Continuous attempts to authenticate user(s) with Dynamic ACLs (configured via radius Vendor Specific Attribute (VSA) ID 232 – Extreme-Policy-ACL), which would exceed the maximum configured or allowed number of ACLs, may cause a crash on the backup node in a stacked system.

The following example log message is an indication this is happening:

1/1/2021 12:00:00.00 <Noti:Policy.SessLmtExcd> Slot-1: Policy 1(policy) assignment by rule [MacSrc |00:00:11:11:22:22|1:1] failed (exceeded blade dynamic acl hardware limits).

1/1/2021 12:00:00.00 <Noti:Policy.SessLmtExcd> Slot-1: Policy 1(policy) assignment by rule [MacSrc |00:00:11:11:22:22|1:1] failed (exceeded blade dynamic acl hardware limits).

Workaround:

Decrease the number of authenticated users or Dynamic ACLs per authenticated user to avoid this crash.

SNMP
EXOS-30775 ExtremeXOS modifies the OID of an SNMP get-request instead of returning a "No Such Instance" response for extremePethPsePortTable.
SummitStacking
EXOS-30060 In a SummitStack with VPEX enabled, the ELSM state remains down when configured on CB ports.
VXLAN
EXOS-29918 If VMAN CEP egress filtering is applied on a VXLAN underlay or MPLS Network port, traffic does not go through.

Workaround:

Run the disable vman cep egress filtering command from the VXLAN underlay port/MPLS network port.