A new beta appliance firmware is now available on Mon, 07 Nov 2022

FirmwareBot
New here
A new beta appliance firmware version is available. Firmware MX 18.103 was just released on 2022-11-07 and has been in this firmware category since 2022-11-07.
1 Comment
cmr
Kind of a big deal
Kind of a big deal

Security appliance firmware versions MX 18.103 changelog

Important notice

  • While Meraki appliances have traditionally relied on UDP port 7351 for cloud communication and TCP ports 80 and 443 for backup communications, with MX 16 we are beginning a transition to using TCP port 443 as the primary means for cloud connectivity. In order to ensure proper connectivity to the Meraki cloud after this upgrade, please ensure that traffic using TCP port 443 between 209.206.48.0/20 is allowed through any firewalls that may be deployed upstream of your Meraki appliances.
  • HTTP proxy, which allows default management traffic from MX appliances to be sent through a proxy, is deprecated on MX 16 and higher firmware versions.
  • The transition to Cisco Talos intelligence for our content filtering services means that some URL categories have changed names, some categories are no longer available, and multiple new categories are now available. Please review your configuration after upgrading to ensure content filtering is effectively tailored to your needs and deployment environment.

Legacy products notice

  • When configured for this version, Z1 and MX80 devices will run MX 14.56.
  • When configured for this version, MX400 and MX600 devices will run MX 16.16.6.

New features

  • Added support for configuring VPN exclusion rules for non-Meraki VPN peers.

Bug fixes

  • Resolved an issue that could result in drops of cellular connectivity when IPv6 was in use with some cellular networks.
  • Added firmware support for LLDP on LAN ports of MX95, MX105, MX250, and MX450 appliances
  • Performance improvements for MX250 and MX450 appliances
  • Corrected an issue that could result in EBGP peering instability when 1) a large number of AutoVPN routes were being advertised via EBGP and 2) the MX appliance had a reduced WAN MTU.
  • Resolved an issue that resulted in IPv6 traffic being dropped when sent over an IPv4 tunnel formed with a non-Meraki VPN peer.
  • Fixed an MX 18.1XX performance regression on MX64(W) and MX65(W) appliances.
  • Corrected an issue that could result in traffic to non-Meraki VPN peers being incorrectly NAT’ed when the peer was configured using an FQDN as opposed to an IP address.
  • Resolved several rare issues for MX67C, MX68CW, and Z3C appliances that could result in the integrated cellular modem being unable to properly initialize after an upgrade from MX 16 was performed.
  • Fixed an MX 18.1XX regression that could result in MX appliances configured in HA or passthrough mode to lose WAN connectivity.
  • Corrected an issue that could result in a device reboot of MX appliances.
  • Corrected an issue that could result in the global IPv6 address being unreachable to some LAN clients when the IP address was obtained via SLAAC on a cellular uplink.
  • Resolved a rare issue that could result in traffic being misclassified by NBAR.
  • Stability improvements for VMX-L appliances deployed in the Umbrella Cloud.

Known issues

  • After making some configuration changes on MX84 appliances, a brief period of packet loss may occur. This will affect all MX84 appliances on all MX firmware versions
  • Due to an MX 15 regression, the management port on MX84 appliances does not provide access to the local status page
  • Client traffic will be dropped by MX65(W), MX67(C,W), and MX68(W,CW) appliances if 1) The client is connected to a LAN port with 802.1X authentication enabled and 2) The VLAN ID of the port is configured to 16, 32, 48, 64, 80, 96, 112, 128, 144, 160, 176, 192, 208, 224, or 240.
  • There is an increased risk of encountering device stability and performance issues on all platforms and across all configurations.