New MX 17.10.9 stable firmware release - IDS/IPS CPU utilization fix! (and an 802.1x fix too)

cmr
Kind of a big deal
Kind of a big deal

New MX 17.10.9 stable firmware release - IDS/IPS CPU utilization fix! (and an 802.1x fix too)

Security appliance firmware versions MX 17.10.9 changelog

Important notice

  • While Meraki appliances have traditionally relied on UDP port 7351 for cloud communication and TCP ports 80 and 443 for backup communications, with MX 16 we are beginning a transition to using TCP port 443 as the primary means for cloud connectivity. In order to ensure proper connectivity to the Meraki cloud after this upgrade, please ensure that all “Meraki cloud communication” traffic specified in the Help > Firewall Info page is allowed through any firewalls or security filtering devices that may be deployed upstream of your Meraki appliances. These requirements have been updated on Nov 2022, so it’s important that you review them.
  • HTTP proxy, which allows default management traffic from MX appliances to be sent through a proxy, is deprecated on MX 16 and higher firmware versions.
  • The transition to Cisco Talos intelligence for our content filtering services means that some URL categories have changed names, some categories are no longer available, and multiple new categories are now available. Please review your configuration after upgrading to ensure content filtering is effectively tailored to your needs and deployment environment.

Bug fixes

  • Corrected a rare issue that could result in excessive device utilization when Intrusion detection and prevention was enabled.
  • Resolved an MX 17 regression that resulted in MX appliances no longer re-authenticating 802.1X clients.

Legacy products notice

  • When configured for this version, Z1 and MX80 devices will run MX 14.56.
  • When configured for this version, MX400 and MX600 devices will run MX 16.16.9.

Known issues

  • After making some configuration changes on MX84 appliances, a brief period of packet loss may occur. This will affect all MX84 appliances on all MX firmware versions
  • Due to an MX 15 regression, the management port on MX84 appliances does not provide access to the local status page

Other

  • Updated the device local status page for MX67C, MX68CW, and Z3C appliances to provide error messages for additional cases where APNs were configured incorrectly.
6 Replies 6
RaphaelL
Kind of a big deal
Kind of a big deal

Can't see that firmware yet 🤔

cmr
Kind of a big deal
Kind of a big deal

Maybe it is just for me 😉

 

cmr_0-1692646142100.png

 

PhilipDAth
Kind of a big deal
Kind of a big deal

It doesn't mention anything about CPU in the bug fix list?

RaphaelL
Kind of a big deal
Kind of a big deal

Only that : 

  • Corrected a rare issue that could result in excessive device utilization when Intrusion detection and prevention was enabled.         So Either CPU / RAM utilization I would guess
cmr
Kind of a big deal
Kind of a big deal

Working in the casino industry means I like to gamble on a 50/50 😉

Brash
Kind of a big deal
Kind of a big deal

Looks like a pretty close alignment to the 18.107.4 release notes.

Now to decide which version to upgrade to... 😅

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels