cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2599
Views
0
Helpful
10
Replies

Amsterdan VS Gibraltar

NetworkGuy!
Level 1
Level 1

Hello

 

I am looking to update my IOS XE 9300/9200 switches, currently running 16.12.5 - I see Amsterdam train (17.3.4a) and wanted to know if this would be good choice with respect to staiblity, performance issues, vulnerabilities etc


We are looking at Cisco DNA centre but nothing like SD WAN functionality we need

 

Please advise

 

Thanks,

10 Replies 10

balaji.bandi
Hall of Fame
Hall of Fame

17.3.4 is good to go for DNAC environment as SD-Access deployment.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thank you, I am not looking at SD features since this feature has lots of
vulnerbilities
So without this feature is 17.x train best way to go?

17.3.3 i am running and stable so far.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Leo Laohoo
Hall of Fame
Hall of Fame

One is buggy and the other is stable.  

For 9300, use 17.3.X.

For 9200, use 16.12.X.

Thank you both, 

what are the new features that are in 17.x that are not in 16.x . if I use 17.x.x, is it memory intensive on 9200/9300? is that why @leo lahoo advising to use 16.12. on 9200's?

 

I was mainly concerned that 17.x is for SD WAN which we dont use and I know there are vulnerabilities relating to SD WAN a lot


@NetworkGuy!  wrote:

what are the new features that are in 17.x that are not in 16.x .


Read the Release Notes.


@NetworkGuy!  wrote:

if I use 17.x.x, is it memory intensive on 9200/9300


I cannot answer that question because I do not know what features, settings and configuration is enabled on the network.  


@NetworkGuy!  wrote:

is that why @leo lahoo advising to use 16.12. on 9200's?


Read the Release Notes.  Look at the Open Caveats section.  For the 9200, it is better to use 16.12.X than 17.3.X. 

For the 9300, it is better to use 17.3.X.


@NetworkGuy!  wrote:

I know there are vulnerabilities relating to SD WAN a lot


You "know" or you "read"?  If someone has taken the time to thoroughly read the Release Notes, it will lead to the Security Bulletin.  The Security Bulletin will have detailed information about what versions are affected, workarounds and fixed versions.  If no one bothers to read the Release Notes and Security Bulletin, then ... ¯\_(ツ)_/¯

checking, for ISR 4400 what would you recommend?


@NetworkGuy!  wrote:

for ISR 4400 what would you recommend?


Without knowing about the network involved, I would say 16.6.X.

jmcgrady1
Level 1
Level 1

Leo, as of Aug 2022, what is a well regarded IOS for ISR4400? Assume simple routing with eigrp, bgp, and some QoS. No SDWAN or SDLAN.

@jmcgrady1, avoid using a train that supports Cisco Smart License. 

For switches, CSL support starts at 16.9.X.  For routers, CSL support starts at 16.10.X.

Have a read:  IOS-XE leaks like a sieve

Review Cisco Networking for a $25 gift card