Cisco CSR 1000v Series Cloud Services Routers Overview


Explore the Content Hub, the all new portal that offers an enhanced product documentation experience.

  • Use faceted search to locate content that is most relevant to you.

  • Create customized PDFs for ready reference.

  • Benefit from context-based recommendations.

Get started with the Content Hub at to craft a personalized documentation experience.

Do provide feedback about your experience with the Content Hub.

Virtual Router

The Cisco Cloud Services Router 1000V (CSR 1000V) is a cloud-based virtual router that is intended for deployment in cloud and virtual data centers. This router is optimized to serve as a single-tenant or a multitenant WAN gateway.

When you deploy a CSR 1000V instance on a VM, the Cisco IOS XE software functions as if it were deployed on a traditional Cisco hardware platform. You can configure different features depending on the Cisco IOS XE software image.

Secure Connectivity

CSR 1000V provides secure connectivity from an enterprise network such as a branch office or a data center, to a public or a private cloud.

Technologies Supported by a Platform

A platform’s product landing page lists technology configuration guides for Cisco IOS XE technologies that the platform supports.

In each technology configuration guide, a Feature Information table indicates when a feature was introduced to the technology. For some features, the table also indicates when additional platforms have added support for the feature.

To determine whether a particular platform supports a technology, view the list of technology configuration guides posted on the platform’s product landing page. For example, see Cisco Cloud Services Router 1000v Series.

System Requirements

Software Images and Licenses

The following sections describe the licensing and software images for CSR 1000V.

Cisco CSR 1000v Evaluation Licenses

Evaluation license availability depends on the software version:

The following evaluation licenses are available:

  • IPBASE technology package license with 10 Gbps maximum throughput

  • SEC technology package license with 5 Gbps maximum throughput

  • APPX technology package license with 5 Gbps maximum throughput

  • AX technology package license with 2.5 Gbps maximum throughput

If you need an evaluation license for the Security technology package, or for an AX technology package with higher throughput, contact your Cisco service representative.

For instructions on obtaining and installing evaluation licenses, see the “Installing CSL Evaluation Licenses for Cisco IOS XE 3.13S and Later” section of the Cisco CSR 1000v Software Configuration Guide .

Cisco CSR 1000v Software Licenses

Cisco CSR 1000v software licenses are divided into feature set licenses. The supported feature licenses depend on the release.

Current License Types

The following are the license types that are supported (Cisco IOS XE Everest 16.4.1 or later):

  • IPBase: Basic Networking Routing (Routing, HSRP, NAT, ACL, VRF, GRE, QoS)

  • Security: IPBase package + Security features (IP Security VPN, Firewall, MPLS, Multicast)

  • AX: IPBase package + Security features + Advanced Networking features (AppNav, AVC, OTV and LISP)

  • APPX Package: IPBase package + Advanced Networking features - Security features (IP security features not supported)

Legacy License Types

The three legacy technology packages - Standard, Advanced, and Premium - were replaced in the Cisco IOS XE Release 3.13 with the IPBase, Security, and AX technology packages.

Features Supported by License Packages

For more information about the Cisco IOS XE technologies supported in the feature set packages, see the overview chapter of the Cisco CSR 1000v Series Cloud Services Router Software Configuration Guide.


The Cisco CSR 1000v router provides both perpetual licenses and term subscription licenses that support the feature set packages for the following maximum throughput levels:

  • 10 Mbps

  • 50 Mbps

  • 100 Mbps

  • 250 Mbps

  • 500 Mbps

  • 1 Gbps

  • 2.5 Gbps

  • 5 Gbps

  • 10 Gbps

The throughput levels are supported for different feature set packages in each version. For more information about how the maximum throughput levels are regulated on the router, see the Cisco CSR 1000v Cloud Services Router Software Configuration Guide.

Memory Upgrade

A memory upgrade license is available to add memory to the Cisco CSR 1000v router (Cisco IOS XE 3.11S or later). This license is available only for selected technology packages.

Additional Information about Licenses and Activation

For more information about each software license, including part numbers, see the Cisco CSR 1000v Router Datasheet. For more information about the standard Cisco IOS XE software activation procedure, see the Software Activation Configuration Guide, Cisco IOS XE Release 3S.

Software Image Nomenclature for OVA, ISO, and QCOW2 Installation Files

The Cisco CSR 1000v installation file nomenclature indicates properties supported by the router in a given release.

For example, these are filename examples for the Cisco IOS XE Everest 16.4.1 release:

  • csr1000v-universalk9.16.04.01.ova

  • csr1000v-universalk9.16.04.01.iso

  • csr1000v-universalk9.16.04.01.qcow2

The filename attributes are listed below, along with the release properties.

Table 1. OVA Installation Filename Attributes

Filename Attribute



Installed image package.


Indicates that the software image is for the Cisco IOS XE 3.9.0aS release image (mapped to the Cisco IOS 15.3(2) release).

std or ext

Standard release or extended maintenance support release.

Features and Notes: Cisco IOS XE Fuji 16.8.1a


Features—Cisco IOS XE Fuji 16.8.1a

The following new software features are supported on the Cisco CSR 1000v for Cisco IOS XE Fuji 16.8.1a.


The following section includes important notes about the Cisco CSR 1000v for Cisco IOS XE Fuji 16.8.

Encrypted Traffic Analytics records may not be exported after a reload if an "inactive timeout" command has been configured

When the router is reloaded with a large configuration, which generates many messages for initializing features in the data plane, the Encrypted Traffic Analytics (ETA) records may not be exported. This occurs if the ETA inactive timeout command is included in the configuration.


Remove inactive timeout command from the ETA configuration. After a reload, you can add the inactive timeout command to the configuration.

VMware ESXi Multicast Register Failure


The following multicast register failure message may be shown (Cisco IOS XE Fuji 16.7.1 or later) if you have configured a multicast feature such as CDP or HSRP.

Example: Dec 13 03:51:48.192 EST: %VXE_VNIC_IF-3-MSGINITERROR: VXE vNIC interface command: multicast_register failed: -1 for GigabitEthernet

This failure has been noticed for a Cisco CSR 1000v running in one of these environments: VMware ESXi or KVM (RHEL) 7.4.


The environment upon which the Cisco CSR 1000v is running (e.g VMware ESXi) prevents the Cisco CSR 1000v from being able to set MAC addresses, after a limit on the number of MAC addresses is reached. This occurs as a result of configuring a multicast address on an interface (for example, when configuring CDP or HSRP). .


Reboot the guest Cisco CSR 1000v. Note that in some environments (for example, RHEL KVM 7.4) this workaround is ineffective—after you reboot, the error messages continue to appear.


Cisco IOS software images are subject to deferral. We recommend that you view the deferral notices at the following location to determine whether your software release is affected:

Field Notices

Limitations and Restrictions in Cisco IOS XE Fuji 16.8.1a

There are no new limitations and restrictions in Cisco IOS XE Fuji 16.8.1a.



Caveats, or “bugs,” describe unexpected behavior. Severity 1 caveats are the most serious. Severity 2 caveats are less serious. Severity 3 caveats are moderate caveats. This section includes severity 1, severity 2, and selected severity 3 caveats.


The Dictionary of Internetworking Terms and Acronyms contains definitions of acronyms that are not defined in this document:

Bug Search Tool

If you have an account on, you can also use the Bug Search Tool (BST) to find select caveats of any severity. To reach the Bug Search Tool, log into and go to .

If a defect that you have requested cannot be displayed, it may be because the defect number does not exist or the defect does not have a description available.

You can use to the Bug Search Tool to view new and updated caveats: .

For Best Bug Search Tool Results

For best results when using the Bug Search Tool:

  • In the Product field, enter Cloud Services Router.

  • In the Releases field, enter one or more Cisco IOS XE releases of interest. The search results include caveats related to any of the releases entered in this field.

The tool provides autofill while you type in these fields to assist in entering valid values.

A search using release number 16.6 should find the caveats for Cisco IOS XE Everest 16.6.1.

Field Notices

We recommend that you view the field notices for the current release to determine whether your software or hardware platforms are affected. You can access the field notices from the following location:

Caveats: Cisco IOS XE Fuji 16.8.2

Open Caveats—Cisco IOS XE Fuji 16.8.1a

Caveat ID Number



DMVPN: Crypto session stuck into UP-IDLE status after reconfiguring tunnel

Resolved Caveats—Cisco IOS XE Fuji 16.8.1a

Caveat ID Number



Microsoft Azure: CSR 1000v occasionally experiencing high traffic latency


R0/0: ASR1002-X kernel: bullseye_i2c_master_xfer Error Repeats Every Hour


IPv4 PLU mtrie lookup return invalid oce_chain_p


ARP request in not triggered in half-duplex VRF with the additional VRF


ASR1009-X FAN SN in show inventory displays incorrectly after replacing the FAN and an RP switchover


ISR1100 Pause frame generation is not working


ASR 1000 Series SSL VPN CLI should be blocked


ISR 4000 Series SW MTP configured as TRP does not relay sRTCP messages


TDM-IP, QoS marking is varying to 0 and EF for the same RTP stream


Invalid QFP load calculation (Recommit CSCvg92754)


Preempt timer does not work, due to an old HSRP Hello packet get just after interface up


Interoperability failure between some Fortitude Ports and SmartJack Westell NIU


T38 Faxes Fail Going IP to PRI When Coming From A BDI with DOT1Q Tagging


ESP crashes with high scale QoS configuration


Suite-B Not Supported with ESP-200 on ASR1000-X Platform


In B2B HA, active box is not generating syslog alert for watermark high/low value.


FP crash with scaled IKE sessions.


ESP crash when flapping interface with l2tp tunnels that have qos applied to the tunnels.


cpp-mcplo-ucode crash when layer 2 switching packet


ISR4451-X sometime drop the packet when volume -based rekey occurred


Router crashes after interface flap where sessions get moved from one interface to another


16.6: VFR-related drops are not observed in the CSR 1000v platform


FP crash @cpp_qm_create_queue while adding fair-queue


16.6 :ISR4k Core file seen @cvmx_pow_work_response_async


ASR1K - ECMP load-balance w/ DPI L2TP Tunnel visibility and QoS may generate ucode crash


CPP crash in MMA


[UniScale]csr1k1vCPU crashed while verifying performance at IPv4 ACLs per system scale


Performance monitor related field (like SSRC) is not collected.


CFT: Improve processing of elephant flows for NBAR


CSR1000v: invalid QFP load calculation (Recommit CSCvg92754)

Caveats: Cisco IOS XE Fuji 16.8.2

Open Caveats—Cisco IOS XE Fuji 16.8.2

Caveat ID Number



CUBE: FPI Hung Sessions and Provisioning Failures observed in Standby CUBE


CSR1k-FlexVPN: Spoke to Spoke: Implicit NHRP entry due to expired resolution request handling.


Hoot-n-holler multicast traffic marked with DSCP 0


Standby crashed when defaulting vlan config reconfig vlan config with fnf/et-analytics


Router crash - AFW_application_process


Adaptive QOS : Target shape rate is set to floor rate when lower floor and ceiling rates are used


CUBE crashes at sipSPI_ipip_vcc_CheckCodecSetType


CSRs failing due to kernel panic within AWS


DHCP Relay not working after power outage


"clear crypto sa vrf MyVrf" triggers crash after updating pre-shared-keys


BGP updates missing ISIS advertising-bits led to LDP label purge on peer.


Crash under AFW_application_process with shared-line configuration


Cisco IOS XE 16 Router - CPUHog - SNMP ENGINE crashed with Watchdog timeout

Resolved Caveats—Cisco IOS XE Fuji 16.8.2

Caveat ID Number



IOS-XE Fails to correctly populate RTCP SSRC Field


Cisco IOS XE Software for Cisco ISRv Router Static Credential Vulnerability


router reloaded when doing show BGP RT filter routes


PFRV3: Site Prefix shows unreachable after removing and adding the specific route for the prefix


Traceback is observed during mid-call media IP and port change


Prefix SID delete after SSO.


CPUHOG on QoS statistics collection for DMVPN. QoS crash with DMVPN/NHRP.


NAT MIB not populated when using traditional NAT


Polaris Routers - Memory leak under process RECMSPAPP in IOSd


Interop vrrp doesnt work between cedge and vedge


Local LAN-only prefix present in master route-import table but not present in site prefix DB


QoS Overrides loadbalancing to per prefix even with only session level policing applied


iBGP dynamic peer using TTL 1


ZBF not able to identify the WAAS optimized flow and drops ACK


Throughput defaults to 1000kbps after license expires


Subsystem stopped: ios-emul-oper-db due to bgp table issue


OSPF: process crashed when the interface priority is configured for 0.


Vz: Non-Polaris to Polaris ISSU compatibility issue


Cisco IOS XE Software Authent., Author., and Accounting Login Authent. Remote Code Execution Vuln.


RP crash @policymap_associated_to_multiple_instances


CME/BE4K crashes when trying to check help command for new device type BEKEM


Restored DB is session-lock locked out with insane timeout after boot


active SUP crash when active run 16.7.1 and standby run 3.18.2aSP


Memory leaks seen at PKI_name_list_add(0xa139cc0)+0x3e


OSPF SSPF/SRTE: absolute value configured for the SRTE tunnel not configured by OSPF.


Standby RP crashes due to Memory usage in ospf_insert_multicast_workQ


NMR TTL is wrongly considering eid-record of for its calculation


link local multicast packets are received when the SVI is in down state


Router crash when removing route-target and with hard clear


IPv6 address not assigned or delayed when RA Guard is enabled


Reverse-tunnel routes under PMIPv6 MAG config not using configured distance metric


Router crashed when lsp-mtu is changed


msmr+xtr carsh during scale wireless roaming


Crash when doing SNMP walk and applying QOS over a GRE tunnel


Telnet Sessions Hang/Become unavailable at execution of "show run"


dynamic vlan assignment causes all sisf entires under the port to be deleted


Backup path incorrect for ring topology where high ISIS cost is configured on 1 link.


ospf routing loop for external route with multiple VLINKs/ABRs


Path of Last Resort Sending Probes in Standby State


Crash while doing a conference call


OSPF SR uloop : After issuing "clear ip ospf process". ospf process crashed.


BGP high CPU when config 256k vxlan static route


High Availability system with two Voice Gateways - Crash


CSR1000v running inside Citrix XenServer 7.0 crashed


Device Tracking - Memory leak observed with IPv6 NS/NA Packets .


IP SLA multicast appear as "Unknown"


CUBE incorrectly fomats SIP SDP


CUBE is not responding to SIP INFO


Crash due to out-of-memory condition Memory leak@CENT-BR-0