Documentation Index

Fetch the complete documentation index at: https://docs.crossworkassurance.cisco.com/llms.txt

Use this file to discover all available pages before exploring further.

New: Try our AI‑powered Search (Ctrl + K) — Read more

Crosswork Assurance 25.7 Release Notes

Prev Next

We’re GA!

The Cisco Crosswork Assurance team is very proud to announce the general availability of the 25.7 release! Through numerous early field trials and hardening efforts, the product is finally ready to spread its wings. This release is an important first step in our journey to better support customers that chose to run the entire assurance platform within their own infrastructure.

Recapping some of the important advancements this release brings:

  1. Streamlined platform deployment process

  2. Inclusion of embedded assurance sensor management functions

  3. Unified user management with optional customer configurable SSO

  4. Improved platform observability and robust out of the box application tuning

IMPORTANT:

  • Legacy Orchestrator is not required for the on-prem solution. This functionality is provided as a built-in feature of the Crosswork Assurance platform, known as Sensor Management, removing the need to install a separate component.


New Features

Deployment in IPv4 Virtual Machine Environments

We prioritized the hardening of our most popular model:

  • Lab and small dimensioning

  • IPv4 environment with No-DNS or DNS support

  • Airgap and non-airgap installations

  • Deployed as single node on bare-metal or virtual machine infrastructure

Coming Soon: Other installation options are still in controlled availability and will be reclassified as generally available soon!
This will include the following features:

  • IPv4/IPv6 dual stack environments

  • Multi-node virtual machine deployment

  • Customer provided Kubernetes cluster (including Openshift support)

Sensor Management

  • Command Line Interface: Includes an updated set of CLI commands, enhancing user interaction. To provide a consistent and familiar interface while reducing training and management efforts, a climanager service is installed on the host. This update streamlines command execution within the Sensor Management CLI environment.

  • Support for SAT Notifications: Sensor Management component incorporates Service Activation Test (SAT) notifications for state change events.

    • When a SAT service is created or deleted

    • When a SAT service is initiated and the various state changes it undergoes until execution is complete

    • When the associated UNI/NNI port goes down, triggering notifications for all SAT services on that port

    • When the managed entity (ME) to which the SAT is assigned is deleted

  • Enhanced Device Backup Information: The Sensor Management Backup & Restore tab for devices includes additional information for increased clarity; the firmware version of each device is visible at the time the backup was taken, providing users with essential data for system management and troubleshooting.

  • Application-Level Password Policy Enhancement: To enhance security, default passwords at the application level are not permitted beyond the installation phase. Authentication requires unique credentials, either created by the customer or generated randomly upon request. Additionally, users must change their passwords immediately following a fresh system installation, enforcing a first-time password change requirement to ensure secure access.

  • Crosswork Assurance Sensor Compatibility: Sensor Management component has been enhanced to be backward compatible with Crosswork Assurance Sensors, including release 25.07 for Assurance Sensors LT, LX, and GT as well as release 24.08 for Assurance Sensors F100 and F25.

  • Crosswork Assurance Sensor Control Compatibility: Sensor Management component has been enhanced to operate with Assurance Sensor Control release 25.07.2.
    Note: Sensor Management releases prior to release 23.04 are unable to provide RTT values for TWAMP and ETH-DM using Sensor Control releases 22.12 or later. If you intend to deploy Sensor Control 22.06 or later to your network, please ensure you have upgraded to Sensor Management release 25.7.

  • Reflector Configuration API Enhancements: Sensor Management component supports expanded API requests for reflector configuration on Assurance Sensor Control. Users can retrieve reflector configurations and filter these configurations by peer type or protocol. Additionally, the API allows updating the status and port for single or multiple reflector configurations, improving management flexibility and control.

  • Enhanced Stop Action for Northbound API Sessions: The stop action in the Sensor Management component has been updated to perform both the stop and terminate action. Previously, users needed to issue the stop action twice to properly transition the session into the terminated state.

  • Assurance Sensors Certificate Management: This release removes the use of default device certificates (pre-generated private CA certificates). Users must generate self-signed certificates or import their own certificates for each device. This change enhances security and affects the Sensor Management reverse proxy functionality.

Known Limitations

Deployers: 25.7.250-108

Telemetry Collector r25.07 (0.80.0)

Sensor Collector: 0.659.2-fips

Limitation

Description

Workaround

Upgrade

Upgrades are supported from the preceding early drop of 25.7.250-96

Upgrade previous deployments running 25.7.233 to 25.7.250-96 prior to moving to this release.

Fresh installs are fine to take this release as their initial installation.

Offline maps

Environments where access to our online map provider is not available will not be able to leverage that capability.

This version relies on the user browser having connectivity to our online map provider service. We will provide an update to 25.7 offering support offline maps in the future so user who are also in an airgap environment can use our geo map features.

Download Portal showing incorrect steps for upgrading airgap deployments

When using the Download Portal to upgrade an airgap deployment, in some circumstances the instructions shared are incorrectly showing helm CLI commands rather than instructions to obtain the airgap bundle via a cURL command.

Contact support if this happens to you to generate the proper command for you to download an airgap bundle.

Cannot change a deployment from DNS to no-DNS

If upgrading a deployment, changing from using a DNS to using direct IP access is not functioning correctly and results in your deployment being misconfigured.

Do not attempt to reconfigure a deployment from using DNS to using no-DNS. Resetting the deployment and reinstalling from scratch will allow this. If this is necessary or this was attempted by mistake, contact support.

Sensor Management Operational Considerations

Device Interoperability

The following section details the firmware releases that are known to interoperate with this release. Please refer to the Sensor Management Administrative Operations documentation for a listing of supported functions for each firmware version.

For the releases mentioned below, support for maintenance releases is also included.

Product

Supported Releases

Assurance Sensor Control

19.12 -> 25.07.2

Assurance Sensor GT

7.1.2 -> 25.07

Assurance Sensor LT

7.1.2 -> 25.07

Assurance Sensor LX

7.9 -> 25.07

Assurance Sensor F100

22.01.1 -> 24.08

Assurance Sensor F25

23.09 -> 24.08

AT 1G Sensor Element

1.2.1

AT 10G Sensor Elements

2.1 -> 2.3

CE & NE Sensor Elements

6.1.0.4 -> 6.4

GE Skylight Element

4.9

GX Skylight Element

7.4 -> 24.11

Skylight VCX

2.5, 2.7 -> 19.07

TE Sensor Element

6.1.0.4-> 6.4

Velocity FS

1.0 and 1.1

Velocity FSX

2.1 and 2.2

HTTP Interface Deprecation

The HTTP interface for Sensor Management is no longer supported for GUI operations or REST and XML APIs. Web service clients must transition to the secure HTTPS protocol.

Customers currently using HTTP on port 6080 will be automatically redirected to HTTPS on the same port, meaning no firewall changes are required.

To ensure a secure and seamless experience, access Analytics directly via the Open Crosswork Assurance button located within the Sensor Management interface. Please update any existing bookmarks or client applications to utilize the HTTPS protocol to maintain full security and functionality.

Browser Support Limitations

The minimum recommended screen resolution to operate Sensor Management is 1360 x 768. Lower resolutions will not provide an optimal experience.

Performing a zoom on your display is not recommended due to incompatible implementations with browsers. If a zoom must be applied, please use a Firefox browser as it has the most standard support for this function.

Due to issues with browser compatibility mode and web sockets, Internet Explorer is no longer supported. Please use Google Chrome (version 70 or higher) or Firefox (version 52 or higher) to access the Sensor Management web interface.

IMPORTANT: On some devices running Ubuntu 22.04, Google Chrome may not allow you to interact with the user interface after login due to a known compatibility issue. It is highly recommended that you use Mozilla Firefox in this environment. Alternatively, you can launch Chrome from the terminal using the following command to restore full functionality:

google-chrome --ozone-platform=x11

For Windows users, it is also recommended to leave the scale and layout option of the Display settings at a value of 100%.

Metrics Collection CSV Filename Timestamp

In order to align with the CSV filename convention of all other Cisco Crosswork Assurance products (Assurance Sensor Control and Assurance Sensors), this naming strategy is changed in Sensor Management. The timestamp in the CSV filename represents the time when the file was created.

In all cases, the timestamps of the metrics themselves (present within the content of the file) represent the time of when the metric was produced. Only the timestamp contained in the CSV filename is impacted by this change.

Vision Collect Streaming Limitations on 6.4.1.2 and 6.4.2

When using release firmware 6.4.1.2 with Vision Collect, a disconnection from Sensor Management may incur data loss. The data retention periods are not respected and data loss can occur after a few seconds of disconnection.

When using firmware release 6.4.2 in Skylight elements in high resolution mode with packet loss greater than 10% of the management network, some reporting periods may be lost. Please ensure a reliable management network is in place.

These issues are corrected in Skylight element firmware releases 6.4.3 and higher.

The First Result Records for a New Session Are Skipped by CSV Export

When the CSV producer detects a new performance session, it marks its data for extract from the first time it views the session. If the CSV producer is configured to run every five (5) minutes, this can mean that the first five minutes of result data for a new session will not be exported.

This is expected behavior; all performance data after this initial detection phase will be captured by the CSV producer.

Result Records for Sync Sessions Are Not Exported in Real Time

Sync sessions are not properly aligned with CSV export. Results are not being exported in real time as Assurance Sensor Control is delivering measurement results and Sensor Management is generating CSV files at the exact same time.

If the CSV producer is configured to run every five (5) minutes and sync session has five (5) minute interval, this can indicate that result data for that session will be exported five minutes late.

Zitadel Interoperability

A login failure occurs on the Sensor Management GUI if Zitadel sends both valid and invalid roles during the authentication process. Ensure that only valid roles are assigned to users in Zitadel before attempting to log in to the Sensor Management GUI.

Device Password Management

When supporting or upgrading devices, be aware of password management requirements and potential limitations that may affect device access and integration.

  • When supporting Assurance Sensor Control 24.09 or later and Assurance Sensors 24.07 or later, users may not be aware when a device password change is required. As a result, the device may remain in-service but not function properly because most commands are disabled in Sensor Management. To change the password, users must either manually access the device(s) via Web GUI or CLI or follow the procedure in Changing Default Password for Devices to update the password via CLI set on Sensor Management.

  • It is not possible to change the password for Assurance Sensor Control or Assurance Sensors running version 25.7 or later during the first login if accessing through a reverse proxy. To change the password, access the device directly (via Web GUI or CLI) or follow the procedure in Changing Default Password for Devices to update the password via CLI set on Sensor Management.

Device Onboarding Limitation

When onboarding devices with firmware version 25.7 or later, do not onboard more than 200 devices at a time. Onboarding more than 200 devices concurrently may result in intermittent failures for some of these devices. To avoid issues, split large onboarding operations into batches of 200 devices or fewer.

Data Rewinds

When performing a data rewind operation in Sensor Management, ensure that Analytics has fully processed the current data before initiating another rewind.

For optimal results, avoid performing multiple large rewinds in quick succession.

For small deployments, it is recommended to limit rewinds to a single 7-day period at a time as this helps ensure system stability.

Refer to the sizing guidelines for details.

Authentication and Session Management

When a session timeout occurs, the authentication token may not be properly released. If you reload the page, you may still be logged in.

To ensure session termination and maintain system security, always logout before leaving your workstation unattended.

25.7 Lifecycle

This section lists the planned lifecycle dates of this software release. See the table below outlining the following milestones:

Milestone

Description

Date

General Availability

Date where the product is available for general field deployment for both new installations and upgrades.

2027-03-20

End of Security Support

Date where security patches will no longer be delivered for this release. Any correctives for security defects required after this date will be delivered using the next major release of the software.

Next major release

End of Product Support

Date where functional patches will no longer be delivered for this release. Any correctives for functional defects required after this date will be delivered using the next major release of the software.

2028-03-20

End of Technical Support

Date where technical assistance is no longer available from the Technical Assistance Center for this release.

2029-03-20

© 2026 Cisco and/or its affiliates. All rights reserved.

For more information about trademarks, please visit:
Cisco trademarks 
For more information about legal terms, please visit:
Cisco legal terms