Overview
This article documents improvements and bug fixes added to Crosswork Assurance 25.7 since the General Availability (GA) release (Deployer: 25.7.250-108).
Software Component Versions
| Component | Version |
|---|---|
| Deployer | 25.7.250-174 |
| Sensor Collector | 0.652.15-fips |
| Telemetry Collector | r25.07 (0.80.0) |
Fixes and Enhancements
This maintenance release includes several stability and performance improvements for lab-sized deployments. Lab size deployments continue to support up to 1,000 sessions. To ensure improved stability, lab-sized deployments no longer support the ingestion of latent data (data older than 2 hours).
This maintenance release introduces support for deploying Crosswork Assurance on customer-managed Kubernetes clusters using the KOTS installer. This enables on-premises deployment on supported Kubernetes platforms.
Supported Kubernetes Platforms:
- OpenShift
- Google Kubernetes Engine (GKE)
Supported Deployment Configurations:
- Air-gapped (disconnected) environments
- Standard network (non-airgap) environments
- DNS and non-DNS configurations
Note: Upgrading from release 25.7 to a KOTS-based deployment is not supported. KOTS deployments require a fresh installation.
The following table lists fixes and enhancements delivered since the GA release:
| ID | Area | Type | Description |
|---|---|---|---|
| 1215593951061201 | Deployment and Administration | Enhancement | Added a preflight check to refuse embedded cluster installation when a swap partition is present. |
| 1215052373492709 | Metric Streaming | Fix | Fixed an issue where Spark app API calls failed when customer-provided TLS certs were not present in the JVM truststore. |
| 1214846501322852 | Deployment and Administration | Fix | Fixed an issue where generated TLS certificates changed CA after cert-manager renewal, breaking Sensor Collector connections. |
| 1214659718973013 | Deployment and Administration | Fix | Fixed an issue where Sensor Management rejected TLS certificates containing a self-signed root CA in the chain. |
| 1214322185345709 | DB Backup and Restore | Fix | Fixed an issue where Dgraph backup files were not being transferred to MinIO in Kubernetes deployments. |
| 1213887697927606 | Inventory | Fix | Fixed an issue where dynamic metadata failed to map for certain object types due to a session stitching ID mismatch. |
| 1213815293772923 | DB Backup and Restore | Fix | Fixed an issue where error backup pods were observed during replicated deployment. |
| 1213798608114566 | Alerting | Fix | Fixed an issue where duplicate alert entries appeared, showing one as in-progress and another as recovered. |
| 1213472910455619 | Data Pipeline and Storage | Fix | Fixed an issue where Druid datasource retention rules were reset to incorrect values after patching. |
| 1213256354687510 | Reports | Fix | Fixed an issue where dataset configurations could not be deleted and reappeared after a page refresh. |
| 1213234152218531 | Users | Fix | Fixed an issue where updating a user's email did not update the associated username and login methods. |
| 1212299078007088 | Deployment and Administration | Fix | Fixed an issue where agent tokens were not automatically renewed before expiration, causing reconnection failures. |
| 1211443152320689 | Dashboards and Analysis | Fix | Fixed an issue causing dashboard slowness and timeout errors for multiple tenants. |
Sensor Management Operational Considerations
Device Interoperability
The following section details the firmware releases that are known to interoperate with this release of Sensor Management. Please refer to the Sensor Management Administrative Operations documentation for a listing of supported functions for each firmware version.
For the releases mentioned below, support for maintenance releases is also included.
| Product | Supported Releases |
|---|---|
| Assurance Sensor Control | 19.12 → 25.07.2 |
| Assurance Sensor GT | 7.1.2 → 25.07 |
| Assurance Sensor LT | 7.1.2 → 25.07 |
| Assurance Sensor LX | 7.9 → 25.07 |
| Assurance Sensor F100 | 22.01.1 → 24.08 |
| Assurance Sensor F25 | 23.09 → 24.08 |
| AT 1G Sensor Element | 1.2.1 |
| AT 10G Sensor Elements | 2.1 → 2.3 |
| CE & NE Sensor Elements | 6.1.0.4 → 6.4 |
| GE Skylight Element | 4.9 |
| GX Skylight Element | 7.4 → 24.11 |
| Skylight VCX | 2.5, 2.7 → 19.07 |
| TE Sensor Element | 6.1.0.4 → 6.4 |
| Velocity FS | 1.0 and 1.1 |
| Velocity FSX | 2.1 and 2.2 |
HTTP Interface Deprecation
The HTTP interface for Sensor Management is no longer supported for GUI operations or REST and XML APIs. Web service clients must transition to the secure HTTPS protocol.
Customers currently using HTTP on port 6080 will be automatically redirected to HTTPS on the same port, meaning no firewall changes are required.
To ensure a secure and seamless experience, access Analytics directly via the Open Crosswork Assurance button located within the Sensor Management interface. Please update any existing bookmarks or client applications to utilize the HTTPS protocol to maintain full security and functionality.
Browser Support Limitations
The minimum recommended screen resolution to operate Sensor Management is 1360 x 768. Lower resolutions will not provide an optimal experience.
Performing a zoom on your display is not recommended due to incompatible implementations with browsers. If a zoom must be applied, please use a Firefox browser as it has the most standard support for this function.
Due to issues with browser compatibility mode and web sockets, Internet Explorer is no longer supported. Please use Google Chrome (version 70 or higher) or Firefox (version 52 or higher) to access the Sensor Management web interface.
IMPORTANT: On some devices running Ubuntu 22.04, Google Chrome may not allow you to interact with the user interface after login due to a known compatibility issue. It is highly recommended that you use Mozilla Firefox in this environment. Alternatively, you can launch Chrome from the terminal using the following command to restore full functionality:
google-chrome --ozone-platform=x11
For Windows users, it is also recommended to leave the scale and layout option of the Display settings at a value of 100%.
Metrics Collection CSV Filename Timestamp
In order to align with the CSV filename convention of all other Cisco Crosswork Assurance products (Assurance Sensor Control and Assurance Sensors), this naming strategy is changed in Sensor Management. The timestamp in the CSV filename represents the time when the file was created.
In all cases, the timestamps of the metrics themselves (present within the content of the file) represent the time of when the metric was produced. Only the timestamp contained in the CSV filename is impacted by this change.
Vision Collect Streaming Limitations on 6.4.1.2 and 6.4.2
When using release firmware 6.4.1.2 with Vision Collect, a disconnection from Sensor Management may incur data loss. The data retention periods are not respected and data loss can occur after a few seconds of disconnection.
When using firmware release 6.4.2 in Skylight elements in high resolution mode with packet loss greater than 10% of the management network, some reporting periods may be lost. Please ensure a reliable management network is in place.
These issues are corrected in Skylight element firmware releases 6.4.3 and higher.
The First Result Records for a New Session Are Skipped by CSV Export
When the CSV producer detects a new performance session, it marks its data for extract from the first time it views the session. If the CSV producer is configured to run every five (5) minutes, this can mean that the first five minutes of result data for a new session will not be exported.
This is expected behavior; all performance data after this initial detection phase will be captured by the CSV producer.
Result Records for Sync Sessions Are Not Exported in Real Time
Sync sessions are not properly aligned with CSV export. Results are not being exported in real time as Assurance Sensor Control is delivering measurement results and Sensor Management is generating CSV files at the exact same time.
If the CSV producer is configured to run every five (5) minutes and sync session has five (5) minute interval, this can indicate that result data for that session will be exported five minutes late.
Zitadel Interoperability
A login failure occurs on the Sensor Management GUI if Zitadel sends both valid and invalid roles during the authentication process. Ensure that only valid roles are assigned to users in Zitadel before attempting to log in to the Sensor Management GUI.
Device Password Management
When supporting or upgrading devices, be aware of password management requirements and potential limitations that may affect device access and integration.
- When supporting Assurance Sensor Control 24.09 or later and Assurance Sensors 24.07 or later, users may not be aware when a device password change is required. As a result, the device may remain in-service but not function properly because most commands are disabled in Sensor Management. To change the password, users must either manually access the device(s) via Web GUI or CLI or follow the procedure in Changing Default Password for Devices to update the password via CLI set on Sensor Management.
- It is not possible to change the password for Assurance Sensor Control or Assurance Sensors running version 25.7 or later during the first login if accessing through a reverse proxy. To change the password, access the device directly (via Web GUI or CLI) or follow the procedure in Changing Default Password for Devices to update the password via CLI set on Sensor Management.
Device Onboarding Limitation
When onboarding devices with firmware version 25.7 or later, do not onboard more than 200 devices at a time. Onboarding more than 200 devices concurrently may result in intermittent failures for some of these devices. To avoid issues, split large onboarding operations into batches of 200 devices or fewer.
Data Rewinds
When performing a data rewind operation in Sensor Management, ensure that Analytics has fully processed the current data before initiating another rewind.
For optimal results, avoid performing multiple large rewinds in quick succession.
For small deployments, it is recommended to limit rewinds to a single 7-day period at a time as this helps ensure system stability.
Refer to the sizing guidelines for details.
Authentication and Session Management
When a session timeout occurs, the authentication token may not be properly released. If you reload the page, you may still be logged in.
To ensure session termination and maintain system security, always logout before leaving your workstation unattended.
Rsync CSV Export Requires Manual Host Key Acceptance
After generating and importing an SSH key for Rsync destinations, CSV files may fail to transfer. This occurs because the Rsync destination's host key has not been accepted inside the mediation pod.
Workaround:
-
Identify the mediation pod:
sudo /usr/local/bin/k0s kubectl -n pca get pod | grep sm-medn -
Access the mediation pod:
sudo /usr/local/bin/k0s kubectl -n pca exec -it <mediation-pod-name> -- /bin/bash -
SSH to the Rsync destination and accept the host key:
ssh <user>@<destination-ip>
You will see a prompt asking to verify the host's authenticity. -
When prompted, type
yesto accept the host key.
After completing these steps, CSV files transfer to the Rsync destination as expected.
© 2026 Cisco and/or its affiliates. All rights reserved.
For more information about trademarks, please visit: Cisco trademarks
For more information about legal terms, please visit: Cisco legal terms