These release notes cover the requirements, new features, and changes for the Cisco® Provider Connectivity Assurance Sensor GT/GT-S (formerly Accedian Skylight GT and GT-S Performance Elements) firmware version 25.07.
See Accedian Skylight is now Cisco Provider Connectivity Assurance for a table of all the new product names.
We highly recommend you read all release notes prior to installing this firmware version.
For more information, see: Cisco Provider Connectivity Assurance Sensor GT
Requirements
Assurance Sensor GT/GT-S 25.07 requires Legacy Orchestrator 23.12.3 or 24.09.1, or Sensor Management 25.07 or later.
| Product Name | Software Version | Build Number | Software Files |
|---|---|---|---|
| Provider Connectivity Assurance Sensor GT/GT-S | 25.07 GA | 25.07_121591 | Accedian_MIBS_121591 AMT_25.07_121591.afl Note: Customer sign-in credentials are required to access this link. |
Operational Considerations
Be aware of these operational considerations:
- IMPORTANT: If you are downgrading the firmware without performing a factory reset, you will not be able to connect to the board via CLI or WEB interfaces.
- IMPORTANT: Prior to upgrading the firmware on a unit where the History Buckets feature is enabled, certain precautions may need to be taken to prevent a loss of history data during the upgrade. Refer to ATRC-B10797 for details.
- In a G.8032 ring configuration, the Assurance Sensor GT-S supports a maximum of 62 policies on the LAG port (i.e. policies that govern how traffic is dropped from the ring to UNI ports). This limitation does not apply to the UNI ports (i.e. policies that govern how traffic is added to the ring) unless the VLAN-tagged customer traffic is passed transparently from the UNI port to the ring through one-to-one mapping.
One way to avoid this limitation and maximize the number of usable UNI policies is to encapsulate multiple customer VLANs (coming from the UNI) under a single service provider VLAN on the ring. Doing so reduces the number of policies required by the LAG port. - Redundant Parameter Handling: If you enter redundant parameters in a command line, the system applies only the value of the last instance. For example, in the command
mode edit syslog-ng enable syslog-ng disable, the system applies the final parameter valuesyslog-ng disable. - When the system starts and PCA-AAA is not yet configured, the
pca-aaa-client show connection statuscommand intentionally displays the default value ofOKforlast tokenstatus andlast auth request, and0D:00H:00M:00Sfornext token update. In contrast, similar parameters for thepca-aaa-client show session statuscommand, such asLast statusandUptime, are empty. - By default, the tcpdump application converts the Source IP address and Destination IP address from the IP Header into hostname strings if the capture is directed to the console (stdout).
- Safari is not a supported browser. Accessing the application with Safari may result in limited functionality or unexpected behavior.
New Features and Enhancements
This Assurance Sensor GT/GT-S release introduces the following new features and enhancements:
Cryptography, Encryption, and Key Management Enhancements
Enhanced cryptography, encryption, and key management capabilities, including:
- Key-pair generation for local certificates
- Management of local default and custom certificates
- Certificate revocation status checks
- Alarms for certificate expiration and expired certificates
- CLI support for certificate operations
- Trusted Root Store (TRS) bundle management via Management Web Interface
Identity and Access Management Enhancements
Implemented security improvements to identity and access management while maintaining backward compatibility. Key enhancements include:
- Secure storage of credentials
- Access management via password policies
- Removal of default credentials
- Prevention of undocumented access
Application and Interface Security Enhancements
Implemented a comprehensive set of application and interface security enhancements. Key features include
- Input validation
- Secure data handling
- Protection against injection attacks, cross-site scripting (XSS), CSRF, and click-jacking
- Enforcement of HTTP Strict Transport Security
- Safe URL handling
Digital Signature Verification for AFL Files
Software update procedure now supports digital signature verification for AFL files, enhancing product security with improved authenticity and integrity checks.
Syslog Data Streaming to Multiple Destinations and IPv6 Support
Enabled syslog data streaming to multiple destinations via TCP, allowing alerts to be forwarded to administrators and Information System Security Officers (ISSOs) and added syslog application support for the IPv6 protocol at the network and for the configuration of the RLS (Remote Logging Server) destination in a string-based format representing an IPv6 address.
Provider Connectivity Assurance AAA and MFA Integration
Added support for secure access to a centralized Authentication, Authorization, and Accounting (AAA) server and Multi-Factor Authentication (MFA) capabilities to Cisco Provider Connectivity Assurance Sensors.
This feature is available in the Alpha state intended for early field trials only and is not recommended for production environments. For further details, contact Cisco Technical Support.
Cisco SSL and Cisco SSH Library Integration and FIPs Mode Activation
Integrated Cisco SSL and Cisco SSH libraries to support FedRAMP (Federal Risk and Authorization Management Program) compliance. This feature includes a runtime switch to enable FIPS (Federal Information Processing Standards) mode for these libraries. FIPS mode can be enabled or disabled via the fips edit CLI command.
Corrected Issues
This Assurance Sensor GT/GT-S release corrects the following issues:
Management Web Interface Access Inaccessible with DNS Name
After upgrading to version 24.07, the Management Web Interface is inaccessible when using the DNS name, resulting in an 'Access Error: Site or page Not found' message.
Release 25.07 Lifecycle
This section lists the planned lifecycle dates for this release.
| Milestone | Description | Date |
|---|---|---|
| General Availability | Date where the product is available for general field deployment for both new installations and upgrades. | 2025-08-01 |
| End of Security Support | Date where security patches will no longer be delivered for this release. Any correctives for security defects required after this date will be delivered using the next major release of the software. | Next Major Release |
| Last Time Buy / Last Time Ship | Date where this release can no longer be purchased. | 2027-08-01 |
| End of Product Support | Date where functional patches will no longer be delivered for this release. Any correctives for functional defects required after this date will be delivered using the next major release of the software. | 2027-08-01 |
| End of Technical Support | Date where technical assistance is no longer available from the Technical Assistance Center for this release. | 2030-08-01 |
© 2026 Cisco and/or its affiliates. All rights reserved.
For more information about trademarks, please visit: Cisco trademarks
For more information about legal terms, please visit: Cisco legal terms
For legal information about Accedian Skylight products, please visit: Accedian legal terms and trademarks