While doing software upgrades/ISSU with the "no-validate" option, from any version before 21.2R2 to any version starting 21.2R2 and later, make sure you have a complete TCP session authentication configuration. Either it should be complete with both “authentication-algorithm” and “authentication-key-chain” clauses or neither should be present.