Topic106 problems· 1 reviewed

Switching And Vlan Design

106 incident problems about Switching And Vlan Design. Start with the reviewed ones.

All problems (106)

NETWORK-1682A VLAN trunk is up and one floor still failsOne floor still loses connectivity after a VLAN renumbering.NetworkBeginner6 minFreeNETWORK-1692A VLAN trunk is up and one floor still failsOne floor still loses connectivity after VLAN cleanup.NetworkBeginner6 minFreeNETWORK-1711A VLAN trunk is up and one floor still failsOne floor still fails after a VLAN trunk cleanup.NetworkBeginner6 minFreeNETWORK-1637A VLAN trunk is correct and one access floor still failsOne floor still fails after a VLAN renumbering.NetworkBeginner7 minFreeNETWORK-1647A VLAN trunk is correct and one floor still failsOne floor still fails after a VLAN renumbering.NetworkBeginner7 minFreeNETWORK-1657A VLAN trunk is correct and one floor still failsOne floor still fails after a VLAN renumbering.NetworkBeginner7 minFreeNETWORK-1667A VLAN trunk is correct and one floor still failsOne floor still fails after a VLAN renumbering.NetworkBeginner7 minFreeNETWORK-090EVPN MAC mobility is detected but the dampening timer keeps traffic pinned to the old leafThe control plane sees the move, yet data still breaks because mobility dampening delays acceptance of the new location longer than the workload can tolerate.NetworkAdvanced22 minProNETWORK-125Policy-based routing on the SVI forces user traffic toward a firewall but also bypasses the local DHCP relay pathSecurity steering works, but address assignment becomes unstable because a local service path was not exempted from the policy.NetworkIntermediate15 minProNETWORK-160A campus fabric migration preserves the SVI gateway addresses, but one downstream ACL still keys off the old chassis MAC and security monitoring floods with false anomaliesRouting is fine, yet dependent controls still expect the previous gateway identity.NetworkAdvanced17 minProNETWORK-399A first-hop redundancy group fails over the gateway IP while one NAC or security system still authorizes the old active member based on switch identity during a staged decommissionGateway continuity hides an adjacent policy engine that keys off the old box. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkAdvanced17 minProNETWORK-336A gateway IP remains stable while one downstream security policy still keys off the previous virtual MAC after a fabric migration during a failover rehearsalAddress continuity masks an identity change that another control still cares about. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.NetworkAdvanced18 minProNETWORK-110The ACL is accepted in the config, but TCAM is full and the new deny rule is never programmed into hardwareOperators trust the running configuration, yet packets keep flowing because the forwarding ASIC could not install the rule set.NetworkAdvanced18 minProNETWORK-126The MLAG peer link looks healthy, but orphan port behavior prevents storage VLAN failover the way the team expectedRedundant links exist, yet one edge case in dual-chassis behavior leaves a subset of single-homed devices isolated.NetworkAdvanced18 minProNETWORK-073QinQ outer VLAN mismatch isolates one tenant even though the provider handoff is upThe carrier circuit is healthy, but one tenant stays dark because the outer service tag expected by the handoff does not match on both edges.NetworkAdvanced21 minProNETWORK-066ECMP asymmetric return traffic breaks the stateful firewall even though both routers look healthyEvery routing table looks correct, yet sessions reset because the forward and return directions traverse different firewall state holders.NetworkAdvanced22 minProNETWORK-062MLAG peer link is healthy but the orphan VLAN is not allowed and ARP blackholes one rackThe chassis pair stays up, yet half the rack cannot resolve the gateway because the affected VLAN was never permitted across the peer path.NetworkAdvanced23 minProNETWORK-085VXLAN VTEP peers are reachable but the overlay MAC table never learns one tenant segmentThe underlay looks healthy, yet one tenant still cannot communicate because the overlay learning path or segment mapping is broken for that VNI only.NetworkAdvanced23 minProNETWORK-152An access switch voice VLAN is correct, but storm-control on multicast suppresses paging traffic only during announcementsThe network is healthy for normal calls, yet bursty multicast paging crosses a threshold the design did not anticipate.NetworkIntermediate15 minProNETWORK-116A multi-auth 802.1X port authorizes the phone, but the PC loops through reauthentication when the data MAC ages outVoice stays online, yet desktop access flaps because the access policy handles multiple identities with different aging behavior.NetworkIntermediate16 minPro