Vendor560 problems· 4 reviewed

Cisco

560 incident problems in Cisco environments.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

All problems (560)

NETWORK-064ACL shadow rule blocks load balancer health checks from the SNAT poolUser traffic seems permitted on paper, but backends stay marked unhealthy because the firewall never allowed the translated health-check source range.ReviewedNetworkIntermediate18 minFreeNETWORK-041OSPF neighbors stay in EXSTARTBoth routers can ping each other, but adjacency never reaches full because one side advertises a different interface MTU on the same link.ReviewedNetworkIntermediate21 minFreeNETWORK-1611A trunk link comes up and one VLAN still failsOne VLAN still fails right after a renumbering change.ReviewedNetworkBeginner6 minFreeNETWORK-1615A BGP session comes up and traffic still exits wrongTraffic still exits the old path after a BGP preference change.ReviewedNetworkBeginner7 minFreeNETWORK-072LACP bundle never forms after a stack replacementCabling is correct, but the upstream sees a different partner identity and refuses to aggregate the links into the expected bundle.NetworkIntermediate16 minFreeNETWORK-107DHCP relay uses the correct helper address but the source interface belongs to the wrong VRF so replies never returnDiscover messages leave the switch, yet offers vanish because the server replies into a routing context that has no path back to the client segment.NetworkIntermediate17 minFreeNETWORK-079OSPF virtual link stays downArea IDs still look familiar, but the virtual link cannot form because the transit area assumptions were broken during a partial topology cleanup.NetworkIntermediate17 minFreeNETWORK-068Port-channel min-links keeps the bundle down after a partial member failureOne physical path still forwards traffic, but the logical interface remains down because the configured minimum bundle size is no longer satisfied.NetworkIntermediate17 minFreeNETWORK-084Spanning-tree guard blocks one hypervisor uplinkThe network configuration is stable, but a host starts sending unexpected bridge protocol units and the protection feature shuts the access port down.NetworkIntermediate17 minFreeNETWORK-080MAC flapping alarms appearThe network is stable, but one mobile workload triggers MAC move alarms and intermittent forwarding loss because the switching design assumes slower host movement.NetworkIntermediate18 minFreeNETWORK-057Dynamic ARP inspection drops a host after a static IP move without updated bindingsLayer2 connectivity looks normal, but one endpoint stops talking because the protection policy still trusts the old DHCP or ARP binding state.NetworkIntermediate19 minFreeNETWORK-033Cross-vendor EtherChannel failsThe bundle comes up on one side only, leaving traffic hashed inconsistently, because the two platforms are not negotiating the channel mode the same way.NetworkIntermediate23 minFreeNETWORK-075IPv6 RA guard blocks the real router after a campus template is copied to the uplinkIPv4 still works, but IPv6 clients lose their gateway because the edge protection template was applied to the wrong interface type.NetworkIntermediate15 minFreeNETWORK-087Router-on-a-stick subinterface works for one VLAN but the allowed list omits the new segmentInter-VLAN routing exists overall, but the newly added segment remains isolated because the trunk never allowed that VLAN onto the router link.NetworkIntermediate15 minFreeNETWORK-094VLAN exists on both switches but VTP pruning removes the path users think is activeThe database is correct, yet traffic still disappears because dynamic pruning removed the VLAN from a trunk users assumed was always carrying it.NetworkIntermediate15 minFreeNETWORK-106A QinQ handoff preserves the service VLAN but rewrites the inner PCP bits so voice traffic loses priorityConnectivity remains intact, but quality degrades because the handoff normalizes priority bits the downstream voice design expected to preserve.NetworkIntermediate16 minFreeNETWORK-082Access switch uplink looks up but the native VLAN changed and voice phones never get the right DHCP scopeLink status is healthy, yet phone onboarding fails because the expected voice and management traffic classification changed with the trunk native VLAN baseline.NetworkIntermediate16 minFreeNETWORK-092EtherChannel load-balancing hash sends one chatty flow over the only degraded member linkMost traffic looks normal, but one application suffers because its flow hash repeatedly lands on the weakened physical member of the bundle.NetworkIntermediate16 minFreeNETWORK-069Internal clients cannot reach the public VIPExternal users connect normally, yet internal users fail on the same FQDN because the firewall does not hairpin the connection back to the inside service path.NetworkIntermediate16 minFreeNETWORK-103Root guard blocks the intended new spanning-tree root after maintenance and access switches stay pinned to the old pathThe maintenance plan is correct, yet the protection feature prevents the desired root election because the uplink role changed during rewiring.NetworkIntermediate16 minFree