Vendor560 problems· 4 reviewed

Cisco

560 incident problems in Cisco environments.

All problems (560)

NETWORK-399A first-hop redundancy group fails over the gateway IP while one NAC or security system still authorizes the old active member based on switch identity during a staged decommissionGateway continuity hides an adjacent policy engine that keys off the old box. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkAdvanced17 minProNETWORK-153A GRE over IPsec tunnel survives WAN failover, but MSS adjustment stays on the old physical interface and large HTTP transfers start hangingOverlay continuity exists, yet payload sizing logic remained attached to the wrong underlay object.NetworkAdvanced17 minProNETWORK-1295A NAT exemption survives on paper but one backup path still translatesA VPN path works on the active firewall and fails only after failover or during HA testing.NetworkAdvanced17 minProNETWORK-148A PBR next-hop tracks the firewall IP, but the firewall can still answer ARP while the service process behind it is deadThe tracked object remains reachable even though the real dependency has failed.NetworkAdvanced17 minProNETWORK-1297A PMTUD issue affects only DNSSEC responsesUsers resolve common domains correctly and validation-heavy DNS workflows fail in one network path.NetworkAdvanced17 minProNETWORK-369A QoS policy marks the right classes while tunnel overhead changed and one class now fragments or drops before the shaped queue ever sees it during a staged decommissionClassification is correct, but the packet size math no longer fits the path. The service still works through the primary path, but one dependency only fails when the old component is finally drained away.NetworkAdvanced17 minProNETWORK-1299A route reflector cluster stays healthy but one edge blackholes trafficA route policy cleanup on a reflector changes forwarding behavior without dropping any BGP sessions.NetworkAdvanced17 minProNETWORK-330A route summary survives while every specific path behind it is now gone and traffic keeps choosing the black hole during a failover rehearsalAggregation stays healthy after the real forwarding options disappeared. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.NetworkIntermediate17 minProNETWORK-221A route-map matches the right prefix set while one additive community action is replaced instead of appended after a maintenance template changeThe route is still policy-matched, yet a downstream signal disappears because one action semantics was misunderstood. The path looked healthy before the template changed, but one inherited assumption no longer matches the live environment.NetworkAdvanced17 minProNETWORK-225A route-map matches the right prefix set while one additive community action is replaced instead of appended after a retention policy refreshThe route is still policy-matched, yet a downstream signal disappears because one action semantics was misunderstood. The operational object still exists somewhere in the system, but the lifecycle policy around its supporting state no longer matches reality.NetworkAdvanced17 minProNETWORK-223A route-map matches the right prefix set while one additive community action is replaced instead of appended after an environment identity renameThe route is still policy-matched, yet a downstream signal disappears because one action semantics was misunderstood. The functional path still exists, but one identity, namespace, or naming assumption still points at the previous environment contract.NetworkAdvanced17 minProNETWORK-141A route-policy preserves MED during normal operation, but a maintenance template strips it on the backup edge and inbound traffic never returns after failoverPaths exist both ways, yet partner preference signals vanish only on the standby path.NetworkAdvanced17 minProNETWORK-119A route-policy regex matches the AS path set too broadly and blackholes partner prefixes that should stay externalTraffic loss starts after a policy cleanup because the new pattern captures more paths than the operator intended.NetworkAdvanced17 minProNETWORK-121A transit interface was left out of passive-interface default exceptions, and a rogue OSPF adjacency forms during an access switch replacementThe underlay works until maintenance introduces a neighbor on a segment that should never have participated in routing.NetworkAdvanced17 minProNETWORK-1227A trunk passes most VLANs but one voice segment still failsA cross-vendor trunk migration leaves data VLANs healthy while one voice or management path becomes unstable.NetworkIntermediate17 minProNETWORK-270A VRRP pair shares the gateway IP while one downstream ACL still permits only the previous virtual MAC during a failover rehearsalRedundancy is healthy and the dependent security policy remains bound to yesterday's identity. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.NetworkAdvanced17 minProNETWORK-144A VXLAN flood-and-learn segment still receives BUM traffic, but ARP suppression on one VTEP keeps a stale host mapping and east-west packets disappearThe overlay fabric is generally healthy, yet one stale optimization prevents correct endpoint learning.NetworkAdvanced17 minProNETWORK-146An MPLS TE tunnel comes up, but autoroute announce is disabled on one node and normal traffic never uses the engineered pathThe tunnel exists, yet forwarding behavior does not change because one control flag was left off.NetworkAdvanced17 minProNETWORK-129BFD minimum receive timers do not align between vendors, and only one side believes the session is stableBoth devices show partial liveliness, but the negotiated timing reality differs enough to keep the path flapping.NetworkAdvanced17 minProNETWORK-115BGP confederation sub-AS policy strips the community needed to choose the correct exit pathThe routes arrive everywhere, but exit selection is wrong because a transit policy removed the signal the edge uses for preference.NetworkAdvanced17 minPro