04-02-2025 07:11 AM
We have recently deployed more than 80 C1300-8FP-2G switches in our environment, at several remote locations. I am seeing this problem on several switches at all locations.
The issue is that the switch appears to lose it's default gateway at times. We have a management IP assigned to a VLAN (99) on the switch. At times I cannot PING or access this switch remotely from a different subnet. During this remote ping failure, I am able to PING the switch from the core switch that is providing the SVI for this IP that is on the same subnet. The switch is not down, all the ports are UP.
This problem will eventually clear on its own, and I am able to PING and access the switch remotely again. We have updated the firmware on a few switches (4.1.6.54) and are still seeing this problem.
Has anyone else experienced this ?
04-02-2025 08:53 AM
- Check logs on the device and look for clues,
M.
04-02-2025 02:23 PM
If when the problem is happening you are able to ping/access from within vlan 99 but not from other vlans, then it does sound like an issue with routing/default gateway. When the problem is happening are devices connected in other vlans able to function normally?
04-08-2025 12:40 PM
I'm sorry for not responding sooner. We don't believe that this is a routing/gateway issue. We have several 2960X series switches on the network, in the same VLAN, using the same default gateway and routing, no problems with these.
We are getting these messages on the switch for port Gi10, which is the trunk port.
08-Apr-2025 16:09:13 :%SECURITYSUITE-I-SECSYNBLOCKED: 08-Apr-2025 16:09:13:
A TCP SYN Attack was identified on port gi10.
TCP SYN traffic destined to the local system is automatically blocked for 60 seconds.
04-08-2025 03:28 PM
Thanks for the additional information (and the delay in responding is not a problem). It certainly does seem that security implemented in the switch software is blocking traffic. Based on the messages shown in your recent post I can understand why management access might be impacted. I am bit puzzled why ping would be impacted if the security issue is with TCP traffic.
04-09-2025 09:26 AM
Agreed, not sure why TCP SYN traffic being blocked for 60 seconds would effect UDP ICMP traffic ? We are working a TAC case with Cisco.
Thanks...
04-09-2025 01:08 PM
Thanks for the update. Glad to know that you are working a case with TAC. Please update us as you learn anything from them.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide