cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9684
Views
80
Helpful
27
Replies

Dynamic VLAN assignement works randomly on 2960-X after upgrading in 15.2(7)E1

AURELIEN MERE
Level 1
Level 1

Hello

 

After upgrading our 2960-X stacks from 15.2(6)E3 to 15.2(7)E1, dynamic vlan assignment through MAB works randomly.

We sometimes encounter this kind of errors :

%PM-3-INTERNALERROR: Port Manager Internal Software Error (vlan > 0 && vlan < PM_MAX_VLANS: ../switch/pm/pm_vlan.c: 878: pm_vlan_test_portlist)

the port stays in VLAN 1 and MAC address on the port is in "Drop" state in the MFT.

We have the problem only with 2960-X stacks in 15.2(7)E1, all others are working fine.

RADIUS Debug show that the Tunnel-Private-Group-Id is correctly received on the switch, but somehow is discarded.

Have you encountered the same issue ?

Thanks for your help

 

Aurélien

27 Replies 27

Hi Y C,

 

Thanks for sharing this. We took some time to analyze your situation and compare it with ours.

 

We've upgraded from 15.2(7)E0a to 15.2(7)E3 and downgraded to 15.2(7)E2.
In the original config (E0a) we've used the line portfast edge on multiple access ports, we downgraded and upgraded to a version where this line was still supported. So I'm not sure if this is relatable ?


The problem only started for us (V15.2(7)E2) when we changed an accessports to assign a vlan via ISE.
When we configured a port, inline the connection was lost and everything broke down.

 

We assume that the disabled ports, stp errors, port management errors and more are a mudslide of errors which resulted from the bug mentioned earlier.

But the chance is that we're staring ourselves blind at these similar bugs cause that is the only link we've found that relates to this behavior.

 

Note: We've also started to creating a TAC Case.
The deployment of ISE on stacked switches are on hold at the moment. bummer

Hello,

 

After months of investigations with the TAC and developers, default has been confirmed/identified on 15.2(7)E1 and E2 while absent on 15.2(7)E0a.

Fix has been tested on lab and will be include on 15.2(7)E4 which should be released on March.

 

Regards,

 

Thibault

Thibault - Please elaborate, what default are you talking about?

Hello Y C

 

The one described by Aurélien.

Does anybody have information about the release date of 15.2(7)E4 ?

 

Many people are waiting for this update.....

 

It was released today (22.03.2021).

 

But I didn't check if the issue is fixed.

Maybe someone can confirm it?

 

Regards
Pascal

I've upgraded a few switches in test environment and for the moment no regression found.

I'm currently waiting for the release notes to be published to go further and upgrade a switch in production environment to see if problem is actually fixed.

Release notes are published --> Release Notes for Cisco IOS Release 15.2(7)E4 - Cisco

 

Those release notes are for the IOT/Industrial series switches. This is the link to the 2960x series. It does note that CSCvv94988 is resolved.

 

And it's not yellow star'd yet so as policy we may not consider it for production. E0a is still the target for our upgrade when it comes time.

Melantrix
Level 1
Level 1

It was released. At the moment I'm unable to clarify if this/our problems was fixed.

mel-ghazali
Level 1
Level 1

Dears,

Earlier we had upgraded to 15.2.7E2 but got in an issue that in stack switches when a dot1x/mab authentication from ISE with dynamic vlan assignment, when users went to Quarantine it got stuck and users didn’t reached from any where.

As per Tac, they suggested to go to 15.2.4E10 and then everything went fine.

recently we’ve upgraded to 15.2.7E2 but we got the same issue as described earlier.

 

We are running 17.2.7e4 for a month now, without any issues.
(on devices whith and without an cisco ISE deployment)

AURELIEN MERE
Level 1
Level 1

We also have been running 15.2(7)E4 on small production environment since the release without any problems on 2960X/C/CX.

Bug seems to be finally fixed.

Btw, the release is now "suggested" / yellow-star on Cisco dowloads, we are currently planning the upgrade of all production switches.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card