Loading...
Loading...
Ping from switch to directly connected hosts in VRF fails with 100% packet loss despite ICMP echo replies arriving at the CPU inband interface. The replies pass CoPP without drops but are not delivered to the VRF network namespace. This affects local host reachability verification and any control-plane originated traffic to directly connected endpoints.
Ping from the switch to directly connected endpoints in a VRF returns 100% packet loss. ethanalyzer on inband shows ICMP replies arriving correctly. tcpdump on the SVI in the VRF namespace captures zero packets. Kernel ICMP counters do not increment. Peer switch with identical platform and configuration can ping the same endpoints successfully. Traffic flows sending through the N9K-C9348GC-FX3PH are not affected. Only ping to local connected hosts failed. Ping to hosts connected to TOR6 in same VLAN will be successful.
N9K-C9348GC-FX3PH running NX-OS 10.6(3) in LXC boot mode. SR-MPLS network edge with HSRP across multiple VRFs. Endpoints authenticated via dot1x MAB multi-domain on access ports. Traffic from routed paths and control-plane protocols (ARP, HSRP) on the same SVI works normally. Only locally-terminated ICMP from directly connected hosts is affected.
None.
Packet is lost in the internal software delivery path between the CPU inband interface and the VRF network namespace. CoPP definitively ruled out (zero drops after clearing stats). L2/L3 forwarding, ACLs, dot1x, TCAM, and hardware all verified correct. Removing directed-broadcast, NetFlow, ACL, or dot1x does not resolve. Bug persists across original 10.6(3) and CSCwt18905 patched image.
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.