How can I determine what is causing a switch to stop switching?

Posted on 2007-08-07
Last Modified: 2008-02-25
Several times today we have had to re-power a couple of the SWITCHES on our network (we have 5 in this building).  I begin to get complaints of "loss of connection" from users.  Before long I begin to notice they are all on the same switch.  Re-powering that switch seems to correct the problem.   How can I determine what is causing the switch to over-load and shutdown?
Question by:JayMulkey
    LVL 8

    Expert Comment

    it shouldnt be anything to do with overloading unless your switch is aweful, i would reccommend updating the firmware on the switch if thats possible, otherwise look into replacing the switch

    Author Comment

    Each switch is a DELL PowerConnect 3048.  Each has an IP address which I can browse to.  Is updating the firmware difficult?

    If a particular user on a switch were to have a virus which generated excessive traffic, would that cause a switch to stop switching?
    LVL 8

    Expert Comment

    no it shouldnt although you may get reduced performance. I would expect such a problem to be network wide too. switches are non-blocking so its unlikely that it would only affect hosts directly attached to the switch. there should be somewhere on the web console to update the firmware, otherwise call dell they are normally pretty good with hardware support
    LVL 2

    Expert Comment

    If one switch is doing it I would think bad caps in the power supply of the switch occasionally causing low voltage and locking up the switch.  If they are all identical, you can try swapping places and see if the problem follows the switch.

    If more than one is doing it you might check into heat issues.  Are they all in the same room?  How warm do they get?  Are they in an attic or crawl space that gets more sun in a certain part of the day (do you find that a certain one locks up in the morning and others lock up in the afternoon)?

    I also found someone with a similar problem, but theirs is traffic related, see if you might be passing similar data

    The symptoms they report are:

    o uplink/forwarding port lights blink constantly even when there
       is no network traffic

    o Switch becomes unpingable

    o Serial console connection freezes

    o Serial console reports the following strange types of error

       Unhandled interrupts (isc): 00000002 (GT-48304)
       Unhandled interrupts (isc): 00000002 (GT-48304)
       Unhandled interrupts (isc): 00000040 (GT-48304)
       Unhandled interrupts (imec): 40000000 (GT-48304

    The serial connection may be harder to test, but do you have anything similar on your switches like the lights always flashing?
    LVL 27

    Accepted Solution

    I'm surprised that no one has mentioned this directly - you have to get some visibility into the switch.  What kind of switch is it?  Are we talking Cisco or Linksys.  Get into it and look at logs, port statistics, cpu, memory, performance.

    After that get SNMP and RMON working on it and start feeding to a syslog server and monitoring your logs.  Frequently, a good switch will give out detailed messages about what's wrong and you can get a clue as to how to fix it.

    Author Comment

    Each switch is a DELL PowerConnect 3048.  Each has an IP address which I can browse to from my laptop.  My problem is:  the data, graphs, and terms mean little to me ("inbound non-unicast packets", "ethernet oversize packets", "outbound octet rate", etc.)  
    I'm able to see activity on each port but what would constitute abnormal activity?  I guess if each port on the switch (which represents a single user) shows 'normal' activity and one is 'off the chart' that might give me a user to go talk to.
    I think it may even keep a running history.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Find Ransomware Secrets With All-Source Analysis

    Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

    Suggested Solutions

    Every server (virtual or physical) needs a console: and the console can be provided through hardware directly connected, software for remote connections, local connections, through a KVM, etc. This document explains the different types of consol…
    PRTG Network Monitor lets you monitor your bandwidth usage, so you know who is using up your bandwidth, and what they're using it for.
    Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
    In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

    779 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    12 Experts available now in Live!

    Get 1:1 Help Now