I'm trying to determine if anyone else has observed this on the CCR2004 and if should file a bug report or if I need to try to capture more data to determine what is going on with the device.
I have a CCR2004-16G-2S+ as an edge router/NAT-firewall for a /24 of private addresses. In addition to the src-NAT, I have a small number of simple dst-NAT rules and pretty typical input and forward chain rules for a device performing the work this box is doing. I do have uPNP enabled for xbox, although it's probably not a factor. CPU utilization is always very low on the device. I have fast track disabled because I am not sure if it can be trusted on this device yet.
The router is also acting as a switch on some of it's gigabit ports, since i only have 10gig ports in this rack otherwise. These gigabit ports are in a bridge and the port that goes to my ISP is a tagged VLAN interface with a pppoe connection - the port that goes to the ISP is not in the bridge with the devices in question. The 10gig SFP+ interface of the CCR2004 is connected via DAC to a CRS312 (the root bridge in an STP environment - i'm running plain STP for the sonos stuff), which feeds my 10gig switching infrastructure but that interface does not flap.
I don't see anything in the logs around that time other than what is in the attached image. But what I believe happens is the pppoe connection goes down first, then the WAN's physical interface goes down (16 in the attached image). Then the 100mb interfaces on the same device will flap. I think that the interfaces being 100mbit is related to them flapping for some reason. The other gigabit interfaces don't flap when this happens (other than the first offender - the WAN), and the 10gig interface going into my root bridge/10gig core doesn't flap.
I have read other posts where something similar was occurring, so I am wondering if this is possibly a bug. Or do I need to explicitly enable more (perhaps STP) logging to better diagnose? What do you think?