CCNP Enterprise
795 incident response problems that help with CCNP Enterprise prep.
Read first
When DNS changed but some clients still hit the old backendAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the DNS record is updated but resolver cache, HTTP/2 keepalive, or client pools hold on to the old target.Network3 min readWhen firewalld looks open but connections keep getting blockedAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a port rule appears to exist but the connection fails because of zone, runtime/permanent drift, source binding, or an upstream firewall.Network3 min readHow to separate timeout and connection refused by network pathAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when DNS, route, firewall, proxy, and listener states all look like the same connection failure.Network3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
NETWORK-002Port exhaustion in a high-request segment and kernel tuningCovers how ephemeral ports, TIME_WAIT, and sysctl parameters connect to a service failure.ReviewedNetworkAdvanced30 minProNETWORK-041OSPF neighbors stay in EXSTARTBoth routers can ping each other, but adjacency never reaches full because one side advertises a different interface MTU on the same link.ReviewedNetworkIntermediate21 minFreeNETWORK-064ACL shadow rule blocks load balancer health checks from the SNAT poolUser traffic seems permitted on paper, but backends stay marked unhealthy because the firewall never allowed the translated health-check source range.ReviewedNetworkIntermediate18 minFreeNETWORK-1611A trunk link comes up and one VLAN still failsOne VLAN still fails right after a renumbering change.ReviewedNetworkBeginner6 minFreeNETWORK-1613A DNS server is reachable and one zone still failsOne zone still fails after changing a DNS forwarder.ReviewedNetworkBeginner6 minFreeNETWORK-1615A BGP session comes up and traffic still exits wrongTraffic still exits the old path after a BGP preference change.ReviewedNetworkBeginner7 minFree
All problems (795)
NETWORK-064ACL shadow rule blocks load balancer health checks from the SNAT poolUser traffic seems permitted on paper, but backends stay marked unhealthy because the firewall never allowed the translated health-check source range.ReviewedNetworkIntermediate18 minFreeNETWORK-041OSPF neighbors stay in EXSTARTBoth routers can ping each other, but adjacency never reaches full because one side advertises a different interface MTU on the same link.ReviewedNetworkIntermediate21 minFreeNETWORK-1613A DNS server is reachable and one zone still failsOne zone still fails after changing a DNS forwarder.ReviewedNetworkBeginner6 minFreeNETWORK-1611A trunk link comes up and one VLAN still failsOne VLAN still fails right after a renumbering change.ReviewedNetworkBeginner6 minFreeNETWORK-1615A BGP session comes up and traffic still exits wrongTraffic still exits the old path after a BGP preference change.ReviewedNetworkBeginner7 minFreeNETWORK-1626A DNS failover rule is ready and one check still failsOne DNS failover probe still fails after an endpoint move.ReviewedNetworkBeginner7 minFreeNETWORK-072LACP bundle never forms after a stack replacementCabling is correct, but the upstream sees a different partner identity and refuses to aggregate the links into the expected bundle.NetworkIntermediate16 minFreeNETWORK-107DHCP relay uses the correct helper address but the source interface belongs to the wrong VRF so replies never returnDiscover messages leave the switch, yet offers vanish because the server replies into a routing context that has no path back to the client segment.NetworkIntermediate17 minFreeNETWORK-079OSPF virtual link stays downArea IDs still look familiar, but the virtual link cannot form because the transit area assumptions were broken during a partial topology cleanup.NetworkIntermediate17 minFreeNETWORK-068Port-channel min-links keeps the bundle down after a partial member failureOne physical path still forwards traffic, but the logical interface remains down because the configured minimum bundle size is no longer satisfied.NetworkIntermediate17 minFreeNETWORK-084Spanning-tree guard blocks one hypervisor uplinkThe network configuration is stable, but a host starts sending unexpected bridge protocol units and the protection feature shuts the access port down.NetworkIntermediate17 minFreeNETWORK-080MAC flapping alarms appearThe network is stable, but one mobile workload triggers MAC move alarms and intermittent forwarding loss because the switching design assumes slower host movement.NetworkIntermediate18 minFreeNETWORK-054VRRP stays on the backup routerFailover worked during the incident, but the original priority path never resumes because preemption policy no longer matches the intended steady state.NetworkIntermediate18 minFreeNETWORK-037Internal clients cannot reach the public VIPExternal users can access the service normally, but inside clients fail when they resolve the same public name because the edge path does not support loopback NAT.NetworkIntermediate20 minFreeNETWORK-033Cross-vendor EtherChannel failsThe bundle comes up on one side only, leaving traffic hashed inconsistently, because the two platforms are not negotiating the channel mode the same way.NetworkIntermediate23 minFreeNETWORK-106A QinQ handoff preserves the service VLAN but rewrites the inner PCP bits so voice traffic loses priorityConnectivity remains intact, but quality degrades because the handoff normalizes priority bits the downstream voice design expected to preserve.NetworkIntermediate16 minFreeNETWORK-092EtherChannel load-balancing hash sends one chatty flow over the only degraded member linkMost traffic looks normal, but one application suffers because its flow hash repeatedly lands on the weakened physical member of the bundle.NetworkIntermediate16 minFreeNETWORK-103Root guard blocks the intended new spanning-tree root after maintenance and access switches stay pinned to the old pathThe maintenance plan is correct, yet the protection feature prevents the desired root election because the uplink role changed during rewiring.NetworkIntermediate16 minFreeNETWORK-051OSPF passive-interface default suppresses the new transit VLAN neighborThe router has the right addressing and can ping the far side, but adjacency never forms because the new transit interface still inherits passive mode.NetworkIntermediate20 minFreeNETWORK-042HSRP split behavior appears after trunk allowed list drops the failover VLANGateway redundancy works on most VLANs, but one subnet loses predictable failover because the standby control traffic no longer crosses the trunk everywhere it should.NetworkIntermediate22 minFree