Certification795 problems· 7 reviewed

CCNP Enterprise

795 incident response problems that help with CCNP Enterprise prep.

All problems (795)

NETWORK-1572An MLAG peer template is updated and one VLAN still lands wrongOne VLAN lands wrong after MLAG template cleanup.NetworkAdvanced10 minProNETWORK-1561An NGINX ingress keeps the new upstream and one site still reports the old client IPOne site logs the wrong client IP after ingress and real_ip cleanup.NetworkAdvanced10 minProNETWORK-1571An NGINX map update is correct and one hostname still routes oldOne hostname still routes to the old upstream after a map update.NetworkAdvanced10 minProNETWORK-1581An NGINX upstream keepalive fix lands and one site still speaks to the old backendOne site still talks to the old backend after an NGINX keepalive fix.NetworkAdvanced10 minProNETWORK-1474A CARP failover restores sessions and branch DNS still breaksBranch traffic survives failover while local name overrides disappear until the primary returns.NetworkAdvanced11 minProNETWORK-1477A Cloudflare Access tunnel looks authenticated and still fails WebSocketsAuthenticated WebSockets fail only on one route family behind Cloudflare Tunnel.NetworkAdvanced11 minProNETWORK-1467A Cloudflare Tunnel reconnects repeatedlyCloudflare Tunnel becomes unstable after a firewall policy refactor on the return path.NetworkAdvanced11 minProNETWORK-1553A Cloudflare Tunnel route is active and websocket upgrades still failOnly websocket traffic fails on one connector after origin certificate rotation.NetworkAdvanced11 minProNETWORK-1488A Cloudflare Tunnel upgrade restores websockets and one path still dropsWebSocket sessions still die after a cloudflared upgrade, but only through one proxy path.NetworkAdvanced11 minProNETWORK-1557A NetFlow exporter migrates and one collector still attributes traffic to the old zoneTraffic is misattributed only after a NetFlow exporter restart and migration.NetworkAdvanced11 minProNETWORK-1565A Palo Alto decryption profile updates and one rule still exempts trafficOne firewall rule still exempts traffic after decryption policy updates.NetworkAdvanced11 minProNETWORK-1486A Palo Alto HA failover succeeds and inbound traffic still diesInbound traffic drops briefly after firewall failover even though the HA pair reports a clean transition.NetworkAdvanced11 minProNETWORK-1499A Palo Alto URL category override deploys and one browser still hits the old categoryA URL category override works for most traffic and fails for a browser flow that bypasses decrypt policy.NetworkAdvanced11 minProNETWORK-1509A URL category override deploys and one browser still hits the old categoryA URL category override works for most traffic and fails for a browser flow that bypasses decrypt.NetworkAdvanced11 minProNETWORK-1519A URL category override deploys and one browser still sees the old policyA URL category override works for most traffic and fails for one decrypt-bypass browser flow.NetworkAdvanced11 minProNETWORK-1529A URL category override deploys and one browser still sees the old policyA URL override works for most traffic and fails for one bypass flow.NetworkAdvanced11 minProNETWORK-1568An Envoy retry policy changes and one cluster still retries the old priority setOne cluster retries the wrong backend set after an Envoy policy change.NetworkAdvanced11 minProNETWORK-1562An EVPN import policy is updated and one leaf still learns the old route-targetOne EVPN leaf keeps learning a retired route-target after policy updates.NetworkAdvanced11 minProNETWORK-1551An NGINX gateway reloads and one location still uses the old upstreamOne route keeps hitting the old upstream after a gateway reload.NetworkAdvanced11 minProNETWORK-1495An NGINX ingress proxy serves HTTP/2 correctly and one backend still sees plain HTTPA migrated backend still receives HTTP on one path after the rest of the platform has moved to HTTPS upstreams.NetworkAdvanced11 minPro