A pfSense policy route looks correct and return traffic still escapes
The rule is right, but active states keep steering replies by the old gateway preference until they are rebuilt.
NetworkAdvanced
A Palo Alto HA failover succeeds and inbound traffic still dies
The firewall pair is healthy, but the neighboring switch ignores the failover advertisement long enough to blackhole new flows.
NetworkAdvanced
A Cloudflare Tunnel upgrade restores websockets and one path still drops
The tunnel is healthy, but a middle proxy times out upgraded streams earlier than the edge expects.
NetworkIntermediate
Internal clients cannot reach the public VIP
External users can access the service normally, but inside clients fail when they resolve the same public name because the edge path does not support loopback NAT.