Route or Adjacency Loss
21 incident problems that show up as “Route or Adjacency Loss”.
Read first
When DNS changed but some clients still hit the old backendAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the DNS record is updated but resolver cache, HTTP/2 keepalive, or client pools hold on to the old target.Network3 min readWhen firewalld looks open but connections keep getting blockedAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a port rule appears to exist but the connection fails because of zone, runtime/permanent drift, source binding, or an upstream firewall.Network3 min readHow to separate timeout and connection refused by network pathAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when DNS, route, firewall, proxy, and listener states all look like the same connection failure.Network3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
NETWORK-041OSPF neighbors stay in EXSTARTBoth routers can ping each other, but adjacency never reaches full because one side advertises a different interface MTU on the same link.ReviewedNetworkIntermediate21 minFreeSECURITY-016MFA enforcement skipped for legacy admin endpointMFA enforcement skipped for legacy admin endpoint is a hands-on troubleshooting drill. The main login path correctly enforces MFA, but a secondary admin route still accepts a weaker path. Identity and Access Management needs to be checked by narrowing scope, recent change, and...ReviewedSecurityBeginner14 minFreeNETWORK-014The port is open but a reverse path filter keeps the response from returningA situation where incoming connections are visible but response packets are blocked by kernel policy, so the session never establishes.NetworkBeginner18 minFreeNETWORK-019After a BGP route change, only certain ASNs take a detour pathA network operations problem where the global route is alive but only certain carrier networks get an inefficient detour.NetworkAdvanced30 minPro
All problems (21)
NETWORK-041OSPF neighbors stay in EXSTARTBoth routers can ping each other, but adjacency never reaches full because one side advertises a different interface MTU on the same link.ReviewedNetworkIntermediate21 minFreeSECURITY-016MFA enforcement skipped for legacy admin endpointMFA enforcement skipped for legacy admin endpoint is a hands-on troubleshooting drill. The main login path correctly enforces MFA, but a secondary admin route still accepts a weaker path. Identity and Access Management needs to be checked by narrowing scope, recent change, and...ReviewedSecurityBeginner14 minFreeNETWORK-014The port is open but a reverse path filter keeps the response from returningA situation where incoming connections are visible but response packets are blocked by kernel policy, so the session never establishes.NetworkBeginner18 minFreeNETWORK-054VRRP stays on the backup routerFailover worked during the incident, but the original priority path never resumes because preemption policy no longer matches the intended steady state.NetworkIntermediate18 minFreeNETWORK-057Dynamic ARP inspection drops a host after a static IP move without updated bindingsLayer2 connectivity looks normal, but one endpoint stops talking because the protection policy still trusts the old DHCP or ARP binding state.NetworkIntermediate19 minFreeNETWORK-033Cross-vendor EtherChannel failsThe bundle comes up on one side only, leaving traffic hashed inconsistently, because the two platforms are not negotiating the channel mode the same way.NetworkIntermediate23 minFreeNETWORK-051OSPF passive-interface default suppresses the new transit VLAN neighborThe router has the right addressing and can ping the far side, but adjacency never forms because the new transit interface still inherits passive mode.NetworkIntermediate20 minFreeNETWORK-042HSRP split behavior appears after trunk allowed list drops the failover VLANGateway redundancy works on most VLANs, but one subnet loses predictable failover because the standby control traffic no longer crosses the trunk everywhere it should.NetworkIntermediate22 minFreeSECURITY-019Nginx basic auth protects one path but leaves upload endpoint openNginx basic auth protects one path but leaves upload endpoint open is a hands-on troubleshooting drill. The visible admin page is protected, but an adjacent upload route bypasses the same security control. NGINX Identity and Access Management needs to be checked by narrowing s...SecurityBeginner13 minFreeNETWORK-038Spanning tree root shifts after switch replacement resets bridge priorityA replacement access switch joins successfully, but traffic starts taking the wrong path because the expected root priority was never re-applied.NetworkBeginner16 minFreeNETWORK-055DHCP relay helper is configured but the reply is blocked on the return ACLThe client broadcast is forwarded correctly, yet lease assignment still fails because the routed reply path is filtered differently on the way back.NetworkBeginner17 minFreeNETWORK-034DHCP snooping blocks voice VLAN leases on a new access stackClients on the data VLAN receive addresses correctly, but phones on the voice VLAN fail because the uplink trust boundary or helper path was not mirrored.NetworkBeginner17 minFreeNETWORK-019After a BGP route change, only certain ASNs take a detour pathA network operations problem where the global route is alive but only certain carrier networks get an inefficient detour.NetworkAdvanced30 minProNETWORK-056Site-to-site VPN comes up but traffic still needs NAT exemption for the internal subnetIKE and tunnel status look healthy, but packets still do not pass because the interesting traffic is translated before it can match the VPN policy.NetworkAdvanced24 minProNETWORK-052BFD flaps continuouslyThe routing session looks unstable for no obvious reason, but the real break is that BFD control traffic is handled differently from the data path and gets dropped or delayed.NetworkAdvanced26 minProNETWORK-059Cross-vendor redistribution loop appearsRedistribution seemed correct in each direction separately, but the combined policy creates a feedback loop because the tags used to stop reimport are not interpreted the same way everywhere.NetworkAdvanced28 minProNETWORK-058Controller telemetry fails although the management VRF can still ping the destinationBasic reachability tests look fine, but telemetry and API registration fail because the source interface or VRF binding used by the application differs from the test command path.NetworkAdvanced23 minProNETWORK-035BGP session is established but the expected prefix never reaches the RIBThe neighbor shows Established, yet the target route is absent because a prefix list, route map, or best-path rule discards it before installation.NetworkAdvanced26 minProNETWORK-060SD-WAN policy prefers the worse pathThe controller has path metrics, but the application policy still chooses the higher-latency circuit because the SLA measurement feeding the decision is scoped incorrectly.NetworkAdvanced27 minProNETWORK-039VRF leak design misses the import policy for a shared services subnetThe route exists in the source VRF, but shared services remain unreachable because the target VRF never imports the right route target or policy match.NetworkAdvanced27 minPro