DNS and Routing
67 incident problems about DNS and Routing. Start with the reviewed ones.
먼저 읽을 가이드
추천 문제
All problems (67)
NETWORK-019After a BGP route change, only certain ASNs take a detour pathA network operations problem where the global route is alive but only certain carrier networks get an inefficient detour.NetworkAdvanced30 minProNETWORK-016Packets arrive, but new connections fail due to conntrack table saturationA situation where the firewall and network are alive but new sessions cannot open due to the kernel connection-tracking limit.NetworkAdvanced29 minProNETWORK-036Path MTU black hole appearsSmall requests succeed while large responses hang, because the firewall blocks the control message needed for PMTUD to adjust the path.NetworkAdvanced24 minProNETWORK-056Site-to-site VPN comes up but traffic still needs NAT exemption for the internal subnetIKE and tunnel status look healthy, but packets still do not pass because the interesting traffic is translated before it can match the VPN policy.NetworkAdvanced24 minProNETWORK-053ECMP asymmetry breaks return traffic when one hop is statefulForward traffic succeeds across equal-cost paths, but responses vanish because a stateful device on one branch never sees the original session creation.NetworkAdvanced25 minProNETWORK-052BFD flaps continuouslyThe routing session looks unstable for no obvious reason, but the real break is that BFD control traffic is handled differently from the data path and gets dropped or delayed.NetworkAdvanced26 minProNETWORK-059Cross-vendor redistribution loop appearsRedistribution seemed correct in each direction separately, but the combined policy creates a feedback loop because the tags used to stop reimport are not interpreted the same way everywhere.NetworkAdvanced28 minProNETWORK-026Latency spike follows asymmetric routing after failoverLatency spike follows asymmetric routing (Timeouts and Latency) is a hands-on troubleshooting drill. Traffic technically succeeds, but the response path changes after failover and introduces an expensive detour. DNS and Routing needs to be checked by narrowing scope, recent ch...NetworkAdvanced28 minProNETWORK-1485A BGP community policy looks symmetric and one route reflector still leaks defaultsDefault routes leak only during maintenance refreshes and not during normal convergence.NetworkAdvanced12 minProNETWORK-1481A pfSense policy route looks correct and return traffic still escapesReturn traffic still uses the old WAN path after a gateway group failover policy update.NetworkAdvanced12 minProNETWORK-1482An Arista MLAG peer-link recovers and one VLAN still blackholesOne VLAN stays blackholed after MLAG recovery even though the peer-link and control plane are healthy.NetworkAdvanced12 minProNETWORK-1490An EVPN type-5 route is present and traffic still missesOnly one tenant VRF misses a newly advertised external prefix during a staged EVPN rollout.NetworkAdvanced12 minProNETWORK-058Controller telemetry fails although the management VRF can still ping the destinationBasic reachability tests look fine, but telemetry and API registration fail because the source interface or VRF binding used by the application differs from the test command path.NetworkAdvanced23 minProNETWORK-035BGP session is established but the expected prefix never reaches the RIBThe neighbor shows Established, yet the target route is absent because a prefix list, route map, or best-path rule discards it before installation.NetworkAdvanced26 minProNETWORK-060SD-WAN policy prefers the worse pathThe controller has path metrics, but the application policy still chooses the higher-latency circuit because the SLA measurement feeding the decision is scoped incorrectly.NetworkAdvanced27 minProNETWORK-039VRF leak design misses the import policy for a shared services subnetThe route exists in the source VRF, but shared services remain unreachable because the target VRF never imports the right route target or policy match.NetworkAdvanced27 minProNETWORK-1489A DHCP relay sends Option 82 correctly and one scope still misassignsClients in one closet keep receiving the wrong scope after an access switch replacement.NetworkIntermediate10 minProNETWORK-1487A split-horizon DNS design is correct and one branch still resolves the public addressOnly one branch office keeps resolving the public endpoint after an internal split-horizon migration.NetworkIntermediate10 minProNETWORK-1484An NGINX upstream DNS update is correct and one pool still serves dead backendsTraffic continues hitting dead backend IPs after a DNS cutover behind NGINX.NetworkIntermediate10 minProNETWORK-1483A Cisco GRE tunnel forms and OSPF still flapsAn OSPF over GRE path flaps only when larger updates cross after a tunnel template merge.NetworkIntermediate11 minPro