Firewall and Proxy Paths
33 incident problems about Firewall and Proxy Paths. Start with the reviewed ones.
Read first
When DNS changed but some clients still hit the old backendAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the DNS record is updated but resolver cache, HTTP/2 keepalive, or client pools hold on to the old target.Network3 min readWhen firewalld looks open but connections keep getting blockedAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when a port rule appears to exist but the connection fails because of zone, runtime/permanent drift, source binding, or an upstream firewall.Network3 min readHow to separate timeout and connection refused by network pathAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when DNS, route, firewall, proxy, and listener states all look like the same connection failure.Network3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
NETWORK-002Port exhaustion in a high-request segment and kernel tuningCovers how ephemeral ports, TIME_WAIT, and sysctl parameters connect to a service failure.ReviewedNetworkAdvanced30 minProNETWORK-006Only the load balancer health check is blocked by the firewall, dropping the whole serviceA situation where the application is fine but a different health-check path policy drains all traffic.ReviewedNetworkIntermediate20 minFreeNETWORK-009An SNI routing problem where the TLS handshake fails only on certain domainsA situation where the certificate is valid but SNI routing is wrong, so only some domains fail.ReviewedNetworkAdvanced24 minProNETWORK-024Firewall allow rule exists but interface match is wrongFirewall allow rule exists but interface match is wrong is a hands-on troubleshooting drill. The rule looks present, yet traffic still drops because it is attached to a different input interface than expected. Firewall and Proxy Paths needs to be checked by narrowing scope, re...ReviewedNetworkBeginner14 minFreeNETWORK-027Resolver search suffix turns short name into wrong destinationResolver search suffix turns short name into wrong destination is a hands-on troubleshooting drill. A short hostname works in one environment and points somewhere else in another because search suffix order changed. DNS and Routing needs to be checked by narrowing scope, recen...ReviewedNetworkBeginner13 minFreeNETWORK-011A proxy-header problem that works with curl but looks like a CORS error only in the browserA proxy-header problem that works with curl but looks like a CORS error only... is a hands-on troubleshooting drill. A situation where it is not an actual network outage but a response-header policy that fails only browser requests. NGINX Firewall and Proxy Paths needs to be c...NetworkBeginner16 minFree
All problems (33)
NETWORK-006Only the load balancer health check is blocked by the firewall, dropping the whole serviceA situation where the application is fine but a different health-check path policy drains all traffic.ReviewedNetworkIntermediate20 minFreeNETWORK-027Resolver search suffix turns short name into wrong destinationResolver search suffix turns short name into wrong destination is a hands-on troubleshooting drill. A short hostname works in one environment and points somewhere else in another because search suffix order changed. DNS and Routing needs to be checked by narrowing scope, recen...ReviewedNetworkBeginner13 minFreeNETWORK-024Firewall allow rule exists but interface match is wrongFirewall allow rule exists but interface match is wrong is a hands-on troubleshooting drill. The rule looks present, yet traffic still drops because it is attached to a different input interface than expected. Firewall and Proxy Paths needs to be checked by narrowing scope, re...ReviewedNetworkBeginner14 minFreeNETWORK-011A proxy-header problem that works with curl but looks like a CORS error only in the browserA proxy-header problem that works with curl but looks like a CORS error only... is a hands-on troubleshooting drill. A situation where it is not an actual network outage but a response-header policy that fails only browser requests. NGINX Firewall and Proxy Paths needs to be c...NetworkBeginner16 minFreeNETWORK-037Internal clients cannot reach the public VIPExternal users can access the service normally, but inside clients fail when they resolve the same public name because the edge path does not support loopback NAT.NetworkIntermediate20 minFreeNETWORK-021Proxy forwards HTTPS as HTTP after port-based rule rewriteProxy forwards HTTPS as HTTP (Timeouts and Latency) is a hands-on troubleshooting drill. Traffic reaches the proxy, but a port rewrite changes the scheme assumption and breaks the application redirect flow. NGINX Firewall and Proxy Paths needs to be checked by narrowing scope,...NetworkBeginner15 minFreeNETWORK-055DHCP relay helper is configured but the reply is blocked on the return ACLThe client broadcast is forwarded correctly, yet lease assignment still fails because the routed reply path is filtered differently on the way back.NetworkBeginner17 minFreeNETWORK-010A missing WebSocket upgrade header drops real-time connectionsCovers a reverse-proxy misconfiguration where plain HTTP works but only WebSocket fails.NetworkIntermediate18 minFreeNETWORK-007A missing ip_forward setting blocks NAT egress after a rebootCovers a kernel network setting problem that a temporary fix resolves but that breaks again after a reboot.NetworkIntermediate22 minFreeNETWORK-009An SNI routing problem where the TLS handshake fails only on certain domainsA situation where the certificate is valid but SNI routing is wrong, so only some domains fail.ReviewedNetworkAdvanced24 minProNETWORK-002Port exhaustion in a high-request segment and kernel tuningCovers how ephemeral ports, TIME_WAIT, and sysctl parameters connect to a service failure.ReviewedNetworkAdvanced30 minProNETWORK-013IPv6 precedence slows connections for only some clientsIPv6 precedence slows connections for only some clients is a hands-on troubleshooting drill. A situation in a dual-stack environment where poor IPv6 path quality causes connection delays for only certain users. Firewall and Proxy Paths needs to be checked by narrowing scope, r...NetworkAdvanced26 minProNETWORK-036Path MTU black hole appearsSmall requests succeed while large responses hang, because the firewall blocks the control message needed for PMTUD to adjust the path.NetworkAdvanced24 minProNETWORK-056Site-to-site VPN comes up but traffic still needs NAT exemption for the internal subnetIKE and tunnel status look healthy, but packets still do not pass because the interesting traffic is translated before it can match the VPN policy.NetworkAdvanced24 minProNETWORK-053ECMP asymmetry breaks return traffic when one hop is statefulForward traffic succeeds across equal-cost paths, but responses vanish because a stateful device on one branch never sees the original session creation.NetworkAdvanced25 minProNETWORK-040Firewall rule shadowing makes the app port reachable from one segment onlyAn allow rule was added for the correct service, but an earlier broader rule still matches first on another path and blocks the flow unexpectedly.NetworkAdvanced25 minProNETWORK-052BFD flaps continuouslyThe routing session looks unstable for no obvious reason, but the real break is that BFD control traffic is handled differently from the data path and gets dropped or delayed.NetworkAdvanced26 minProNETWORK-026Latency spike follows asymmetric routing after failoverLatency spike follows asymmetric routing (Timeouts and Latency) is a hands-on troubleshooting drill. Traffic technically succeeds, but the response path changes after failover and introduces an expensive detour. DNS and Routing needs to be checked by narrowing scope, recent ch...NetworkAdvanced28 minProNETWORK-1488A Cloudflare Tunnel upgrade restores websockets and one path still dropsWebSocket sessions still die after a cloudflared upgrade, but only through one proxy path.NetworkAdvanced11 minProNETWORK-1486A Palo Alto HA failover succeeds and inbound traffic still diesInbound traffic drops briefly after firewall failover even though the HA pair reports a clean transition.NetworkAdvanced11 minPro