Topic46 problems· 1 reviewed

Firewall Policy Basics

46 incident problems about Firewall Policy Basics. Start with the reviewed ones.

Read first

Recommended problems

Reviewed problems first, then problems with detailed scenarios.

All problems (46)

Port times out only from outside: it works on the server itselfPort times out only from outside: it works on the server itself is a hands-on troubleshooting drill. When a port works locally but times out remotely, check the firewall. firewall-policy-basics needs to be checked by narrowing scope, recent change, and the current live signal...ReviewedNetworkBeginner3 minFreeSECURITY-1345A Cloudflare Access protected app still exposes a management portA Cloudflare Access protected app still exposes a management port focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cloudflare. Zero Trust at the front door does not automatically secure alternate p...SecurityAdvanced15 minProSECURITY-1365A Cloudflare Access app is protected on 443 and an alternate admin listener remains publicA team puts an app behind Cloudflare Access and later discovers a side-channel admin port on the same origin is still reachable directly.SecurityAdvanced13 minProSECURITY-1355A Cloudflare Access app is protected on 443 and an alternate admin port...A Cloudflare Access app is protected on 443 and an alternate admin port... focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cloudflare. Zero Trust at the main hostname does not automatically...SecurityAdvanced14 minProNETWORK-1345A Cisco DHCP relay looks healthy and the server still logs the wrong sourceA Cisco DHCP relay looks healthy and the server still logs the wrong source focuses on firewall-policy-basics and asks the reader to isolate the key signal in Cisco. DHCP relay failures after VRF moves often come from source context drift, not...NetworkAdvanced15 minProLINUX-1324A firewall reload drops production trafficA firewall automation refactor is shipped and operators later see short traffic drops aligned exactly with every policy reload.LinuxAdvanced15 minProLINUX-1334A kernel update fixes a driver issue and a custom nftables service still failsA host kernel upgrade is followed by sporadic early boot network exposure or missing firewall enforcement until services settle.LinuxAdvanced15 minProNETWORK-1290A load balancer can reach the service IP but health checks still failA service behind a load balancer never becomes healthy even though the backend responds from the same subnet during manual testing.NetworkIntermediate15 minProNETWORK-1332A pfSense or Netgate policy route appears correct and return traffic still...A pfSense or Netgate policy route appears correct and return traffic still... focuses on firewall-policy-basics and asks the reader to isolate the key signal in netgate. Stateful firewall return-path behavior can override a route that loo...NetworkAdvanced15 minProNETWORK-1308Large DNS lookups fail only on TCP fallbackOnly large DNS responses or DNSSEC-heavy queries fail through a path that otherwise seems to resolve names correctly.NetworkAdvanced15 minProNETWORK-1301A Palo Alto security rule looks correct but sessions still miss itA firewall change window updates NAT and only afterward one access policy appears to stop matching with no clear deny log explanation.NetworkAdvanced16 minProLINUX-1307Published Docker ports disappear after firewall reloadA host firewall hardening reload runs cleanly and all container-published ports quietly stop receiving traffic.LinuxAdvanced16 minProK8S-1265A LoadBalancer Service works from inside the cluster but external traffic...A LoadBalancer Service works from inside the cluster but external traffic... focuses on firewall-policy-basics and asks the reader to isolate the key signal in AWS. Success from inside the cluster can hide that the backend applies different policy...KubernetesAdvanced17 minProK8S-1270A LoadBalancer Service works from inside the cluster but external traffic...A LoadBalancer Service works from inside the cluster but external traffic... focuses on firewall-policy-basics and asks the reader to isolate the key signal in AWS. Success from inside the cluster can hide that the backend applies different policy...KubernetesAdvanced17 minProNETWORK-1295A NAT exemption survives on paper but one backup path still translatesA VPN path works on the active firewall and fails only after failover or during HA testing.NetworkAdvanced17 minProNETWORK-1297A PMTUD issue affects only DNSSEC responsesUsers resolve common domains correctly and validation-heavy DNS workflows fail in one network path.NetworkAdvanced17 minProNETWORK-1285A firewall cluster syncs configuration but not connection state, so asymmetric return traffic after failover only breaks one long-lived application protocolPolicies match and sessions establish initially, yet one application fails after failover because session state was not replicated the way operators assumed.NetworkAdvanced18 minProNETWORK-1280A firewall migration preserves ACL intent but one application still failsA firewall migration keeps most services working and leaves one application path failing in a way the old ACL logic did not predict.NetworkAdvanced18 minProSECURITY-1208Emergency allowlist fixes the outage but quietly leaves a much broader bypass than intendedA temporary rule restores access, yet it also permits traffic far outside the original blast radius because the exception is too broad.SecurityIntermediate18 minProLINUX-1229An nftables ruleset looks restored but one legacy iptables service replays a stale NAT table on bootThe new ruleset is correct on disk, yet after restart translated traffic behaves as if the old table still owns packet flow.LinuxAdvanced19 minPro