Topic46 problems· 1 reviewed

Firewall Policy Basics

46 incident problems about Firewall Policy Basics. Start with the reviewed ones.

All problems (46)

NETWORK-1208Stateful firewall drops only the return pathA service opens outbound sessions successfully but return packets come back through another path and get dropped.NetworkAdvanced21 minProNETWORK-1358A DNS service resolves small answers and signed domains failA DNS service resolves small answers and signed domains fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub success does not prove the recursive server can complete its own fallback path.NetworkIntermediate12 minProNETWORK-1366A DNS service resolves small records and DNSSEC-heavy zones failA DNS service resolves small records and DNSSEC-heavy zones fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub success does not prove the recursive server can finish its own fallback behavior.NetworkIntermediate12 minProNETWORK-1364A Netgate policy route sends packets out the intended WAN and health probes still failA multi-WAN design appears correct on paper and later operators see health checks and user traffic disagree on which path is active.NetworkIntermediate12 minProNETWORK-1354A Netgate policy route sends traffic out the right WAN and health checks still failA multi-WAN firewall is tuned for one application and later probes disagree with user traffic about which path is actually in use.NetworkIntermediate13 minProNETWORK-1340A pfSense HA pair passes XMLRPC sync and still divergesAn HA firewall pair is upgraded and later one node behaves differently despite successful XMLRPC config sync.NetworkIntermediate13 minProNETWORK-1342A pfSense policy route works for clients and monitoring still reports the...A pfSense policy route works for clients and monitoring still reports the... focuses on firewall-policy-basics and asks the reader to isolate the key signal in netgate. Policy routing can look correct until reply-to pins the reverse path so...NetworkIntermediate13 minProNETWORK-1277Manual DNS testing passesA DNS incident appears solved after a manual command, but applications continue failing in production.NetworkIntermediate13 minProNETWORK-1338A DNS path fails only for signed domainsOperators validate DNS from a client and still see production resolvers fail selectively for signed zones.NetworkIntermediate14 minProNETWORK-1318A DNS resolver works for most records and large TXT lookups failA DNS resolver works for most records and large TXT lookups fail focuses on dns-resolution and asks the reader to isolate the key signal in Cisco. Partial DNS breakage often starts with packet-size assumptions, not name data quality.NetworkIntermediate14 minProNETWORK-1348A DNS resolver works for most zones and signed domains failA DNS resolver works for most zones and signed domains fail focuses on dns-resolution and asks the reader to isolate the key signal in Cloudflare. Stub resolver success does not prove the recursive server can complete its own fallback behavior.NetworkIntermediate14 minProNETWORK-1329A firewall path breaks oversized DNSSEC answersA security hardening change is followed by selective failures against DNSSEC-enabled domains while ordinary resolution remains fine.NetworkIntermediate14 minProNETWORK-1316A Palo Alto URL override fixes one domain and another subpath still...A Palo Alto URL override fixes one domain and another subpath still... focuses on firewall-policy-basics and asks the reader to isolate the key signal in palo-alto. URL categorization can vary within a site enough to make a single broad-loo...NetworkIntermediate14 minProLINUX-1368A rootless Podman service reports healthy and the first outbound call failsA rootless Podman service reports healthy and the first outbound call fails focuses on firewall-policy-basics and asks the reader to isolate the key signal in Linux. Reload-safe firewall state matters more when user-namespace-specific rule...LinuxAdvanced14 minProNETWORK-1265Manual DNS tests over TCP succeed but real users still failNetwork incident scenario used for structured troubleshooting practice.NetworkIntermediate14 minProNETWORK-1270Manual DNS tests over TCP succeed but real users still failA DNS outage seems cleared after a successful test command, but applications continue failing because they never use the same transport that the operator tested.NetworkIntermediate14 minProNETWORK-1249A manual DNS test succeeds over TCP but real clients still failAn operator proves DNS with one command and later finds the application still cannot resolve names in production.NetworkIntermediate15 minProNETWORK-1254A manual TCP DNS test succeeds but real clients still failAn operator proves DNS with one command and later finds that the application still cannot resolve names in production.NetworkIntermediate15 minProNETWORK-1244DNS over TCP passes the manual test but users still failAn operator proves DNS works with one TCP command and later finds the production application still fails every ordinary lookup.NetworkIntermediate15 minProNETWORK-1234DNS over TCP succeeds but ordinary lookups still failOperators validate a DNS query using TCP and wrongly conclude the general resolver path has recovered.NetworkIntermediate15 minPro