Firewalls & Routing

Practical troubleshooting paths for MSP technicians dealing with real-world support failures.

Firewalls & Routing policy change applies in admin console but target users never receive it

Field Summary

Firewalls & Routing policy change applies in admin console but target users never receive it is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Outbound SMTP relay blocked because egress policy matches wrong object group

Field Summary

Outbound SMTP relay blocked because egress policy matches wrong object group is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Route-based tunnel carries traffic one way only after ISP failover

Field Summary

Route-based tunnel carries traffic one way only after ISP failover is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Firewall HA pair stays synchronized but secondary fails takeover test

Field Summary

Firewall HA pair stays synchronized but secondary fails takeover test is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Web filter category update blocks line-of-business app download endpoint

Field Summary

Web filter category update blocks line-of-business app download endpoint is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Inter-VLAN routing works for ping but not for HTTPS sessions

Field Summary

Inter-VLAN routing works for ping but not for HTTPS sessions is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Edge firewall firmware upgrade resets one custom application rule

Field Summary

Edge firewall firmware upgrade resets one custom application rule is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Static NAT entry published correctly yet source IP logging shows proxy address

Field Summary

Static NAT entry published correctly yet source IP logging shows proxy address is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Port forward works externally but internal hairpin access fails

Field Summary

Port forward works externally but internal hairpin access fails is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Firewall geo-block policy stops vendor access from approved country range

Field Summary

Firewall geo-block policy stops vendor access from approved country range is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.