Networking

Practical troubleshooting paths for MSP technicians dealing with real-world support failures.

What This Category Covers

Networking tickets should separate physical/link state, IP assignment, DNS, routing, firewall policy, VLAN tagging, and application reachability. Test by IP and hostname before changing infrastructure.

First Layer to Isolate

IP layer first, then DNS, route, firewall/VLAN, and application port.

Useful Tools, Logs, and Portals

  • ipconfig /all
  • nslookup
  • ping/tracert
  • route print
  • Firewall logs
  • Switch/AP controller
  • DHCP scopes

Before You Escalate

  • Source/destination identified
  • IP and hostname tests compared
  • VLAN/firewall path checked
  • Recent network changes reviewed

Articles in This Path

Pick the closest symptom and work from there.

802.1X wired authentication fails after switch firmware updateAlways On VPN device tunnel connects but user tunnel failsAlways-on VPN profile deploys but tunnel does not start before logonApplication publish rule works by IP not FQDNClient receives APIPA address even though DHCP scope has free leasesConditional forwarder works from domain controllers but not DNS management test toolConditional forwarder works on one server onlyConference room SSID works until more than twenty devices connectDHCP failover pair healthy but one scope stops issuing leasesDHCP lease updates fail after credential account lockoutDHCP option for VoIP phones applies at headquarters but not branch scopeDHCP reservations present but wrong scope hands out addressesDHCP scope has leases available but clients self-assignDNS & DHCP alerts indicate success while end-user experience never changesDNS & DHCP configuration survives testing but resets after restart or syncDNS & DHCP credential or certificate rotation breaks an existing integrationDNS & DHCP feature works in web app but fails in desktop clientDNS & DHCP healthy dashboard status masks a failing production workflowDNS & DHCP logging shows delivery yet the target workflow never completesDNS & DHCP new deployment works for pilot group but not for production rolloutDNS & DHCP policy change applies in admin console but target users never receive itDNS & DHCP quarantine or protection action triggers but recovery workflow failsDNS & DHCP workflow succeeds for one account but fails for shared or delegated accessDNS scavenging removes active record for appliance with static IP reservationDNSSEC validation breaks only one third-party SaaS domain lookupEdge firewall firmware upgrade resets one custom application ruleFirewall geo-block policy stops vendor access from approved country rangeFirewall HA pair stays synchronized but secondary fails takeover testFirewall HA pair syncs config but not session stateFirewall rules present but traffic still blockedFirewalls & Routing alerts indicate success while end-user experience never changesFirewalls & Routing configuration survives testing but resets after restart or syncFirewalls & Routing connector health looks normal but data stops syncingFirewalls & Routing credential or certificate rotation breaks an existing integrationFirewalls & Routing feature works in web app but fails in desktop clientFirewalls & Routing healthy dashboard status masks a failing production workflowFirewalls & Routing logging shows delivery yet the target workflow never completesFirewalls & Routing new deployment works for pilot group but not for production rolloutFirewalls & Routing policy change applies in admin console but target users never receive itFirewalls & Routing quarantine or protection action triggers but recovery workflow failsFirewalls & Routing workflow succeeds for one account but fails for shared or delegated accessGeo block enabled but approved vendor traffic also blockedGuest VLAN clients receive lease but no DNS serversGuest Wi-Fi portal loads slowly only on Apple devicesHome user VPN drops every hour on the dotInter-VLAN routing works for ping but not for HTTPS sessionsInternal DNS record resolves correctly on servers but not on Wi-Fi clientsInternal DNS zone replicates but one domain controller serves stale recordsInternal website resolves to old server for one subnet onlyL2TP or SSTP VPN broken after ISP modem swapLoop detected warnings after moving conference room switchManaged switch port flaps when docking station connects multiple monitorsNew ISP circuit installed but outbound policy still uses old WANNew switch stack forms but VLAN tagging is inconsistentOffice guest Wi-Fi captive portal loops foreverOutbound SMTP relay blocked because egress policy matches wrong object groupPoE switch powers phones but access points reboot under peak loadPort forward works externally but internal hairpin access failsPrinters renew DHCP but keep old DNS hostnamePTR records missing and backup software fails verification

Wi-Fi & Switching healthy dashboard status masks a failing production workflow

Field Summary

Wi-Fi & Switching healthy dashboard status masks a failing production workflow is a Wi-Fi & Switching ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Wi-Fi & Switching policy change applies in admin console but target users never receive it

Field Summary

Wi-Fi & Switching policy change applies in admin console but target users never receive it is a Wi-Fi & Switching ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Outbound SMTP relay blocked because egress policy matches wrong object group

Field Summary

Outbound SMTP relay blocked because egress policy matches wrong object group is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Route-based tunnel carries traffic one way only after ISP failover

Field Summary

Route-based tunnel carries traffic one way only after ISP failover is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Firewall HA pair stays synchronized but secondary fails takeover test

Field Summary

Firewall HA pair stays synchronized but secondary fails takeover test is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Web filter category update blocks line-of-business app download endpoint

Field Summary

Web filter category update blocks line-of-business app download endpoint is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Inter-VLAN routing works for ping but not for HTTPS sessions

Field Summary

Inter-VLAN routing works for ping but not for HTTPS sessions is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Edge firewall firmware upgrade resets one custom application rule

Field Summary

Edge firewall firmware upgrade resets one custom application rule is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Static NAT entry published correctly yet source IP logging shows proxy address

Field Summary

Static NAT entry published correctly yet source IP logging shows proxy address is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.

Port forward works externally but internal hairpin access fails

Field Summary

Port forward works externally but internal hairpin access fails is a Firewalls & Routing ticket where the visible symptom can be misleading. Network tickets should be split into link, IP assignment, DNS, route, VLAN/firewall policy, and application reachability. Green status on one layer does not prove the path works. The fastest path is to identify which layer changed and prove it with logs or a repeatable test.