Memory hook: Test name resolution, route, permission, listener and response as separate hypotheses.
Must remember
- Use Network Watcher connection troubleshooting, IP flow verification, effective routes/security rules and packet capture for supported scenarios. Connection Monitor measures paths over time. A configuration-analysis result is not the same as a successful business request.
- VNet flow logs provide supported traffic metadata; legacy NSG flow-log availability/retirement differs, so use current guidance when deploying new telemetry. Flow data does not contain every application payload; packet capture has additional permissions, privacy and volume implications.
- Check DNS from the affected client context, including private-zone links and forwarding. Compare actual destination IP with the intended endpoint. A successful public lookup can hide a missing private DNS configuration.
- Diagnose intermittent outbound failures using SNAT utilisation, connection churn, timeouts and destination distribution. Long-lived connection reuse and an explicit scalable egress design can help; opening every inbound port does not repair SNAT exhaustion.
- Large-packet failures suggest MTU/MSS or path-MTU discovery issues. Asymmetric routing can produce failures that look like random firewall drops. BGP changes and DNS caches can cause different clients to observe different transition times.
- Monitor probes, backend health, gateway/circuit metrics, firewall/WAF events and route changes. Use narrow diagnostic time ranges and known test flows. Automate changes through reviewed IaC with rollback and evaluate cross-zone, gateway, firewall and transfer charges against expected traffic.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Only some new outbound connections fail | Inspect SNAT capacity and connection patterns. |
| One subnet cannot reach an endpoint | Compare its effective routes, NSGs and DNS context. |
| Need historical path availability | Connection Monitor with suitable test targets. |
Traps
- No traffic logs may indicate missing collection rather than no traffic.
- An allow rule cannot repair a missing return path.
- Averages hide intermittent failure and tail latency.
Active recall
1. What does an effective-route view help distinguish?
Which routes are actually available to the interface after system, UDR and BGP interactions.
2. Why compare small and large packets?
To reveal MTU-related failures that basic connectivity tests can miss.
3. Why not immediately allow all traffic?
It removes protection without identifying whether the actual failure is routing, DNS, SNAT or the application.
4. What should a network change record include?
Expected paths, affected scopes, verification tests, observed result and rollback.
5. Which billing dimensions can centralisation increase?
Gateway/firewall processing, cross-zone movement and data transfer.