Memory hook: Name, route, policy, session, application.
Must remember
- Start with source, destination, protocol, port, time and expected path. Resolve DNS, inspect routes and return routes, then evaluate firewall policy and service/backend health.
- VPC Flow Logs provide sampled/aggregated flow visibility; firewall logs explain logged rule decisions; NAT, DNS, VPN, Router and load-balancer logs reveal different layers. Absence in a sampled log is not proof no packet existed.
- Connectivity Tests analyzes supported configuration paths and can provide supported live data-plane verification; it is not a universal packet capture. Network Analyzer finds configuration issues; Firewall Insights highlights rule behavior.
- Network Topology visualizes connections/traffic; Performance Dashboard shows latency/loss; Flow Analyzer explores flow records. Use the tool that answers the specific hypothesis.
- For hybrid incidents, separate physical/link state, tunnel state, BGP session state, advertised prefixes, MTU and application health. For load balancers, inspect frontend, URL map, backend health and draining separately.
- Monitor baseline latency, loss, throughput, NAT ports, tunnel availability and errors. Capture packets only with authorization and controlled retention because payloads can contain sensitive data.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| One subnet cannot reach a private service | Compare effective routes, policies, DNS and service-connection configuration. |
| Traffic fails only for large payloads | Investigate MTU and path-MTU discovery as well as application limits. |
Traps
- A successful ping does not prove TCP/HTTPS is permitted.
- Flow logs do not replace complete packet capture when exact payload evidence is required.
Active recall
1. What is the first useful incident description?
Exact endpoints, protocol/port, time, scope and expected behavior.
2. How find a missing return route?
Trace the destination-side route back to the original or translated source.
3. What does Firewall Insights help identify?
Firewall rule use and opportunities to investigate or improve policy.
4. Why compare multiple time series?
Correlated route changes, errors and latency can reveal the actual cause.
5. What should follow a network fix?
Validate the intended flow, unintended exposure and monitoring across both directions.