Skip to content

Diagnostics and troubleshooting

Troubleshooting is safest when it starts with an expected path and observable evidence. Record the interface, source, destination, protocol, time, and change that preceded the problem before changing configuration.

The supported Network Diagnostics package consolidates allow-listed MTR, Nmap top-port, iperf3 client, and ARP tools. It validates targets, ports, and interfaces rather than accepting arbitrary shell input. Use it to test a specific hypothesis, not as a replacement for broad scanning policy.

  1. Check link state, interface address, gateway status, and time.
  2. Inspect the relevant firewall, service, or package logs.
  3. Confirm DNS resolution independently from reachability.
  4. Test the route and path with bounded diagnostics.
  5. Make one reversible change and repeat the observation.

Keep console access for interface, firewall, and routing changes. Export the configuration before maintenance. If an incident involves a package, capture its service state and logs before restarting it; restart can erase the most useful evidence.