Diagnostics and troubleshooting
Troubleshooting is safest when it starts with an expected path and observable evidence. Record the interface, source, destination, protocol, time, and change that preceded the problem before changing configuration.
Network Diagnostics package
Section titled “Network Diagnostics package”The supported Network Diagnostics package consolidates allow-listed MTR, Nmap top-port, iperf3 client, and ARP tools. It validates targets, ports, and interfaces rather than accepting arbitrary shell input. Use it to test a specific hypothesis, not as a replacement for broad scanning policy.
A useful sequence
Section titled “A useful sequence”- Check link state, interface address, gateway status, and time.
- Inspect the relevant firewall, service, or package logs.
- Confirm DNS resolution independently from reachability.
- Test the route and path with bounded diagnostics.
- Make one reversible change and repeat the observation.
Recovery
Section titled “Recovery”Keep console access for interface, firewall, and routing changes. Export the configuration before maintenance. If an incident involves a package, capture its service state and logs before restarting it; restart can erase the most useful evidence.