Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2Network AssuranceMedium

A network technician is troubleshooting a client's inability to connect to a specific internal application server. The client reports that other network resources are accessible, but this particular application consistently times out. The technician suspects a firewall in the path might be blocking the connection. Which troubleshooting step should the technician perform first to confirm or deny the firewall as the cause?

  1. AExamine the firewall logs for dropped packets from the client's IP to the server's IP and port.
  2. BCheck the client's DNS settings.
  3. CRestart the application server service.
  4. DPing the application server's IP address from the client.
Show answer & explanation

Correct answer: A. Examine the firewall logs for dropped packets from the client's IP to the server's IP and port.

If a firewall is suspected, the most direct and efficient first step to confirm or deny this is to check the firewall's logs. Firewall logs explicitly record traffic that is permitted, denied, or dropped, providing immediate evidence if it is blocking the connection to the specific server and port.

Why the other options are wrong

  • B. DNS issues typically affect all name-based lookups, not just a single application server, and wouldn't directly point to a firewall block.
  • C. Restarting the application server service is a potential solution if the server itself is the problem, but it's premature before confirming if a network device (firewall) is interfering.
  • D. Pinging only checks ICMP reachability (Layer 3) and wouldn't confirm if a firewall is blocking the specific application port (e.g., TCP 80/443).

Troubleshooting Firewall Blocks

Troubleshooting firewall blocks involves systematically checking firewall configurations and logs to identify if traffic is being intentionally or unintentionally denied between source and destination.

  • Firewalls block traffic based on rules (source/destination IP, port, protocol).
  • Logs are the primary source of truth for identifying blocked traffic.
  • Common issues include incorrect rules, implicit deny, or stateful inspection failures.

Memory trick: Firewall First: Find the Logs, Fix the Flow.

More Network Assurance questions