Troubleshooting Playbooks

Quick-reference guides for diagnosing and fixing common networking issues.

Playbooks List

  • VPN Up but No Traffic (ESP Counters Not Incrementing)
    When a tunnel is “up” but traffic doesn’t pass, validate selectors, routing, NAT exemption, and security policy.
    Symptoms

  • Firewall Policy Allows Ping but Blocks Application Traffic
    Troubleshoot cases where ICMP works but the application fails by validating ports, stateful inspection, and return traffic handling.
    Symptoms

  • Route-Map or Prefix-List Accidentally Filtering BGP Updates
    Quickly validate if BGP policy is filtering updates by checking received routes and policy attachments.
    Symptoms

  • Native VLAN Mismatch Causing Intermittent VLAN Issues
    Detect and correct native VLAN mismatches that cause untagged traffic leaks and intermittent connectivity.
    Symptoms

    • Native VLAN mismatch logs
    • Intermittent connectivity for voice/AP mgmt
      View Playbook
  • Ansible Verification: Confirm Network State After Change
    Use lightweight Ansible verification to confirm interface/VLAN/route state after a change and catch drift quickly.
    Symptoms

    • Change completed but behavior uncertain
    • Need quick compliance snapshot
      View Playbook
  • NTP Out of Sync Causing Auth/Telemetry Failures
    Fix time drift issues that break TLS, RADIUS, APIs, and logging by validating NTP reachability and source interfaces.
    Symptoms

  • Cisco Catalyst Port Security Violation (Err-Disable)
    Recover from port-security violations that err-disable a port by identifying the violation source and correcting the policy.
    Symptoms

  • Cisco Secure SD-WAN Data Plane Up but App Traffic Fails
    Troubleshoot when control connections are up but data-plane policies/route advertisements prevent application traffic from flowing.
    Symptoms

  • Cisco IOS-XE AP Joins WLC but SSIDs Not Broadcasting
    Diagnose cases where APs are joined but WLANs/SSIDs do not broadcast due to policy profile mapping or RF/radio disable states.
    Symptoms

  • Nexus VLAN Allowed List Mismatch on vPC Peer-Link
    Resolve VLAN propagation issues in Nexus vPC designs by validating peer-link VLAN allow-lists and consistency checks.
    Symptoms

    • VLAN works on one peer but not the other
    • vPC consistency warnings
      View Playbook
  • Interface Auto-Negotiation Mismatch Causing Link Flaps
    Diagnose link flaps caused by mismatched negotiation settings and physical-layer instability.
    Symptoms