# AWS241 Network Path Troubleshooting Workbook

This is a metadata-only, no-change investigation.

## Safety and scope

- Case ID:
- UTC investigation window:
- Source workload and owner:
- Source VPC/subnet/AZ:
- Destination name, protocol, and port:
- Account/Region references (redacted):
- No AWS or production change: Yes / No

## DNS evidence

| Question | Evidence/result |
|---|---|
| Resolver used by workload | |
| A and AAAA answers | |
| Public/private hosted zone and association | |
| Resolver rule/firewall decision | |
| TTL/cache state | |
| Expected versus actual endpoint | |

## Forward packet walk

| Hop/decision | Input destination | Selected route/rule | SG/NACL/policy | Output/source translation | Result |
|---|---|---|---|---|---|
| Application/resolver | | | | | |
| Source ENI/subnet | | | | | |
| NAT/endpoint/peer/TGW | | | | | |
| Inspection | | | | | |
| LB/listener/rule | | | | | |
| Target/process | | | | | |

## Return packet walk

| Hop/decision | Input destination | Selected route/rule | SG/NACL/policy | Translation/state | Result |
|---|---|---|---|---|---|
| Target/subnet | | | | | |
| LB/inspection/transit | | | | | |
| NAT/endpoint/peer/TGW | | | | | |
| Source subnet/ENI | | | | | |
| Application | | | | | |

## First failed decision

- First failed layer:
- Exact safe evidence:
- Why later symptoms are consequences:
- Unknown evidence still required:

## Controlled response

- Root cause:
- Smallest correction:
- Change owner/approval:
- Blast radius:
- Rollback trigger and action:
- Layer-specific retest:
- End-to-end acceptance:
- Alarm/log/policy/runbook prevention:

## Load-balancer worksheet

| Item | Expected | Observed |
|---|---|---|
| DNS name and scheme | | |
| Enabled subnets/AZs | | |
| Listener/protocol/port | | |
| Rule priority/conditions/action | | |
| Target group type/protocol/port | | |
| Target state/reason | | |
| Health protocol/port/path/matcher | | |
| LB and target SG path | | |
| Both subnet NACL directions | | |
| App bind address/log response | | |
| ELB versus target status code | | |

## Cost and no-change closeout

- NAT hours/bytes/AZ path owner:
- Endpoint hours/bytes/AZ count owner:
- Peering/TGW bytes/attachment owner:
- LB capacity/log owner:
- Route 53/Resolver owner:
- Current pricing checked on:
- Inventory before/after:
- Change events:
- Production changed: No

Write a concise incident handoff: impact, tuple, first failed decision, correction/rollback, and proof/prevention.
