# AWS241 Supplied Packet Paths

All names, addresses, and IDs are fictional documentation data. Diagnose only.

## Path 1: private subnet cannot reach package repository

- Source `10.0.11.24` in private subnet A resolves the repository correctly.
- Private route table: `0.0.0.0/0 -> nat-A`.
- `nat-A` is available in public subnet A with EIP.
- Public subnet A route table has only `10.0.0.0/16 -> local`; no internet-gateway default.
- Source SG permits TCP 443 outbound; both NACLs permit forward and ephemeral return traffic.
- NAT `ConnectionAttemptCount` rises; `ConnectionEstablishedCount` does not.

Find the first failed routing decision. Explain both route tables and the resilience design.

## Path 2: S3 gateway endpoint bypassed

- Workload subnet route table is `rtb-app`.
- S3 gateway endpoint is available but associated only with `rtb-batch`.
- `rtb-app` sends `0.0.0.0/0` to a NAT gateway.
- Flow logs show S3-bound traffic using the NAT path.
- Endpoint policy would allow the bucket; bucket policy allows the workload role.

Explain why endpoint health/policy is not the first failure and how to prove effective routing after an approved association.

## Path 3: transitive peering assumption

- VPC A peers actively with B; A also peers actively with C.
- All CIDRs are non-overlapping.
- B routes A CIDR to B-A peering. C routes A CIDR to C-A peering.
- An engineer expects B to connect to C through A.
- No B-C peering or Transit Gateway exists.

Identify the unsupported architecture. Compare direct peering, TGW, and PrivateLink service exposure.

## Path 4: asymmetric stateful inspection

- Spoke A and B attach to a Transit Gateway.
- Traffic must cross a two-AZ firewall fleet in an inspection VPC.
- Forward flow reaches firewall AZ-a.
- Return flow reaches firewall AZ-b and is dropped because no session exists.
- Inspection VPC attachment has appliance mode disabled.
- VPC and TGW route destinations otherwise match.

Explain association/propagation versus the actual failure, appliance mode, HA effects, and symmetric retest evidence.

## Path 5: ALB target is unhealthy

- Public DNS resolves to the intended internet-facing ALB.
- HTTPS listener and rule forward to `orders-tg`.
- Target is registered and app listens on port 8080.
- Health check: HTTP port 8080 path `/health`, matcher 200.
- Target status: `unhealthy`, reason `Target.ResponseCodeMismatch`, observed 404.
- App log shows health request `Host: 10.0.21.8:8080`; virtual host handles only `orders.example.invalid`.

Identify what the reason code proves. Propose a safe readiness endpoint/default-host correction instead of widening the matcher to every status.

## Path 6: private DNS selects the wrong endpoint

- Hybrid client should reach an interface endpoint through Route 53 Resolver.
- In its VPC, the normal AWS service hostname resolves to endpoint private IPs and works.
- On-premises resolver forwards the service domain to an obsolete outbound path and receives public IPs.
- Direct Connect route has no internet/NAT egress.
- Interface endpoint SG already permits the on-premises CIDR.

Separate DNS selection from SG and route symptoms. Define the inbound Resolver/rule path and same-client verification.

## Cross-case review

1. State each five-tuple and first failed decision.
2. Draw every forward and return route table.
3. Name evidence that is relevant but not causal.
4. Identify the smallest approved correction and rollback.
5. Add one preventive control and one cost owner per path.
