1"use strict";(globalThis.webpackChunkazurecertprep=globalThis.webpackChunkazurecertprep||[]).push([[547],{98742(e,n,t){t.r(n),t.d(n,{assets:()=>l,contentTitle:()=>c,default:()=>u,frontMatter:()=>a,metadata:()=>r,toc:()=>d});const r=JSON.parse('{"id":"az-104/networking/challenge-26","title":"Challenge 26: Network Watcher & Diagnostics","description":"60-75 minutes | Estimated cost 10-15%","source":"@site/docs/az-104/04-networking/challenge-26.md","sourceDirName":"az-104/04-networking","slug":"/az-104/networking/challenge-26","permalink":"/docs/az-104/networking/challenge-26","draft":false,"unlisted":false,"editUrl":"https://github.com/azurecertprep/azurecertprep.github.io/tree/main/docs/az-104/04-networking/challenge-26.md","tags":[],"version":"current","sidebarPosition":26,"frontMatter":{"sidebar_position":26,"title":"Challenge 26: Network Watcher & Diagnostics"},"sidebar":"az104Sidebar","previous":{"title":"Challenge 25: Private Endpoints & Service Endpoints","permalink":"/docs/az-104/networking/challenge-25"},"next":{"title":"Challenge 14: Azure Monitor & Alerts","permalink":"/docs/az-104/monitor/challenge-14"}}');var o=t(74848),s=t(28453),i=t(80892);const a={sidebar_position:26,title:"Challenge 26: Network Watcher & Diagnostics"},c="Challenge 26: Network watcher & diagnostics",l={},d=[{value:"Scenario",id:"scenario",level:2},{value:"Exam skills covered",id:"exam-skills-covered",level:2},{value:"Sysadmin \u2194 Azure reference",id:"sysadmin--azure-reference",level:2},{value:"Setup",id:"setup",level:2},{value:"Tasks",id:"tasks",level:2},{value:"Task 1: enable Network watcher",id:"task-1-enable-network-watcher",level:3},{value:"Task 2: IP flow verify",id:"task-2-ip-flow-verify",level:3},{value:"Task 3: next hop analysis",id:"task-3-next-hop-analysis",level:3},{value:"Task 4: packet capture",id:"task-4-packet-capture",level:3},{value:"Task 5: connection Monitor",id:"task-5-connection-monitor",level:3},{value:"Task 6: NSG flow logs",id:"task-6-nsg-flow-logs",level:3},{value:"Task 7: connection troubleshoot",id:"task-7-connection-troubleshoot",level:3},{value:"Task 8: topology view and effective security rules",id:"task-8-topology-view-and-effective-security-rules",level:3},{value:"Success criteria",id:"success-criteria",level:2},{value:"Break & fix",id:"break--fix",level:2},{value:"Scenario a: VM cannot reach internet",id:"scenario-a-vm-cannot-reach-internet",level:3},{value:"Scenario b: asymmetric routing causes drops",id:"scenario-b-asymmetric-routing-causes-drops",level:3},{value:"Scenario c: connection Monitor shows failures",id:"scenario-c-connection-monitor-shows-failures",level:3},{value:"Knowledge check",id:"knowledge-check",level:2},{value:"Cleanup",id:"cleanup",level:2},{value:"Learning resources",id:"learning-resources",level:2}];function h(e){const n={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,s.R)(),...e.components},{Details:t}=n;return t||function(e,n){throw new Error("Expected "+(n?"component":"object")+" `"+e+"` to be defined: you likely forgot to import, pass, or provide it.")}("Details",!0),(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(n.header,{children:(0,o.jsx)(n.h1,{id:"challenge-26-network-watcher--diagnostics",children:"Challenge 26: Network watcher & diagnostics"})}),"\n",(0,o.jsx)(n.admonition,{title:"Estimated Time and Cost",type:"info",children:(0,o.jsxs)(n.p,{children:[(0,o.jsx)(n.strong,{children:"60-75 minutes"})," | ",(0,o.jsx)(n.strong,{children:"Estimated cost"}),": ~$0.20 | ",(0,o.jsx)(n.strong,{children:"Exam Weight: 10-15%"})]})}),"\n",(0,o.jsx)(n.h2,{id:"scenario",children:"Scenario"}),"\n",(0,o.jsx)(n.p,{children:"Contoso Ltd. is troubleshooting connectivity issues between their Azure VMs and external services. The network team needs to use Azure diagnostic tools to identify why certain connections fail, verify NSG rules are correct, trace packet flows, and set up continuous monitoring. You must become proficient with Network Watcher's full toolkit."}),"\n",(0,o.jsx)(n.h2,{id:"exam-skills-covered",children:"Exam skills covered"}),"\n",(0,o.jsxs)(n.ul,{children:["\n",(0,o.jsx)(n.li,{children:"Enable and use Azure Network Watcher"}),"\n",(0,o.jsx)(n.li,{children:"Use IP Flow Verify to test NSG rules"}),"\n",(0,o.jsx)(n.li,{children:"Use Next Hop to diagnose routing"}),"\n",(0,o.jsx)(n.li,{children:"Configure and use Packet Capture"}),"\n",(0,o.jsx)(n.li,{children:"Configure Connection Monitor"}),"\n",(0,o.jsx)(n.li,{children:"Analyze NSG flow logs"}),"\n",(0,o.jsx)(n.li,{children:"Use Network Watcher topology view"}),"\n",(0,o.jsx)(n.li,{children:"Check effective security rules"}),"\n"]}),"\n",(0,o.jsx)(n.h2,{id:"sysadmin--azure-reference",children:"Sysadmin \u2194 Azure reference"}),"\n",(0,o.jsxs)(n.table,{children:[(0,o.jsx)(n.thead,{children:(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.th,{children:"On-Prem / Traditional"}),(0,o.jsx)(n.th,{children:"Azure Equivalent"})]})}),(0,o.jsxs)(n.tbody,{children:[(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"Wireshark / tcpdump"}),(0,o.jsx)(n.td,{children:"Network Watcher Packet Capture"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"traceroute / tracert"}),(0,o.jsx)(n.td,{children:"Next Hop analysis"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"iptables -L / netsh advfirewall show"}),(0,o.jsx)(n.td,{children:"IP Flow Verify / Effective Security Rules"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"Nagios / PRTG connectivity checks"}),(0,o.jsx)(n.td,{children:"Connection Monitor"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"NetFlow / sFlow logs"}),(0,o.jsx)(n.td,{children:"NSG Flow Logs"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"Network topology diagram (Visio)"}),(0,o.jsx)(n.td,{children:"Network Watcher Topology"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"ping / telnet to test ports"}),(0,o.jsx)(n.td,{children:"Connection Troubleshoot"})]})]})]}),"\n",(0,o.jsx)(n.h2,{id:"setup",children:"Setup"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# Variables\nRG="rg-az104-challenge26"\nLOCATION="eastus"\n\n# Create resource group\naz group create --name $RG --location $LOCATION\n\n# Create VNet with subnets\naz network vnet create \\\n --resource-group $RG \\\n --name vnet-diag \\\n --address-prefix 10.0.0.0/16 \\\n --subnet-name subnet-web \\\n --subnet-prefix 10.0.1.0/24\n\naz network vnet subnet create \\\n --resource-group $RG \\\n --vnet-name vnet-diag \\\n --name subnet-db \\\n --address-prefix 10.0.2.0/24\n\n# Create NSG with rules\naz network nsg create --resource-group $RG --name nsg-web\naz network nsg rule create \\\n --resource-group $RG \\\n --nsg-name nsg-web \\\n --name AllowHTTP \\\n --priority 100 \\\n --direction Inbound \\\n --source-address-prefixes "*" \\\n --destination-port-ranges 80 443 \\\n --protocol Tcp \\\n --access Allow\n\naz network nsg rule create \\\n --resource-group $RG \\\n --nsg-name nsg-web \\\n --name DenySSHFromInternet \\\n --priority 200 \\\n --direction Inbound \\\n --source-address-prefixes Internet \\\n --destination-port-ranges 22 \\\n --protocol Tcp \\\n --access Deny\n\n# Associate NSG with web subnet\naz network vnet subnet update \\\n --resource-group $RG \\\n --vnet-name vnet-diag \\\n --name subnet-web \\\n --network-security-group nsg-web\n\n# Create VMs for testing\naz vm create \\\n --resource-group $RG \\\n --name vm-web \\\n --image Ubuntu2204 \\\n --size Standard_B1s \\\n --vnet-name vnet-diag \\\n --subnet subnet-web \\\n --public-ip-address vm-web-pip \\\n --nsg "" \\\n --admin-username azureuser \\\n --generate-ssh-keys\n\naz vm create \\\n --resource-group $RG \\\n --name vm-db \\\n --image Ubuntu2204 \\\n --size Standard_B1s \\\n --vnet-name vnet-diag \\\n --subnet subnet-db \\\n --public-ip-address "" \\\n --nsg "" \\\n --admin-username azureuser \\\n --generate-ssh-keys\n'})}),"\n",(0,o.jsx)(n.h2,{id:"tasks",children:"Tasks"}),"\n",(0,o.jsx)(n.h3,{id:"task-1-enable-network-watcher",children:"Task 1: enable Network watcher"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:"# Network watcher is auto-enabled for most subscriptions\n# Verify it exists for your region\naz network watcher list -o table\n\n# If not enabled, create it\naz network watcher configure \\\n --resource-group NetworkWatcherRG \\\n --locations $LOCATION \\\n --enabled true\n\n# Verify\naz network watcher list \\\n --query \"[?location=='$LO
1CATION'] | [0].{Name:name, Location:location, State:provisioningState}\" -o table\n"})}),"\n",(0,o.jsx)(n.h3,{id:"task-2-ip-flow-verify",children:"Task 2: IP flow verify"}),"\n",(0,o.jsx)(n.p,{children:"Test whether traffic is allowed or denied by NSG rules:"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# Get VM resource IDs\nVM_WEB_ID=$(az vm show -g $RG -n vm-web --query "id" -o tsv)\nVM_WEB_NIC=$(az vm show -g $RG -n vm-web \\\n --query "networkProfile.networkInterfaces[0].id" -o tsv)\nVM_WEB_IP=$(az vm show -g $RG -n vm-web -d \\\n --query "privateIps" -o tsv)\n\n# Test: can internet reach port 80 on the web VM? (Should allow)\naz network watcher test-ip-flow \\\n --direction Inbound \\\n --protocol Tcp \\\n --local "$VM_WEB_IP:80" \\\n --remote "1.2.3.4:12345" \\\n --vm $VM_WEB_ID \\\n --nic $VM_WEB_NIC\n\n# Test: can internet reach port 22 on the web VM? (Should deny)\naz network watcher test-ip-flow \\\n --direction Inbound \\\n --protocol Tcp \\\n --local "$VM_WEB_IP:22" \\\n --remote "1.2.3.4:12345" \\\n --vm $VM_WEB_ID \\\n --nic $VM_WEB_NIC\n\n# Test: can the web VM reach the internet on port 443? (Should allow)\naz network watcher test-ip-flow \\\n --direction Outbound \\\n --protocol Tcp \\\n --local "$VM_WEB_IP:12345" \\\n --remote "8.8.8.8:443" \\\n --vm $VM_WEB_ID \\\n --nic $VM_WEB_NIC\n'})}),"\n",(0,o.jsx)(n.admonition,{title:"IP Flow Verify",type:"tip",children:(0,o.jsx)(n.p,{children:'IP Flow Verify tells you which NSG rule (name and priority) is allowing or denying traffic. It checks both the NIC-level NSG and subnet-level NSG. This is the fastest way to diagnose "why can\'t I connect?" issues.'})}),"\n",(0,o.jsx)(n.h3,{id:"task-3-next-hop-analysis",children:"Task 3: next hop analysis"}),"\n",(0,o.jsx)(n.p,{children:"Determine the next hop for traffic from a VM:"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# What is the next hop for traffic going to the internet?\naz network watcher show-next-hop \\\n --resource-group $RG \\\n --vm vm-web \\\n --source-ip $VM_WEB_IP \\\n --dest-ip 8.8.8.8\n\n# What is the next hop for traffic going to the DB VM?\nVM_DB_IP=$(az vm show -g $RG -n vm-db -d --query "privateIps" -o tsv)\naz network watcher show-next-hop \\\n --resource-group $RG \\\n --vm vm-web \\\n --source-ip $VM_WEB_IP \\\n --dest-ip $VM_DB_IP\n\n# What is the next hop for traffic to a non-existent address?\naz network watcher show-next-hop \\\n --resource-group $RG \\\n --vm vm-web \\\n --source-ip $VM_WEB_IP \\\n --dest-ip 192.168.1.1\n'})}),"\n",(0,o.jsx)(n.h3,{id:"task-4-packet-capture",children:"Task 4: packet capture"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# Create a storage account for packet captures\nCAPTURE_STORAGE="diagcapture$RANDOM"\naz storage account create \\\n --resource-group $RG \\\n --name $CAPTURE_STORAGE \\\n --sku Standard_LRS\n\n# Start a packet capture on the web VM\naz network watcher packet-capture create \\\n --resource-group $RG \\\n --vm vm-web \\\n --name capture-web-traffic \\\n --storage-account $CAPTURE_STORAGE \\\n --time-limit 60 \\\n --filters \'[{"protocol":"TCP","localPort":"80"}]\'\n\n# Check capture status\naz network watcher packet-capture show \\\n --location $LOCATION \\\n --name capture-web-traffic\n\n# Generate some traffic (from another terminal or using the vm)\naz vm run-command invoke \\\n --resource-group $RG \\\n --name vm-web \\\n --command-id RunShellScript \\\n --scripts "curl -s http://localhost > /dev/null; echo done"\n\n# Stop the capture\naz network watcher packet-capture stop \\\n --location $LOCATION \\\n --name capture-web-traffic\n\n# List all packet captures\naz network watcher packet-capture list --location $LOCATION -o table\n\n# Delete capture when done\naz network watcher packet-capture delete \\\n --location $LOCATION \\\n --name capture-web-traffic\n'})}),"\n",(0,o.jsx)(n.admonition,{title:"Packet Capture",type:"tip",children:(0,o.jsx)(n.p,{children:"Packet captures are stored as .cap files in the storage account. You can download and analyze them with Wireshark. The Network Watcher agent must be installed on the VM (automatically installed when you create a capture)."})}),"\n",(0,o.jsx)(n.h3,{id:"task-5-connection-monitor",children:"Task 5: connection Monitor"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# Create a connection Monitor to continuously test connectivity\naz network watcher connection-monitor create \\\n --name cm-web-to-internet \\\n --location $LOCATION \\\n --test-group-name tg-web-external \\\n --endpoint-source-name "vm-web" \\\n --endpoint-source-resource-id $VM_WEB_ID \\\n --endpoint-dest-name "google-dns" \\\n --endpoint-dest-address "8.8.8.8" \\\n --test-config-name "tcp-443" \\\n --protocol Tcp \\\n --tcp-port 443 \\\n --frequency 30\n\n# Create a second test for internal
1connectivity\nVM_DB_ID=$(az vm show -g $RG -n vm-db --query "id" -o tsv)\naz network watcher connection-monitor create \\\n --name cm-web-to-db \\\n --location $LOCATION \\\n --test-group-name tg-internal \\\n --endpoint-source-name "vm-web" \\\n --endpoint-source-resource-id $VM_WEB_ID \\\n --endpoint-dest-name "vm-db" \\\n --endpoint-dest-resource-id $VM_DB_ID \\\n --test-config-name "tcp-5432" \\\n --protocol Tcp \\\n --tcp-port 5432 \\\n --frequency 60\n\n# Check connection monitor status\naz network watcher connection-monitor list --location $LOCATION -o table\n\n# Show test results\naz network watcher connection-monitor show \\\n --location $LOCATION \\\n --name cm-web-to-internet\n'})}),"\n",(0,o.jsx)(n.h3,{id:"task-6-nsg-flow-logs",children:"Task 6: NSG flow logs"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# Create a Log Analytics workspace for flow logs\naz monitor log-analytics workspace create \\\n --resource-group $RG \\\n --workspace-name law-network-diag \\\n --location $LOCATION\n\nWORKSPACE_ID=$(az monitor log-analytics workspace show \\\n --resource-group $RG \\\n --workspace-name law-network-diag \\\n --query "id" -o tsv)\n\n# Create storage account for flow logs\nFLOW_STORAGE="flowlogs$RANDOM"\naz storage account create \\\n --resource-group $RG \\\n --name $FLOW_STORAGE \\\n --sku Standard_LRS\n\n# Get NSG resource ID\nNSG_ID=$(az network nsg show -g $RG -n nsg-web --query "id" -o tsv)\n\n# Enable NSG flow logs (version 2 for traffic analytics)\naz network watcher flow-log create \\\n --location $LOCATION \\\n --name flowlog-nsg-web \\\n --nsg $NSG_ID \\\n --storage-account $FLOW_STORAGE \\\n --workspace $WORKSPACE_ID \\\n --enabled true \\\n --format JSON \\\n --log-version 2 \\\n --retention 7 \\\n --traffic-analytics true \\\n --interval 10\n\n# Verify flow log configuration\naz network watcher flow-log show \\\n --location $LOCATION \\\n --name flowlog-nsg-web\n'})}),"\n",(0,o.jsx)(n.p,{children:(0,o.jsx)(n.strong,{children:"Portal Steps:"})}),"\n",(0,o.jsxs)(n.ol,{children:["\n",(0,o.jsxs)(n.li,{children:["Navigate to ",(0,o.jsx)(n.strong,{children:"Network Watcher"})," > ",(0,o.jsx)(n.strong,{children:"NSG flow logs"})]}),"\n",(0,o.jsx)(n.li,{children:"Select the NSG"}),"\n",(0,o.jsx)(n.li,{children:"Enable flow logs with Version 2"}),"\n",(0,o.jsx)(n.li,{children:"Configure storage account and retention"}),"\n",(0,o.jsx)(n.li,{children:"Enable Traffic Analytics with Log Analytics workspace"}),"\n",(0,o.jsx)(n.li,{children:"Set processing interval (10 minutes recommended)"}),"\n"]}),"\n",(0,o.jsx)(n.h3,{id:"task-7-connection-troubleshoot",children:"Task 7: connection troubleshoot"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:"# One-time connectivity check from VM to destination\naz network watcher test-connectivity \\\n --resource-group $RG \\\n --source-resource vm-web \\\n --dest-address 8.8.8.8 \\\n --dest-port 443 \\\n --protocol Tcp\n\n# Test connectivity to the DB VM on port 5432\naz network watcher test-connectivity \\\n --resource-group $RG \\\n --source-resource vm-web \\\n --dest-resource vm-db \\\n --dest-port 5432 \\\n --protocol Tcp\n\n# Test connectivity to a service that should be blocked\naz network watcher test-connectivity \\\n --resource-group $RG \\\n --source-resource vm-web \\\n --dest-address 10.99.99.99 \\\n --dest-port 80 \\\n --protocol Tcp\n"})}),"\n",(0,o.jsx)(n.h3,{id:"task-8-topology-view-and-effective-security-rules",children:"Task 8: topology view and effective security rules"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:"# Generate network topology\naz network watcher show-topology \\\n --resource-group $RG\n\n# View effective security rules for the web VM NIC\nWEB_NIC_NAME=$(basename $VM_WEB_NIC)\naz network nic list-effective-nsg \\\n --resource-group $RG \\\n --name $WEB_NIC_NAME -o table\n"})}),"\n",(0,o.jsx)(n.p,{children:(0,o.jsx)(n.strong,{children:"Portal Steps for Topology:"})}),"\n",(0,o.jsxs)(n.ol,{children:["\n",(0,o.jsxs)(n.li,{children:["Navigate to ",(0,o.jsx)(n.strong,{children:"Network Watcher"})," > ",(0,o.jsx)(n.strong,{children:"Topology"})]}),"\n",(0,o.jsx)(n.li,{children:"Select your subscription and resource group"}),"\n",(0,o.jsx)(n.li,{children:"View the interactive diagram showing VNets, subnets, NICs, and VMs"}),"\n",(0,o.jsx)(n.li,{children:"Observe the relationships between network resources"}),"\n"]}),"\n",(0,o.jsx)(n.p,{children:(0,o.jsx)(n.strong,{children:"Portal Steps for Effective Security Rules:"})}),"\n",(0,o.jsxs)(n.ol,{children:["\n",(0,o.jsxs)(n.li,{children:["Navigate to ",(0,o.jsx)(n.strong,{children:"Network Watcher"})," > ",(0,o.jsx)(n.strong,{children:"Effective security rules"})]}),"\n",(0,o.jsx)(n.li,{children:"Select the VM or NIC"}),"\n",(0,o.jsx)(n.li,{children:"View the combined list of all applicable NSG rules (NIC + subnet level)"}),"\n",(0,o.jsx)(n.li,{children:"Identify which rule is allowing or blocking traffic"}),"\n"]}),"\n",(0,o.jsx)(n.h2,{id:"success-criteria",children:"Success criteria"}),"\n",(0,o.jsx)(i.A,{storageKey:"az104-challenge-26",items:["Network Watcher enabled in the target region","IP Flow Verify used to test allowed/denied traffic (port 80 allowed, port 22 denied)","Next Hop analysis performed for internet, internal, and unreachable destinations","Packet capture created, traffic captured, and capture stopped","Connection Monitor configured for external and internal
1connectivity tests","NSG flow logs enabled with Traffic Analytics","Connection Troubleshoot used to verify connectivity","Topology view examined","Effective security rules reviewed for combined NIC + subnet NSG impact"]}),"\n",(0,o.jsx)(n.h2,{id:"break--fix",children:"Break & fix"}),"\n",(0,o.jsx)(n.h3,{id:"scenario-a-vm-cannot-reach-internet",children:"Scenario a: VM cannot reach internet"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# Add a deny-all outbound rule to the NSG\naz network nsg rule create \\\n --resource-group $RG \\\n --nsg-name nsg-web \\\n --name BlockOutbound \\\n --priority 100 \\\n --direction Outbound \\\n --source-address-prefixes "*" \\\n --destination-address-prefixes "*" \\\n --destination-port-ranges "*" \\\n --protocol "*" \\\n --access Deny\n\n# Diagnose with IP flow verify\naz network watcher test-ip-flow \\\n --direction Outbound \\\n --protocol Tcp \\\n --local "$VM_WEB_IP:12345" \\\n --remote "8.8.8.8:443" \\\n --vm $VM_WEB_ID \\\n --nic $VM_WEB_NIC\n\n# Output will show: "Access: deny, rule: BlockOutbound"\n\n# Fix: remove the blocking rule\naz network nsg rule delete \\\n --resource-group $RG \\\n --nsg-name nsg-web \\\n --name BlockOutbound\n'})}),"\n",(0,o.jsx)(n.h3,{id:"scenario-b-asymmetric-routing-causes-drops",children:"Scenario b: asymmetric routing causes drops"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# Add a UDR that routes response traffic differently than request traffic\n# This causes asymmetric routing (responses take different path than requests)\n# Diagnose with next hop to see unexpected routing\naz network watcher show-next-hop \\\n --resource-group $RG \\\n --vm vm-web \\\n --source-ip $VM_WEB_IP \\\n --dest-ip 1.2.3.4\n\n# If next hop shows "VirtualAppliance" but no NVA exists, traffic is black-holed\n'})}),"\n",(0,o.jsx)(n.h3,{id:"scenario-c-connection-monitor-shows-failures",children:"Scenario c: connection Monitor shows failures"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:"# Check connection Monitor for failures\naz network watcher connection-monitor show \\\n --location $LOCATION \\\n --name cm-web-to-db\n\n# Common causes:\n# 1. no service listening on destination port\n# 2. NSG blocking the port\n# 3. OS-level firewall (iptables/ufw) blocking\n# Diagnose: use IP flow verify + connection troubleshoot\n"})}),"\n",(0,o.jsx)(n.h2,{id:"knowledge-check",children:"Knowledge check"}),"\n",(0,o.jsx)(n.p,{children:(0,o.jsx)(n.strong,{children:"1. What is the difference between Connection Monitor and Connection Troubleshoot?"})}),"\n",(0,o.jsxs)(t,{children:[(0,o.jsx)("summary",{children:"Show Answer"}),(0,o.jsxs)(n.table,{children:[(0,o.jsx)(n.thead,{children:(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.th,{children:"Feature"}),(0,o.jsx)(n.th,{children:"Connection Monitor"}),(0,o.jsx)(n.th,{children:"Connection Troubleshoot"})]})}),(0,o.jsxs)(n.tbody,{children:[(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"Type"}),(0,o.jsx)(n.td,{children:"Continuous monitoring"}),(0,o.jsx)(n.td,{children:"One-time test"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"Duration"}),(0,o.jsx)(n.td,{children:"Runs indefinitely (scheduled)"}),(0,o.jsx)(n.td,{children:"Single check"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"Alerting"}),(0,o.jsx)(n.td,{children:"Yes (integrates with Azure Monitor)"}),(0,o.jsx)(n.td,{children:"No"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"History"}),(0,o.jsx)(n.td,{children:"Maintains historical data"}),(0,o.jsx)(n.td,{children:"Point-in-time result"})]}),(0,o.jsxs)(n.tr,{children:[(0,o.jsx)(n.td,{children:"Use case"}),(0,o.jsx)(n.td,{children:"Ongoing health monitoring"}),(0,o.jsx)(n.td,{children:"Ad-hoc debugging"})]})]})]})]}),"\n",(0,o.jsx)(n.p,{children:(0,o.jsx)(n.strong,{children:"2. What information does IP Flow Verify provide?"})}),"\n",(0,o.jsxs)(t,{children:[(0,o.jsx)("summary",{children:"Show Answer"}),(0,o.jsx)(n.p,{children:"IP Flow Verify returns:"}),(0,o.jsxs)(n.ul,{children:["\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.strong,{children:"Access"}),": Allow or Deny"]}),"\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.strong,{children:"Rule Name"}),": The specific NSG rule causing the allow/deny"]}),"\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.strong,{children:"NSG ID"}),": Which NSG (NIC-level or subnet-level) contains the matching rule"]}),"\n"]}),(0,o.jsx)(n.p,{children:"It evaluates both NIC-level and subnet-level NSGs and returns the first matching rule. This is the fastest way to diagnose NSG-related connectivity issues."})]}),"\n",(0,o.jsx)(n.p,{children:(0,o.jsx)(n.strong,{children:"3. What are the requirements for packet capture?"})}),"\n",(0,o.jsxs)(t,{children:[(0,o.jsx)("summary",{children:"Show Answer"}),(0,o.jsxs)(n.ul,{children:["\n",(0,o.jsx)(n.li,{children:"Network Watcher agent VM extension must be installed (auto-installed on first capture)"}),"\n",(0,o.jsx)(n.li,{children:"VM must be in a Running state"}),"\n",(0,o.jsx)(n.li,{children:"Storage account in the same region (for storing .cap files)"}),"\n",(0,o.jsx)(n.li,{children:"Maximum capture size and time limits can be configured"}),"\n",(0,o.jsx)(n.li,{children:"Filters can be applied (protocol, local/remote IP, port)"}),"\n",(0,o.jsx)(n.li,{children:"Output can go to storage account, local file on VM, or both"}),"\n"]})]}),"\n",(0,o.jsx)(n.p,{children:(0,o.jsx)(n.strong,{children:"4. What does NSG Flow Log version 2 add over version 1?"})}),"\n",(0,o.jsxs)(t,{children:[(0,o.jsx)("summary",{children:"Show Answer"}),(0,o.jsx)(n.p,{children:"Version 2 adds:"}),(0,o.jsxs)(n.ul,{children:["\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.strong,{children:"Bytes sent/received"})," per flow (bandwidth tracking)"]}),"\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.strong,{children:"Flow
1state"})," information (Begin, Continuing, End)"]}),"\n",(0,o.jsxs)(n.li,{children:[(0,o.jsx)(n.strong,{children:"Traffic Analytics"})," support (requires Log Analytics workspace)"]}),"\n"]}),(0,o.jsx)(n.p,{children:"Version 1 only logs: timestamp, source/dest IP, source/dest port, protocol, traffic direction (inbound/outbound), and allow/deny."})]}),"\n",(0,o.jsx)(n.h2,{id:"cleanup",children:"Cleanup"}),"\n",(0,o.jsx)(n.pre,{children:(0,o.jsx)(n.code,{className:"language-bash",children:'# Delete connection monitors first\naz network watcher connection-monitor delete \\\n --location $LOCATION --name cm-web-to-internet 2>/dev/null\naz network watcher connection-monitor delete \\\n --location $LOCATION --name cm-web-to-db 2>/dev/null\n\n# Delete flow logs\naz network watcher flow-log delete \\\n --location $LOCATION --name flowlog-nsg-web 2>/dev/null\n\n# Delete all resources\naz group delete --name $RG --yes --no-wait\n\necho "Resources are being deleted in the background."\n'})}),"\n",(0,o.jsx)(n.h2,{id:"learning-resources",children:"Learning resources"}),"\n",(0,o.jsxs)(n.ul,{children:["\n",(0,o.jsx)(n.li,{children:(0,o.jsx)(n.a,{href:"https://learn.microsoft.com/azure/network-watcher/network-watcher-monitoring-overview",children:"Azure Network Watcher overview"})}),"\n",(0,o.jsx)(n.li,{children:(0,o.jsx)(n.a,{href:"https://learn.microsoft.com/azure/network-watcher/network-watcher-ip-flow-verify-overview",children:"IP Flow Verify"})}),"\n",(0,o.jsx)(n.li,{children:(0,o.jsx)(n.a,{href:"https://learn.microsoft.com/azure/network-watcher/network-watcher-next-hop-overview",children:"Next Hop"})}),"\n",(0,o.jsx)(n.li,{children:(0,o.jsx)(n.a,{href:"https://learn.microsoft.com/azure/network-watcher/network-watcher-packet-capture-overview",children:"Packet Capture"})}),"\n",(0,o.jsx)(n.li,{children:(0,o.jsx)(n.a,{href:"https://learn.microsoft.com/azure/network-watcher/connection-monitor-overview",children:"Connection Monitor"})}),"\n",(0,o.jsx)(n.li,{children:(0,o.jsx)(n.a,{href:"https://learn.microsoft.com/azure/network-watcher/nsg-flow-logs-overview",children:"NSG Flow Logs"})}),"\n",(0,o.jsx)(n.li,{children:(0,o.jsx)(n.a,{href:"https://learn.microsoft.com/azure/network-watcher/traffic-analytics",children:"Traffic Analytics"})}),"\n"]})]})}function u(e={}){const{wrapper:n}={...(0,s.R)(),...e.components};return n?(0,o.jsx)(n,{...e,children:(0,o.jsx)(h,{...e})}):h(e)}},80892(e,n,t){t.d(n,{A:()=>i});var r=t(96540),o=t(74848);function s({text:e,checked:n,onToggle:t}){return(0,o.jsxs)("li",{onClick:t,style:{display:"flex",alignItems:"flex-start",gap:"0.6rem",padding:"0.5rem 0",cursor:"pointer",userSelect:"none",listStyle:"none"},children:[(0,o.jsx)("span",{style:{fontSize:"1.2rem",lineHeight:"1.4",flexShrink:0},children:n?"\u2705":"\u2b1c"}),(0,o.jsx)("span",{style:{lineHeight:"1.5",textDecoration:n?"line-through":"none",opacity:n?.7:1},children:e})]})}function i({items:e,storageKey:n}){const[t,i]=(0,r.useState)({});(0,r.useEffect)(()=>{try{const e=localStorage.getItem(`success-${n}`);e&&i(JSON.parse(e))}catch{}},[n]);const a=e.length,c=Object.values(t).filter(Boolean).length;return(0,o.jsxs)("div",{children:[c>0&&(0,o.jsxs)("div",{style:{fontSize:"0.85rem",marginBottom:"0.5rem",color:c===a?"#27ae60":"var(--ifm-color-emphasis-600)",fontWeight:c===a?600:400},children:[c,"/",a," completed ",c===a&&"- All done!"]}),(0,o.jsx)("ul",{style:{margin:0,padding:0},children:e.map((e,r)=>(0,o.jsx)(s,{text:e,checked:!!t[r],onToggle:()=>(e=>{const r={...t,[e]:!t[e]};i(r);try{localStorage.setItem(`success-${n}`,JSON.stringify(r))}catch{}})(r)},r))}),c>0&&(0,o.jsx)("button",{onClick:()=>{i({});try{localStorage.removeItem(`success-${n}`)}catch{}},style:{marginTop:"0.5rem",padding:"0.3rem 0.8rem",fontSize:"0.8rem",cursor:"pointer",borderRadius:"4px",border:"1px solid #ccc",background:"transparent"},children:"Reset"})]})}},28453(e,n,t){t.d(n,{R:()=>i,x:()=>a});var r=t(96540);const o={},s=r.createContext(o);function i(e){const n=r.useContext(s);return r.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function a(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:i(e.components),r.createElement(s.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.