IntermediatePublished 2026-09-22
CCNA Break/Fix: Published Services Nobody Outside Can Open
Archive lab
Lab 8 of 13 in CCNA Break/Fix II: Read the Symptom · ← Previous · Next →
CCNA exam domain: IP Services
A DMZ server was rebuilt onto a new IP last week. Since then, outside users cannot open its three published services, while the server itself can browse out normally. Your job: work from the public address toward the inside, diagnose where the forwarding breaks, and republish all three services on the advertised public IP without disrupting outbound internet access.
Learning objectives
- Diagnose external reachability failures for hosted services published via static port translations
- Trace the flow from an outside client through the provider and edge to the inside host using NAT tables
- Isolate breakpoints between policy (published IP/ports), upstream routing, and inside-to-outside translation behavior
- Verify inbound service reachability from the outside and confirm outbound browsing still works after the repair
Troubleshooting focus
- Start from the public IP and test inbound TCP connectivity for each published port from the outside client. Observe connection success vs. refusal vs. timeout.
- Compare the public address on which services are advertised to what the edge translates to internally. Look for address/port reuse conflicts.
- Inspect NAT translations on the edge during your tests. Confirm that inbound flows create the expected entries pointing at the intended inside server.
- Check the upstream router for a path to the site's delegated public block toward the edge. Absence here causes timeouts before NAT can even see the traffic.
- Validate that outbound PAT remains functional so the server can browse out; avoid repairs that break established outbound behavior.
Topology
Subscribe to preview this lab's topology.
See plansGrade your work
How this lab is graded
- Build it your way. Where a lab lets you choose a value — a VLAN name, an interface description — grading checks that you configured it, not which name you picked. Names that another line has to reference, like an ACL applied with
access-class, are stated in the guide and do have to match. - Addresses, modes and protocol keywords are exact. An IP address, a subnet mask,
switchport mode trunk, an encapsulation — these carry the meaning of the lab, so they are graded as written in the guide. - Grading reads your saved configuration. Export the lab from CML after you have configured it, and make sure anything you set is in the
running-config— a change that only exists in a terminal session never reaches the grader. - You can submit as many times as you like. Your best score stands, and each attempt tells you which checks passed so you can work the gaps.
- Scored something you believe is correct? Use Report an issue on this page — that is exactly how the grading fixes in the changelog got found.
Create a free account to submit your lab for grading.
Create a free accountFound a problem with this lab?
Please sign in to report a problem — tying it to your attempts lets us reproduce and fix it faster.