[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"cheat-sheet---en":3,"domain-info---en":3,"topic-info----en":3,"lesson-aws-certified-cloudops-engineer-associate-networking-content-delivery-network-troubleshooting-troubleshooting-cloudfront-issues-en":4,"next-aws-certified-cloudops-engineer-associate-networking-content-delivery-network-troubleshooting-troubleshooting-cloudfront-issues-en":19,"prev-aws-certified-cloudops-engineer-associate-networking-content-delivery-network-troubleshooting-troubleshooting-cloudfront-issues-en":31},null,{"locked":5,"reason":6,"meta":7,"item":3},true,"paywall",{"title":8,"description":9,"isFree":10,"estimatedMinutes":11,"difficulty":12,"learningObjectives":13},"Troubleshooting CloudFront Issues","A CloudFront error can come from the viewer, the edge, or your origin, and the status code alone will not tell you which. This lesson teaches you to read the response headers and log fields that do, and to fix a collapsing cache hit ratio.",false,28,"intermediate",[14,15,16,17,18],"Determine whether a CloudFront response was generated by the edge or by the origin using response headers and log fields","Interpret x-edge-result-type, x-edge-response-result-type, and x-edge-detailed-result-type together","Diagnose a low cache hit ratio by finding the cache key dimension that is fragmenting the cache","Work through the common causes of CloudFront 403, 502, and 504 responses in the order that resolves them fastest","Choose between raising cache TTLs, adding Origin Shield, and invalidating, based on what the evidence shows",{"locked":5,"reason":6,"meta":20,"item":3},{"title":21,"description":22,"isFree":10,"estimatedMinutes":23,"difficulty":24,"learningObjectives":25},"Troubleshooting Hybrid and Private Connectivity","A VPN tunnel that will not come up, a Direct Connect BGP session stuck in Active, an endpoint that resolves to the wrong address. This lesson gives you a bottom-up diagnostic order for hybrid links and the private connectivity failures that look like them.",30,"advanced",[26,27,28,29,30],"Diagnose a hybrid link from the bottom layer up instead of starting at the routing layer","Separate a Site-to-Site VPN Phase 1 failure from a Phase 2 failure from a BGP failure using tunnel state and VPN logs","Work a Direct Connect problem through layer 1, layer 2, and layer 3 in order, using the CloudWatch metric for each","Identify the routing-layer failures that leave a healthy link carrying no traffic, including missing route propagation and prefix limits","Recognize the private connectivity failures caused by DNS, endpoint policies, and the absence of transitive routing",{"locked":5,"reason":6,"meta":32,"item":3},{"title":33,"description":34,"isFree":10,"estimatedMinutes":23,"difficulty":12,"learningObjectives":35},"Analyzing Network Logs","VPC Flow Logs, ELB access logs, CloudFront logs, WAF logs, and Resolver query logs each watch a different hop of the same request. This lesson teaches you to read each one and to pick the right one before you start querying.",[36,37,38,39,40,41],"Match a failing hop to the log source that can actually see it","Read a VPC flow log record field by field, including the version 3 to 5 fields worth adding to a custom format","Separate a security group denial from a network ACL denial using the ACCEPT and REJECT pattern in flow logs","Explain what VPC Flow Logs never capture and why a missing record is not evidence of missing traffic","Interpret the three ALB latency fields and the -1 values that replace them when a request fails","Query flow logs with CloudWatch Logs Insights and Athena to find rejected traffic and top talkers"]