Infrastructure Scenario Tests

We test Corax against real-world infrastructure failures across every vendor, platform, and scenario. Browse the results below.

21,502
Total Tests
100.0%
Pass Rate
21,502
Passed
0
Failed

WatchGuard Firebox BOVPN Tunnel Flap

PASS

A WatchGuard Firebox M590 experiences persistent BOVPN instability to 6 branch offices due to a phase 2 SA lifetime mismatch after a firmware upgrade, causing intermittent branch connectivity.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands27 correlated

HPE Aruba ClearPass Authentication Failure

PASS

The HPE Aruba ClearPass Policy Manager cluster primary node crashes, and the secondary node's database is out of sync, causing all 802.1X authentications to fail across the entire campus network.

NetworkPattern: MEMORY_EXHAUSTIONSeverity: CRITICALConfidence: 88%Remote Hands28 correlated

Juniper Mist Cloud Management Disconnect

PASS

All 85 Juniper Mist-managed APs lose connectivity to the Mist cloud dashboard after a rule change blocks the required outbound ports, leaving APs operational but unmanaged.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 75%Remote Hands22 correlated

Juniper MX Router BGP Session Flap

PASS

A Juniper MX480 border router experiences BGP session flapping with two upstream ISPs due to a line card memory error, causing route oscillation and intermittent internet connectivity for the entire organization.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 85%Remote Hands29 correlated

Juniper EX Switch Virtual Chassis Split

PASS

A Juniper EX4300 virtual chassis of 4 members splits into two partitions when a VCP cable is severed during cable management, causing half the access ports to lose their trunk uplinks.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 85%Remote Hands21 correlated

Juniper SRX Cluster Failover — Chassis Cluster Split

PASS

A Juniper SRX4600 chassis cluster experiences a split-brain condition when both fabric links fail simultaneously, causing both nodes to assume the primary role and creating duplicate gateways on the network.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands26 correlated

SonicWall SD-WAN Policy Routing Failure

PASS

The SonicWall TZ670 SD-WAN policy engine fails to detect WAN link degradation, continuing to route critical VoIP traffic over a congested ISP link instead of failing over to the backup MPLS circuit.

NetworkPattern: SDWAN_EVENTSeverity: CRITICALConfidence: 85%Remote Hands20 correlated

SonicWall CGNAT Port Exhaustion

PASS

The SonicWall NSsp 13700 running carrier-grade NAT exhausts its NAT translation table, preventing new outbound connections while existing sessions remain active.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands20 correlated

SonicWall DPI-SSL Inspection Engine Failure

PASS

The SonicWall NSA 2700 DPI-SSL engine crashes under load, causing all HTTPS traffic to be dropped instead of bypassed, resulting in complete internet outage for 300 users.

NetworkPattern: MEMORY_EXHAUSTIONSeverity: CRITICALConfidence: 92%Remote Hands18 correlated

SonicWall Content Filtering Blocking Business App

PASS

A SonicWall TZ670 content filter policy update blocks access to a critical cloud accounting application by miscategorizing it as gambling/gaming, affecting all finance department workflows.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands18 correlated

Palo Alto URL Filtering Database Corruption

PASS

The PA-3260 URL filtering database becomes corrupted during an update, causing all web traffic to be categorized as 'not-resolved' and bypassing URL filtering policies entirely.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands18 correlated

Palo Alto WildFire Sandbox Analysis Failure

PASS

The PA-5250 WildFire cloud connection fails, causing all unknown file verdicts to default to 'allow' per policy. Potentially malicious files bypass inspection for 3 hours before detection.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 85%Remote Hands21 correlated

Palo Alto Panorama Management Disconnect

PASS

Panorama loses connectivity to all 12 managed PA firewalls after a network change isolates the management VLAN. Firewalls continue forwarding but cannot receive policy updates or log to Panorama.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 85%Remote Hands27 correlated

Palo Alto Threat Prevention False Positive Blocking ERP

PASS

A Palo Alto threat prevention content update incorrectly classifies ERP traffic as a command-and-control callback pattern, blocking all employee access to the SAP ERP system.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands20 correlated

Palo Alto GlobalProtect VPN Gateway Failure

PASS

The Palo Alto PA-5250 GlobalProtect gateway stops accepting new VPN connections after a configuration push corrupts the portal agent configuration. 400 remote workers cannot connect.

NetworkPattern: CLIENT_ERRORSeverity: CRITICALConfidence: 85%Remote Hands20 correlated

Client Site ISP Failover Not Working

PASS

A managed client's secondary ISP failover fails to activate when the primary circuit goes down. The SD-WAN appliance detects the primary failure but the secondary circuit is disconnected due to an unpaid bill. The site is completely offline.

NetworkPattern: TIMEOUTSeverity: CRITICALConfidence: 95%Remote Hands16 correlated

Network TAP/SPAN Port Oversubscription

PASS

The network TAP aggregating traffic for the IDS/IPS and packet capture system becomes oversubscribed. The 10G TAP is receiving 14Gbps of traffic, causing 28% packet loss on the monitoring feed. The IDS misses attack signatures and the packet capture has gaps.

NetworkPattern: PERFORMANCE_DEGRADATIONSeverity: CRITICALConfidence: 85%Remote Hands6 correlated

QoS Misconfiguration — Voice Traffic Not Prioritized

PASS

A switch firmware upgrade resets QoS policies on 12 access switches, removing DSCP marking and priority queuing for voice traffic. VoIP call quality degrades severely during business hours when data traffic competes with voice.

NetworkPattern: VOIP_QUALITYSeverity: CRITICALConfidence: 85%Remote Hands13 correlated

802.1X MAB Failure — IoT Devices Locked Out

PASS

A RADIUS policy change breaks MAC Authentication Bypass (MAB) for IoT devices. Security cameras, badge readers, and building management sensors are all locked out of the network as they cannot perform 802.1X EAP authentication.

NetworkPattern: ACTIVE_DIRECTORYSeverity: CRITICALConfidence: 92%Remote Hands13 correlated

IPAM Exhaustion — No Addresses to Allocate

PASS

The IP Address Management system shows all subnets in the production VLAN are fully allocated. DHCP scopes have no available leases, and new devices cannot obtain IP addresses. Server provisioning and workstation deployment are both blocked.

NetworkPattern: DHCP_EXHAUSTIONSeverity: CRITICALConfidence: 90%Auto-Heal4 correlated
PreviousPage 2 of 5Next

Every scenario is tested against Corax's Neural Engine in a production environment with AI-powered root cause analysis.

Tests run continuously as new infrastructure patterns are added.