A DNS issue is most defensibly debugged by:
dnsScenario: You must choose UDP over TCP. What trade-off are you accepting?
transportNAT is operationally 'stateful' because:
natScenario: TLS fails for one site but HTTP works elsewhere. What is the first evidence to check?
tlsScenario: You can resolve DNS but cannot reach the IP. What layer is most implicated?
routingScenario: A TCP connection stalls under load. What is a defensible next check?
transportScenario: A change 'fixed' DNS for one person but not others. What is the most likely reason?
dnsScenario: You can connect from inside the network but not from outside. What is a primary suspect?
firewallsScenario: DNS and TCP work, but the site returns 502. What does that suggest?
httpScenario: TLS fails only for one hostname. What is the most likely cause?
tlsScenario: Users complain of slowness but there are no errors. What is the most defensible first measurement?
latencyScenario: Traffic works one way but not the return path. What is this often called?
routing