Infrastructure Scenario Tests

We test Corax against real-world infrastructure failures across every vendor, platform, and scenario. Browse the results below.

21,502
Total Tests
100.0%
Pass Rate
21,502
Passed
0
Failed

NTP Stratum Drift — Multiple Servers Affected

PASS

The primary NTP server loses its upstream time source and begins drifting. As a stratum 1 source for the internal network, all downstream servers inherit the drift. Kerberos authentication begins failing when clock skew exceeds 5 minutes.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands6 correlated

TFTP Server Unreachable — Switch Config Backup Failing

PASS

The TFTP server used for automated network device configuration backups becomes unreachable after a server migration. Nightly configuration backups for 80 network devices have not run for 7 days, leaving no recent configuration recovery point.

NetworkPattern: CONNECTION_REFUSEDSeverity: CRITICALConfidence: 85%Auto-Heal4 correlated

Syslog UDP Overflow — Log Data Loss

PASS

The centralized syslog server cannot keep up with the volume of incoming UDP syslog messages during a network event. UDP packets are dropped at the kernel level, causing critical security and audit log data to be permanently lost.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 85%Auto-Heal6 correlated

RADIUS Accounting Failure — Billing Data Loss

PASS

The RADIUS accounting server becomes unresponsive, causing all network access devices to fail sending accounting records. ISP billing data is lost for 8 hours, and compliance logging for network access events stops.

NetworkPattern: SNMP_TRAP_ERRORSeverity: CRITICALConfidence: 85%Auto-Heal8 correlated

Network Segmentation Bypass — Unauthorized Cross-VLAN Traffic

PASS

A misconfigured ACL on the layer 3 switch allows traffic from the guest VLAN to reach the server VLAN, bypassing network segmentation. The IDS detects lateral scanning from a compromised guest device targeting internal servers.

NetworkPattern: FIREWALL_RULE_BLOCKSeverity: CRITICALConfidence: 85%Auto-Heal42 correlated

RADIUS Authentication Server Down — Network Access Blocked

PASS

Both RADIUS servers (backed by Active Directory) become unreachable after an AD domain controller crash. All 802.1X network authentication fails, preventing users from connecting to wired and wireless networks. Existing sessions remain active but no new authentications succeed.

NetworkPattern: ACTIVE_DIRECTORYSeverity: CRITICALConfidence: 92%Remote Hands42 correlated

DNS Zone Transfer Failure — Secondary DNS Serving Stale Records

PASS

The primary DNS server's zone transfer (AXFR) to the secondary fails due to a firewall rule change blocking TCP port 53. The secondary DNS server continues serving increasingly stale records, causing intermittent name resolution failures as TTLs expire.

NetworkPattern: DNS_FAILURESeverity: CRITICALConfidence: 90%Remote Hands42 correlated

Core Switch Power Supply Failure — Stack Degradation

PASS

The primary power supply in the core switch stack fails, causing the switch to reboot onto the secondary PSU. During the reboot, the switch stack ring breaks and a stack master re-election occurs, disrupting all traffic through the core for 90 seconds.

NetworkPattern: SWITCH_STACK_EVENTSeverity: CRITICALConfidence: 92%Remote Hands36 correlated

Network Monitoring Tool Failure — Nagios/PRTG Crash Loop

PASS

The primary network monitoring platform enters a crash loop after a database corruption event during a power fluctuation. All alerting stops, creating a blind spot where infrastructure failures go undetected. The secondary monitoring server was decommissioned last month.

NetworkPattern: PROCESS_CRASH_LOOPSeverity: CRITICALConfidence: 90%Remote Hands26 correlated

MTU Mismatch Causing Packet Fragmentation and Drops

PASS

After a firewall firmware upgrade, the MTU on the WAN interface drops from 1500 to 1400 without updating the MSS clamp. Jumbo frames from the server VLAN hit the firewall and get silently dropped, causing intermittent failures for large file transfers and database replication.

NetworkPattern: NIC_ERRORSSeverity: CRITICALConfidence: 85%Remote Hands36 correlated

VLAN Trunk Misconfiguration — Spanning Tree Reconvergence

PASS

A junior admin accidentally changes a trunk port to access mode on a distribution switch, pruning all VLANs except the native VLAN. The spanning tree topology reconverges, causing a 30-second outage across multiple VLANs and triggering TCN flooding.

NetworkPattern: STP_LOOPSeverity: CRITICALConfidence: 87%Remote Hands47 correlated

BGP Route Leak Causing Traffic Blackhole

PASS

A misconfigured route-map on the border router leaks internal BGP prefixes to the upstream ISP. The ISP begins routing external traffic into a blackhole. Customer-facing services become unreachable from the internet while internal connectivity remains functional.

NetworkPattern: CISCO_EVENTSeverity: CRITICALConfidence: 92%Remote Hands58 correlated

ISP Circuit Brownout — Intermittent Packet Loss

PASS

The primary ISP circuit is experiencing intermittent packet loss (5-15%) due to a degraded fiber segment. Not a full outage — the circuit stays up but quality degrades. VoIP calls have choppy audio, video conferences freeze, and cloud app performance is poor. ISP ticket opened but ETA unknown.

NetworkPattern: UNKNOWNSeverity: CRITICALConfidence: 95%Remote Hands26 correlated

SSL Offload Certificate Mismatch

PASS

During a certificate renewal, the wrong certificate is applied to the load balancer's SSL offload profile. The certificate is for a different domain (staging.acmecorp.com instead of www.acmecorp.com). Browsers show certificate name mismatch warnings. HPKP pins do not match.

NetworkPattern: LOAD_BALANCER_EVENTSeverity: CRITICALConfidence: 85%Remote Hands22 correlated

WAF False Positive Blocking All Traffic

PASS

A WAF rule update on the F5 ASM introduces a false positive that matches a common HTTP header sent by the company's mobile app. All mobile API requests are blocked with 403 Forbidden. 60% of customer traffic comes from the mobile app.

NetworkPattern: FIREWALL_RULE_BLOCKSeverity: CRITICALConfidence: 95%Auto-Heal19 correlated

Load Balancer Health Check Cascade Failure

PASS

An F5 BIG-IP load balancer's health check monitor becomes too aggressive after a config change (interval: 1s, timeout: 2s). A brief 3-second network blip causes all pool members to be marked DOWN simultaneously. The LB returns 503 to all clients.

NetworkPattern: LOAD_BALANCER_EVENTSeverity: CRITICALConfidence: 85%Auto-Heal29 correlated

Wireless Rogue AP Detected

PASS

The WLC detects a rogue access point broadcasting a corporate SSID ('Corp-WiFi') in the parking lot. The rogue AP is performing an evil twin attack, capturing credentials from employees who auto-connect. WIDS alerts trigger but containment is not automatic.

NetworkPattern: WIRELESS_CONTROLLERSeverity: CRITICALConfidence: 95%Auto-Heal8 correlated

WLC Failure — All Managed APs Orphaned

PASS

The Cisco 9800 Wireless LAN Controller crashes, orphaning 60 managed access points. APs enter standalone mode with limited functionality. New client authentications fail because RADIUS proxy is unavailable. Existing clients remain associated but cannot roam.

NetworkPattern: WIRELESS_CONTROLLERSeverity: CRITICALConfidence: 92%Remote Hands36 correlated

Switch Stack Master Election — Temporary Outage

PASS

The master switch in a 3-member stack reboots unexpectedly due to a firmware bug. A new master election occurs, causing a 90-second control plane outage. During the election, no configuration changes can be made, and STP reconverges, causing brief traffic interruption.

NetworkPattern: SWITCH_STACK_EVENTSeverity: CRITICALConfidence: 92%Remote Hands26 correlated

Switch Stack Ring Failure — Stack Split

PASS

A Cisco 9300 4-member switch stack experiences a stack cable failure, splitting the stack into two independent 2-member stacks. Both halves claim the same management IP. MAC address tables conflict. Half the access ports become unreachable from management.

NetworkPattern: SWITCH_STACK_EVENTSeverity: CRITICALConfidence: 92%Remote Hands36 correlated
PreviousPage 3 of 5Next

Every scenario is tested against Corax's Neural Engine in a production environment with AI-powered root cause analysis.

Tests run continuously as new infrastructure patterns are added.