Your segmentation probe to another segment times out - what different situations does that one result hide?
answer
- silence is the weakest possible result
- no reply is not the same as denied
- did it reach the enforcing device at all
- a reset or an ICMP refusal means something answered
- always send a control flow you expect to succeed
basics
~20 sA timeout proves only that no reply came back. It covers a filter silently discarding the packet, the packet never reaching the enforcing device at all, and the packet arriving at a destination that was off or not listening while the reply was dropped. A pass and a broken probe look identical.
solid answer
~60 sSilence is the weakest result a probe can return, and it is the one people read as success. Three very different worlds produce it. First, an enforcing device discarded the packet without answering - the outcome you wanted. Second, nothing ever reached that device: no route, a discard route, the probe host on the wrong VLAN or VRF, a local host filter, or the branch link down. Third, it arrived somewhere alive but nothing was listening and the response was itself discarded on the way back. Compare that with an explicit refusal - a TCP reset, or an ICMP destination unreachable with the administratively-prohibited code - which at least proves something on the path saw the packet and answered. To make silence mean anything you need two extra pieces: a control flow to a destination you expect to succeed, proving the probe host and its path work, and observation at the far side so arrival and non-arrival are distinguishable. Without those, a dead probe host reports a perfect boundary.
go deeper
Know that a timeout means only that no reply came back, and that a reset or an ICMP refusal is a stronger, more informative result because something on the path answered.
Be ready to enumerate the three worlds behind a silent result - silent discard, never reached the device, arrived but nothing answered - and to name concrete causes for the middle one such as a missing route or a probe on the wrong VLAN.
Demonstrate the measurement design: paired control flows, far-side arrival observation, and a reporting rule that renders a probe that did not run as unknown rather than pass.
Be able to argue the estate-wide posture trade-off - refusing explicitly inside and discarding silently at the edge - in terms of evidence quality and investigation cost, not just adversary information.
## The direction of the claim A timeout supports exactly one statement: **no reply arrived within the wait**. Everything past that is inference, and the inference people reach for - "the firewall denied it" - is the one the result cannot carry. This matters because the failure is asymmetric: every way a probe can be broken produces the same silence as a working boundary, so a broken measurement system reports perfect segmentation. ## The three worlds behind one silent result **1. A device on the path discarded it silently.** This is the intended result. A packet filter configured to drop rather than reject sends nothing back, deliberately, so that a prober learns as little as possible. Note the irony: the posture chosen to starve an adversary of information starves your own evidence too. **2. The packet never reached the enforcing device.** This class is large and is what makes green results untrustworthy at estate scale: - no route toward the destination, or a discard route swallowing the prefix upstream of the policy device; - the probe host on the wrong VLAN, in the wrong VRF, or holding an address the network never learned; - a host-level filter on the probe machine itself, dropping outbound before the packet leaves; - the branch link, tunnel or overlay down; - reverse-path filtering upstream discarding the source address; - the destination address simply not assigned to anything. The boundary was never exercised. Nothing about it was learned. **3. It arrived, but nothing answered and the reply was lost.** The destination host is powered off, or nothing is listening on that port and its reset was itself dropped on the return path, or the return path is asymmetric and passes a stateful device that has no record of the outbound flow. Return-path asymmetry is a favourite interview probe: state is built by the device that saw the first packet, and a reply arriving somewhere else is discarded as out-of-state. ## The results that are not silent, and what they mean | Result | What it proves | | --- | --- | | Handshake completes | The path exists and the flow is permitted end to end | | TCP reset | Something on the path answered - either a device configured to reject, or a live host with nothing listening | | ICMP destination unreachable, administratively prohibited | A device on the path saw the packet and chose to refuse it, and it identified itself by doing so | | ICMP host or network unreachable | Routing gave up; usually a path problem, not a policy one | | Nothing at all | No reply arrived. Ambiguous by construction | An explicit refusal is weaker as a security posture and stronger as evidence. That is a genuine trade-off to be able to argue: a reject posture on internal boundaries makes your denial provable and your troubleshooting fast, at the cost of confirming to an intruder that the destination exists and that a filter stands there. Many estates settle on reject internally and silent discard at the outer edge, precisely so internal evidence stays legible. ## Making silence mean something Three techniques turn an ambiguous result into a usable one. **The control flow.** Every negative probe travels with a positive one you expect to succeed - the same destination host on a permitted service, or a known-good service in the same target zone. If the control fails, the negative result is void. This single discipline removes most false green results, because a probe host that has lost its link, its address or its route fails both. **Far-side observation.** A listener in the destination segment that logs arrivals splits "discarded somewhere" from "arrived and was ignored". It does not tell you *which* device dropped the packet - for that you need the enforcing device's own record of the denied flow - but it converts an inference into two measurements. **Probe health as a separate signal.** A probe that did not run, did not report, or failed its control must render as **unknown**, never as pass. At four hundred sites this is the difference between a coverage matrix and a decoration: silence from a site is the most common event in the system, and if silence colours green then the dashboard's brightest state is also its emptiest. ## The adversary's version of the same experiment An intruder in the branch segment runs the same test with better patience and no control flows. They interpret silence correctly - as "unknown, try another port, another destination, another direction" - and they will eventually find a directed pair where the answer is a completed handshake. The defender who read silence as proof stopped testing at the first ambiguous result; the adversary did not.
- Would you rather your internal boundaries drop silently or refuse explicitly, and why?For internal segment boundaries an explicit refusal is often worth it: it makes denial provable, identifies the enforcing device, and turns a five-hour application investigation into a five-minute one. The cost is that anyone inside, including an intruder, learns that a filter stands there and that the destination is real. Many estates refuse internally and discard silently at the outer edge, so the evidence stays legible where you already assume presence.
- Your probe returns a TCP reset. Does that prove the boundary refused it?No. It proves something on the path answered. That could be a filtering device configured to reject, or a live destination host with no service listening on that port, or a middlebox resetting the connection. To attribute the reset you need the far-side arrival record or the enforcing device's own log of a denied flow. On its own, a reset only rules out silence.
- Why does a control flow that also fails void the negative result?Because it shows the failure is upstream of the thing you were testing. If a flow you expect to succeed also produces nothing, the probe host, its address, its local filter, its route or its link is broken - so the silent negative result carries no information about the boundary. The pair must be reported as unknown and the probe fixed before its results count.
saying these in an interview costs you the question
- Reads a timeout as proof the firewall denied the flow
- Runs no control flow alongside the negative probe
- Assumes a TCP reset always comes from the filtering device
- Never checks whether the packet reached anything at all
- Reports a probe that failed to run as a pass
- Ignores asymmetric return paths through stateful devices