Concept and mechanism
A name resolving to the expected IP confirms only part of the path. Next check connectivity, TLS, authorization, and functional response. NACLs are stateless: an HTTPS connection’s response targets the client’s ephemeral port and needs an applicable return rule. For an interface endpoint, private DNS can be correct while the endpoint security group excludes the actual source. To resolve on-premises names from a VPC, a Resolver outbound endpoint and associated rule forward queries when target DNS connectivity exists. Inbound serves the reverse direction.
Guided application
VPC Flow Logs helps observe permitted or rejected traffic without capturing HTTP payload. ACCEPT does not demonstrate a successful business transaction. Reachability Analyzer evaluates supported configuration without sending packets; combine that evidence with authorized real testing. For CloudFront distribution, the cache key must distinguish relevant variants. If the origin produces different public pages by language and caching ignores lang, a cache hit can return the wrong variant without contacting the origin. Correct the policy and handle existing cached objects; increasing TTL merely prolongs error. Always identify exact test parameters so results are reproducible.
An endpoint rule accepts app-test while the application comes from app-prod. Confirm that source, correct only required access, and repeat TCP, TLS, and functional tests.
Common pitfalls
DNS treated as availability; NACL treated as stateful; ACCEPT treated as HTTP success; configuration analysis treated as live testing; cache without variants.
Related topics: Signals, alarms, and missing telemetry · Performance and operational evidence
Each layer provides different evidence; sound decisions connect them to the specific request.
Reference: Reachability Analyzer · SOA-C03; exam guide 1.1