Network Troubleshooting
Median first-response < 3 minutes
Network issues are the black-box of IT support. "WiFi is slow," "VPN keeps dropping," "can't reach the internal wiki" — every case starts as user-perception, and network diagnostics require correlating data from the user's device + the WiFi controller + the DNS server + the VPN concentrator + the firewall + the internal service. Manual triage takes 30-90 minutes and often ends with "try restarting your router."
An hour-by-hour walkthrough.
Step by step.
- 01
Correlate network signals across every hop
Device WiFi + VPN client + ISP + VPN concentrator + firewall + destination service. End-to-end path visibility.
MDM · VPN telemetry · ISP monitoring · Cloud network monitoring - 02
Diagnose from correlated data
Not device-only view. Correlates similar reports; identifies infrastructure-side issues that individual devices can't diagnose.
Reasoning · Similar-report clustering · Infrastructure telemetry - 03
Present remediation options with tradeoffs
User remediation (switch PoP, restart, DNS change) with expected impact. Infrastructure escalation to network ops for shared-cause issues.
Slack · Teams · VPN config · Network ops queue - 04
Execute approved user remediation
Config changes via MDM. Restart guidance. DNS cache clear. User visible + approved.
MDM · VPN client config · Endpoint config - 05
Escalate shared-cause to network ops
Infrastructure issues promoted with correlated impact + suggested action. Network ops sees the pattern + user impact together.
Network ops · PagerDuty · Incident tracker
What you connect to make this run.
MDM · Endpoint telemetry
readDevice network state: WiFi signal, IP config, DNS resolution, active connections.
VPN telemetry · Cisco AnyConnect · Palo Alto GlobalProtect · Tailscale
read+writeVPN client logs + concentrator state. Config-push for PoP changes.
Cloud network monitoring · ISP + regional signals
readInfrastructure-side visibility. PoP load, ISP outages, regional degradations.
Network ops · PagerDuty
writeEscalation for shared-cause issues with correlated impact + suggested action.
Before and after, honestly.
Answers about this playbook.
What about home-network issues (router, ISP)?
Ivy diagnoses reach beyond corporate network to identify home-side vs. corporate-side. Home-side issues get guidance (router restart, ISP contact) rather than corporate escalation.
How does it handle office WiFi issues?
Same correlation model with office-specific signals (AP density, controller health, DHCP pool). Facilities-team escalation for physical issues.
Can it diagnose latency-specific issues (game lag, video quality)?
Latency + jitter analysis included. Application-specific advice: video-conferencing has different tolerances than file transfers.
What about VPN-specific edge cases (split-tunnel, always-on)?
VPN policy-aware diagnostics. Split-tunnel routing questions, always-on-VPN failures each have specific diagnostic paths.
How does it interact with zero-trust network access (ZTNA)?
ZTNA (Cloudflare Access, Zscaler ZPA) telemetry integrated. Different from traditional VPN diagnostics; posture-aware access decisions surfaced.
See it run on your data.
Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.