#InvestigationMethodology
A worker is trying to access to Amazon.fr. We try to solve it.
First we check the transport layer.
- L4 (Transport Layer) : tracert (windows) / traceroute (linux)
192.168.1.188
192.168.254.254
******
******
******
timeout
If I see this, it could be an internet problem. So it could be a problem of the firewall or proxy.
-
L3 (Network Layer) :
ping 192.168.254.254andping 192.168.1.188> a) result could be either ping KO or ping OK- first option : firewall doesn't ping ;
- a physical problem (e.g.: cable not plugged correctly)
- is it a problem on wifi or Ethernet cable or cable of the switch ?
- a logical problem ;
- ICMP could be blocked
- 802.1X
- Could be a GPO rule that blocks the e-commerce websites
- a physical problem (e.g.: cable not plugged correctly)
- second option : ping OK
- a physical problem
- a logical problem
- DNS
- first option : firewall doesn't ping ;
-
L3 (Network layer) : we do
ping google.com> OK -
I go to the browser and try https://google.com and it works
Another problem :
Let's say that a user computer got a malware from the email that manipulates the Powershell or cmd.
- First thing we do is : cut the connection of the computer with the network