DNS resolution fails only on branch VLANs after firewall policy migration.
This guide is for incidents where headquarters and data center lookups still succeed, but remote VLANs or branch segments begin timing out or returning inconsistent answers after firewall rule changes, policy reordering, or uplink redesign.