Include the exact error and targeted service with the SDK and interpreter versions; ping success alone will not identify where the diagnostic request failed.
Have IT investigate the route and permitted service path, while retaining the software-version comparison; the route difference is not yet a demonstrated cause.
Retain that before-and-after comparison and the verified endpoint in the handover, so a later timeout is investigated against a known working setup rather than this original incomplete account.