Techerest

Cisco IP SLA, Object Tracking และ HSRP Tracking: สร้าง Gateway Failover

IP SLA, Object Tracking และ HSRP Tracking เป็นเทคโนโลยีที่ช่วยให้ Cisco Router ตัดสินใจ Failover ได้ฉลาดกว่าการตรวจเพียงว่า Interface ยังเป็น UP หรือ DOWN เพราะสามารถตรวจสอบ Next-Hop, Remote IP หรือเส้นทางปลายทาง แล้วนำผลการตรวจสอบมาเปลี่ยน HSRP Priority หรือ Routing Decision ได้

บทความนี้จะต่อยอดจาก HSRP, VRRP และ GLBP โดยเริ่มจากปัญหาที่ Gateway ยังคงเป็น Active แม้เส้นทาง Internet จะเสีย จากนั้นจะเชื่อมโยง IP SLA → Object Tracking → HSRP Tracking ให้เห็นกระบวนการ Failover ตั้งแต่ต้นจนจบ

ภาค 1: ปัญหาที่ FHRP เพียงอย่างเดียวอาจมองไม่เห็น

Gateway ยัง Active แต่ Internet ใช้งานไม่ได้

สมมติว่าเรามี HSRP:

                 Internet
                    |
                    |
                   ISP
                 /     \
                /       \
              R1         R2
           ACTIVE      STANDBY
              \         /
               \       /
                  SW
                   |
                  PC

Virtual Gateway
192.168.10.1

R1 มี Priority สูงกว่า จึงเป็น Active Gateway

R1 Priority = 110
R2 Priority = 100

ถ้า R1 LAN Interface Down HSRP สามารถตรวจพบ และ R2 สามารถขึ้นมาทำงานแทน

แต่มี Failure อีกประเภทหนึ่ง:

PC
 |
SW
 |
R1 ACTIVE
 |
Gi0/1
 |
ISP Router
 |
 X
Remote Internet Failure

ในกรณีนี้:

R1 LAN Interface = UP
R1 WAN Interface = UP
HSRP = ACTIVE

But...

Remote Path = DOWN

Gateway อาจยังคง Active เพราะ Local Interfaces ยังไม่ได้ Down

Interface UP ไม่ได้หมายความว่า End-to-End Path ใช้งานได้ สายเชื่อมต่อไปยัง ISP Router อาจยัง Up ขณะที่เส้นทางถัดจาก ISP มีปัญหาแล้ว

Interface Tracking คืออะไร?

วิธีพื้นฐานคือให้ HSRP ติดตาม Interface ที่สำคัญ

ตัวอย่าง:

R1
 |
 +-- Gi0/0 LAN
 |
 +-- Gi0/1 WAN

ถ้า Gi0/1 Down ให้ลด HSRP Priority

แนวคิด:

Gi0/1 UP
   |
   v
HSRP Priority = 110


Gi0/1 DOWN
   |
   v
Decrease Priority
   |
   v
HSRP Priority = 90

เมื่อ Priority ของ R1 ต่ำกว่า R2:

R1 = 90
R2 = 100

       |
       v

R2 becomes preferred gateway

ข้อจำกัดของ Interface Tracking

สมมติ:

R1
 |
Gi0/1
 |
ISP Router
 |
 X
Internet

Gi0/1 ยังเป็น:

UP / UP

ดังนั้นการ Track เพียง Interface อาจไม่ตรวจพบว่า ปลายทางไกลออกไปเสีย

จึงต้องใช้ Mechanism ที่สามารถส่ง Probe ไปตรวจ Destination ที่อยู่ไกลออกไป

นั่นคือ:

IP SLA

ภาค 2: Cisco IP SLA

IP SLA คืออะไร?

IP SLA เป็นความสามารถของ Cisco สำหรับสร้าง Active Probe เพื่อวัดหรือตรวจสอบ Network Reachability และ Performance ตาม Operation ที่รองรับ

แนวคิด:

Router
  |
  | Probe
  |
  +--------------------> Target
  |
  | <------------------
  | Response
  |
  v
Success / Failure

IP SLA ไม่จำเป็นต้องรอ ให้ผู้ใช้งานรายงานว่า Network มีปัญหา เพราะ Router สามารถ สร้าง Probe ของตัวเองได้

IP SLA ตรวจอะไรได้บ้าง?

Operation ที่รองรับขึ้นอยู่กับ Platform และ Software Release แต่ตัวอย่างที่พบได้ เช่น:

  • ICMP Echo
  • TCP Connection
  • UDP-based Operations
  • DNS-related Measurement
  • HTTP-related Measurement
  • Jitter Measurement

สำหรับ Gateway Failover ตัวอย่างที่เข้าใจง่ายคือ:

ICMP Echo

IP SLA Probe ทำงานอย่างไร?

สมมติ R1 ต้องตรวจ:

203.0.113.1

Configuration เชิงตัวอย่าง:

ip sla 10
 icmp-echo 203.0.113.1 source-interface GigabitEthernet0/1
 frequency 5

จากนั้น Schedule:

ip sla schedule 10 life forever start-time now

Flow:

R1
 |
 | ICMP Echo
 v
203.0.113.1
 |
 | Reply
 v
R1

Result = Success

หากไม่มี Response:

R1
 |
 | ICMP Echo
 v
203.0.113.1
 X

Result = Failure
Target ของ IP SLA ควรถูกเลือกตามสิ่งที่ต้องการตรวจจริง หากตรวจเพียง ISP Next-Hop จะยืนยันได้เพียงว่า เส้นทางถึง Next-Hop นั้นยังตอบสนอง แต่ไม่ได้ยืนยันว่า Internet หรือ Application ปลายทางทั้งหมด ทำงานปกติ

ภาค 3: Object Tracking

Object Tracking คืออะไร?

IP SLA ทำหน้าที่ สร้าง Measurement หรือ Probe

แต่ Feature อื่นต้องมีวิธี นำผลของ Probe ไปใช้ตัดสินใจ

จึงมี:

Object Tracking

แนวคิด:

IP SLA
  |
  | Probe result
  v
Track Object
  |
  +---- UP
  |
  +---- DOWN

ตัวอย่าง:

track 10 ip sla 10 reachability

ความสัมพันธ์:

IP SLA 10
   |
   v
Track 10
   |
   +---- UP
   |
   +---- DOWN

IP SLA กับ Object Tracking ทำงานร่วมกันอย่างไร?

ให้มองเป็นสามชั้น:

Layer 1
IP SLA
"ตรวจสอบ"


Layer 2
Object Tracking
"แปลงผลเป็นสถานะ"


Layer 3
HSRP / Route / Feature
"นำสถานะไปตัดสินใจ"

ดังนั้น:

IP SLA
   |
   v
Track Object
   |
   v
HSRP

หรือ:

IP SLA
   |
   v
Track Object
   |
   v
Static Route

ภาค 4: HSRP Tracking

HSRP Tracking คืออะไร?

HSRP สามารถนำสถานะ ของ Track Object มาปรับ Priority เพื่อเปลี่ยน Preferred Gateway เมื่อ Network Condition เปลี่ยน

ตัวอย่าง:

R1
Base Priority = 110

Track 10 = UP

Effective Priority
= 110

เมื่อ Track Down:

R1
Base Priority = 110

Track 10 = DOWN

Decrement = 30

Effective Priority
= 80

ขณะที่ R2:

Priority = 100

ผล:

R1 = 80
R2 = 100

R2 becomes preferred Active

Priority Decrement ต้องคำนวณอย่างไร?

สมมติ:

R1 Priority = 110
R2 Priority = 100

ถ้าลด R1 เพียง:

5

จะได้:

R1 = 105
R2 = 100

R1 ยังมี Priority สูงกว่า

แต่หาก Decrement:

20

จะได้:

R1 = 90
R2 = 100

จึงสามารถเปลี่ยน Preferred Role ตาม Design ได้

อย่ากำหนด Decrement แบบสุ่ม ต้องคำนวณจาก Base Priority ของ Gateway ทุกตัว และผลลัพธ์ที่ต้องการ หลัง Track Object เปลี่ยนสถานะ

ภาค 5: Cisco IP SLA + Object Tracking + HSRP Lab

Topology

                         INTERNET
                            |
                    +-------+-------+
                    |               |
                  ISP1             ISP2
                    |               |
                    |               |
                   R1               R2
             Priority 110      Priority 100
                 ACTIVE          STANDBY
                    \               /
                     \             /
                      +-----SW-----+
                            |
                            |
                           PC1

LAN
192.168.10.0/24

Virtual Gateway
192.168.10.1

R1:

LAN
192.168.10.2

WAN
203.0.113.2

HSRP Priority
110

R2:

LAN
192.168.10.3

WAN
198.51.100.2

HSRP Priority
100

Step 1 — Configure R1 LAN และ HSRP

interface GigabitEthernet0/0
 description LAN
 ip address 192.168.10.2 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 110
 standby 10 preempt
 no shutdown

Step 2 — Configure R2 LAN และ HSRP

interface GigabitEthernet0/0
 description LAN
 ip address 192.168.10.3 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 100
 standby 10 preempt
 no shutdown

Step 3 — Configure WAN

R1:

interface GigabitEthernet0/1
 description ISP1
 ip address 203.0.113.2 255.255.255.252
 no shutdown

R2:

interface GigabitEthernet0/1
 description ISP2
 ip address 198.51.100.2 255.255.255.252
 no shutdown

Step 4 — Create IP SLA บน R1

ตัวอย่างนี้ให้ R1 ตรวจสอบ Target ผ่าน WAN

ip sla 10
 icmp-echo 203.0.113.1 source-interface GigabitEthernet0/1
 frequency 5

ip sla schedule 10 life forever start-time now

Flow:

R1 Gi0/1
203.0.113.2
     |
     | ICMP Echo
     v
203.0.113.1

Step 5 — Create Object Tracking

track 10 ip sla 10 reachability

ผลเชิงแนวคิด:

IP SLA Success
      |
      v
Track 10 UP


IP SLA Failure
      |
      v
Track 10 DOWN

Step 6 — เชื่อม Track Object กับ HSRP

interface GigabitEthernet0/0
 standby 10 track 10 decrement 30

สถานะปกติ:

R1
Priority 110
Track UP

Effective Priority = 110


R2
Priority = 100


R1 = ACTIVE

เมื่อ IP SLA Fail:

R1
Priority 110
Track DOWN
Decrement 30

110 - 30 = 80


R2
Priority = 100


R2 becomes preferred gateway

Failover Flow แบบเต็ม

Remote Target fails
       |
       v
IP SLA probe fails
       |
       v
Track 10 = DOWN
       |
       v
HSRP priority decrement
       |
       v
R1: 110 -> 80
       |
       v
R2 priority = 100
       |
       v
R2 becomes ACTIVE
       |
       v
Client continues using
192.168.10.1

เมื่อ Path กลับมาทำงาน

Target responds
      |
      v
IP SLA Success
      |
      v
Track 10 UP
      |
      v
R1 Priority restored
80 -> 110
      |
      v
Preempt
      |
      v
R1 may become ACTIVE again

จุดนี้ต้องระวัง Flapping หาก Network Path ไม่เสถียร

ภาค 6: Tracking Delay และ Failback Stability

ทำไมไม่ควร Failback เร็วเกินไป?

สมมติ WAN:

UP
DOWN
UP
DOWN
UP
DOWN

ถ้าทุก State Change ทำให้ HSRP เปลี่ยน Active Gateway ทันที:

R1 ACTIVE
   |
R2 ACTIVE
   |
R1 ACTIVE
   |
R2 ACTIVE

อาจทำให้ Network ไม่เสถียรยิ่งขึ้น

Object Tracking บาง Platform/Release รองรับ Delay ก่อนประกาศสถานะ Down/Up

ตัวอย่างแนวคิด:

track 10 ip sla 10 reachability
 delay down 10 up 30

ความหมายเชิง Design:

Failure detected
      |
Wait before DOWN
      |
Track DOWN


Recovery detected
      |
Wait longer
      |
Track UP
Syntax และความสามารถของ Track Delay อาจแตกต่างตาม Cisco Platform และ IOS/IOS XE Release ควรตรวจ Command Reference ก่อนใช้ใน Production

HSRP Preempt Delay

อีกแนวทางหนึ่งคือ ไม่ให้ Router ที่เพิ่ง Recovery รีบ Preempt กลับมา ทันที

ตัวอย่างแนวคิด:

standby 10 preempt delay minimum 60

ช่วยให้ Router มีเวลา Stabilize ก่อนกลับมารับ Active Role

ค่า Delay ไม่มีค่าตายตัว ควรกำหนดจาก Convergence Time, Routing Protocol, WAN Stability, Application Requirement และ Failure Scenario ของระบบจริง

ภาค 7: IP SLA กับ Static Route

IP SLA ใช้กับ Static Route ได้หรือไม่?

ได้ใน Design ที่รองรับ โดยสามารถใช้ Track Object ร่วมกับ Static Route

ตัวอย่างแนวคิด:

Primary ISP
     |
     v
Default Route A
     |
     +---- Track 10


Backup ISP
     |
     v
Floating Static Route

ตัวอย่าง:

ip route 0.0.0.0 0.0.0.0 203.0.113.1 track 10

ip route 0.0.0.0 0.0.0.0 198.51.100.1 200

เมื่อ Track 10 Up:

Primary Default Route
Installed

เมื่อ Track Down:

Primary Route removed
        |
        v
Backup Floating Route
becomes usable

ระวัง IP SLA Probe วิ่งออก Backup Path

นี่เป็นปัญหาสำคัญ ใน Dual-WAN Design

สมมติ Probe Target:

8.8.8.8

เมื่อ Primary ISP Fail Routing อาจเปลี่ยนให้ Probe ไปออก Backup ISP

IP SLA
 |
 | intended to test ISP1
 |
 +---- ISP1 failed
 |
 +---- Routing chooses ISP2
 |
 v
Probe still succeeds

ผลคือ Track Object อาจกลับเป็น Up แม้ Primary Path ที่ต้องการตรวจยังเสียอยู่

IP SLA Target และ Routing ของ Probe ต้องออกแบบร่วมกัน ไม่ควรเลือก Public IP แล้วถือว่า Probe จะวิ่งผ่าน ISP ที่ต้องการเสมอ ต้องตรวจ Routing Table, Source Interface และ Path ของ Probe จริง

ภาค 8: IP SLA กับ Dynamic Routing

IP SLA แทน OSPF ได้หรือไม่?

ไม่ได้ ทั้งสองมีหน้าที่ต่างกัน

Technology หน้าที่
IP SLA สร้าง Active Probe เพื่อตรวจ Reachability/Performance ตาม Operation
Object Tracking สร้าง Logical State จากสิ่งที่ Track
HSRP Default Gateway Redundancy
OSPF Dynamic Routing และ Route Convergence

ใน Enterprise Design เทคโนโลยีเหล่านี้ สามารถทำงานร่วมกันได้

Client
   |
   v
HSRP Virtual Gateway
   |
   +---- R1
   |      |
   |      +---- OSPF
   |      |
   |      +---- IP SLA
   |      |
   |      +---- Tracking
   |
   +---- R2
          |
          +---- OSPF
          |
          +---- IP SLA
          |
          +---- Tracking

ภาค 9: ออกแบบ IP SLA Probe อย่างถูกต้อง

ควร Probe ไปที่ไหน?

คำตอบขึ้นอยู่กับ สิ่งที่ต้องการพิสูจน์

Target สิ่งที่ตรวจได้ ข้อจำกัด
Local ISP Next-Hop ตรวจ First-Hop WAN ไม่ยืนยัน Internet Beyond ISP
Remote ISP Address ตรวจ Path ได้ไกลขึ้น ขึ้นกับ Routing และ Remote Response
Public DNS/IP ตรวจ Internet Reachability บางส่วน Target อาจ Block ICMP หรือ Probe อาจออกผิด ISP
Own Remote Server ตรวจ Service Path ที่องค์กรควบคุม Server Failure อาจถูกตีความเป็น WAN Failure

อย่าพึ่ง Target เดียวโดยไม่วิเคราะห์ Failure Domain

ตัวอย่าง:

Router
 |
 +---- ISP
       |
       +---- Internet
             |
             +---- Target

ถ้า Target Server Down แต่ Internet ปกติ:

IP SLA = Failure

but

WAN = Healthy

Router อาจ Failover โดยไม่จำเป็น

ดังนั้นต้องถามก่อนว่า:

What exactly
does this probe prove?

Frequency เร็วกว่าไม่ได้แปลว่าดีกว่าเสมอ

ตัวอย่าง:

frequency 5

หมายถึง Probe ตามรอบเวลาที่กำหนด

หาก Probe ถี่เกินไป อาจเพิ่ม Control Traffic และทำให้ Failover ไวต่อ Transient Failure มากเกินความจำเป็น

หาก Probe ช้าเกินไป Failover Detection ก็ช้าลง

จึงต้องสมดุล:

Detection Speed
      |
      +
Network Stability
      |
      +
Probe Overhead
      |
      +
Application Requirement

ภาค 10: Verification Commands

ตรวจ IP SLA Configuration

show ip sla configuration

ตรวจ IP SLA Statistics

show ip sla statistics

ตรวจ Track Object

show track

ตรวจ HSRP

show standby
show standby brief

ตรวจ Interface

show ip interface brief
show interfaces

ตรวจ Routing

show ip route
show ip route 0.0.0.0

ตรวจ Path

ping 203.0.113.1
traceroute 203.0.113.1
Ping และ Traceroute เป็นเพียงเครื่องมือส่วนหนึ่ง ของการ Troubleshoot เพราะบาง Network จำกัด ICMP หรือมี Control-Plane Policy ที่ทำให้ผลทดสอบ ไม่สะท้อน Application Traffic โดยตรง

ภาค 11: IP SLA และ HSRP Troubleshooting

Troubleshooting Workflow

Physical Interface
       |
       v
IP Address
       |
       v
Routing
       |
       v
Can router reach target?
       |
       v
IP SLA running?
       |
       v
IP SLA result?
       |
       v
Track object state?
       |
       v
HSRP tracking applied?
       |
       v
Priority changed?
       |
       v
Peer priority?
       |
       v
Preempt behavior?
       |
       v
Failover successful?
       |
       v
Application works?

ปัญหา 1 — IP SLA ไม่เริ่มทำงาน

Configure Operation แล้ว แต่ลืม Schedule

ip sla 10
 icmp-echo 203.0.113.1

แต่ไม่มี:

ip sla schedule 10 life forever start-time now

ตรวจ:

show ip sla configuration
show ip sla statistics

ปัญหา 2 — IP SLA Success แต่ Track Down

ตรวจ Mapping:

IP SLA 10
     |
     v
Track 10

Configuration:

track 10 ip sla 10 reachability

ตรวจว่าหมายเลข SLA Operation และ Track Object เชื่อมกันถูกต้อง

ปัญหา 3 — Track Down แต่ HSRP Priority ไม่เปลี่ยน

ตรวจ:

show track
show standby
show running-config interface GigabitEthernet0/0

ควรพบ Configuration เช่น:

standby 10 track 10 decrement 30

ปัญหา 4 — Priority ลดแล้วแต่ R2 ไม่ขึ้น Active

ตัวอย่าง:

R1
110 - 5 = 105

R2
100

R1 ยังสูงกว่า

ต้องคำนวณ:

R1 after decrement
<
R2 priority

หากต้องการให้ R2 มี Preferred Priority เมื่อ Track Down

ปัญหา 5 — Failover สำเร็จ แต่ Internet ยังไม่ได้

ตรวจ R2 ต่อ:

R2 Routing
    |
    v
Default Route
    |
    v
NAT
    |
    v
Firewall
    |
    v
ISP
    |
    v
Return Path

HSRP Failover สำเร็จ ไม่ได้รับประกันว่า Data Plane ของ Backup Router พร้อมใช้งานทุก Feature

ปัญหา 6 — Failover ไปมา

ตรวจ:

Probe frequency

Timeout

Track delay

Preempt

Preempt delay

WAN packet loss

Target stability

อาการนี้อาจเกิดจาก Probe Target หรือ WAN Path ไม่เสถียร

ปัญหา 7 — Probe วิ่งผิด ISP

ตรวจ Routing Path จาก Source Interface ไปยัง Target

show ip route TARGET-IP

traceroute TARGET-IP

อย่าสรุปว่า source-interface เพียงอย่างเดียว จะควบคุม Forwarding Path ได้ทุกสถานการณ์ Routing Decision ยังต้องถูกตรวจสอบ

ภาค 12: Production Design Checklist

ก่อนใช้ IP SLA + HSRP Tracking

1. Define failure scenario

2. Decide what must be monitored

3. Select probe target

4. Verify target reliability

5. Verify probe routing path

6. Configure IP SLA

7. Schedule IP SLA

8. Configure object tracking

9. Define HSRP base priorities

10. Calculate decrement value

11. Configure tracking

12. Review preempt behavior

13. Consider track delay

14. Consider preempt delay

15. Verify backup routing

16. Verify NAT on backup

17. Verify firewall on backup

18. Test primary path failure

19. Test remote path failure

20. Test recovery/failback

21. Monitor logs

22. Document expected states

High Availability Test Matrix

Failure Test สิ่งที่ควรตรวจ
R1 Power Failure R2 รับ Active Role ได้หรือไม่
R1 LAN Interface Down Gateway Failover
R1 WAN Interface Down Tracking และ Failover
ISP Next-Hop Failure IP SLA Detect หรือไม่
Remote Path Failure Probe Target ตรวจพบหรือไม่
Path Recovery Track กลับ UP หรือไม่
R1 Failback Preempt ทำงานตาม Design หรือไม่
Unstable WAN เกิด Gateway Flapping หรือไม่
Backup Active Routing/NAT/Firewall ใช้งานได้จริงหรือไม่

ภาค 13: คำถามที่พบบ่อย

IP SLA คืออะไร?

IP SLA เป็นความสามารถ สำหรับสร้าง Active Probe เพื่อตรวจ Reachability หรือวัด Network Performance ตาม Operation ที่รองรับ

Object Tracking คืออะไร?

Object Tracking ใช้สร้างสถานะ Logical เช่น UP/DOWN จาก Object หรือ Operation ที่ติดตาม เพื่อให้ Feature อื่น นำสถานะไปใช้ต่อ

IP SLA กับ Object Tracking เหมือนกันหรือไม่?

ไม่เหมือนกัน

IP SLA
= Performs measurement/probe


Object Tracking
= Tracks resulting state

HSRP Tracking ทำอะไร?

HSRP Tracking สามารถนำสถานะของ Track Object มาปรับ HSRP Priority เพื่อเปลี่ยน Gateway Role ตาม Network Condition

ทำไม Track Interface อย่างเดียวไม่พอ?

เพราะ Interface สามารถเป็น UP แม้ Remote Network หรือ Upstream Path จะมีปัญหา

IP SLA ต้องใช้ HSRP เสมอหรือไม่?

ไม่ IP SLA สามารถนำไปใช้ ร่วมกับ Feature อื่น ตามความสามารถของ Platform เช่น Object Tracking และ Route Decision

ควร Ping 8.8.8.8 เป็น IP SLA Target เสมอหรือไม่?

ไม่ควรกำหนดเป็นกฎตายตัว Target ต้องเลือกตาม Failure Domain ที่ต้องการตรวจ รวมถึง Routing Path, Target Availability และนโยบายของ Network ปลายทาง

IP SLA Target ตอบไม่ได้แปลว่า Internet เสียหรือไม่?

ไม่เสมอไป Target อาจ Down, ไม่ตอบ ICMP หรือมี Policy ป้องกัน Probe ขณะที่ Network ส่วนอื่น ยังใช้งานได้

ทำไมต้องใช้ Decrement?

เพื่อลด HSRP Priority ของ Gateway เมื่อ Track Object Down จน Backup Gateway มี Priority สูงกว่า ตาม Failover Design

Decrement เท่าไรจึงเหมาะสม?

ไม่มีค่าตายตัว ต้องคำนวณจาก Base Priority ของ Gateway ทุกตัว และ Role ที่ต้องการ หลัง Failure

Preempt กับ Tracking ต่างกันอย่างไร?

Tracking ใช้เปลี่ยน Priority ตามสถานะของ Object

Preempt เกี่ยวข้องกับการให้ Gateway ที่มี Priority เหมาะสมกว่า กลับมารับ Preferred Role ตาม Protocol Behavior และ Configuration

IP SLA แทน Network Monitoring ได้หรือไม่?

ไม่ทั้งหมด IP SLA เป็นเครื่องมือ Active Measurement ส่วนระบบ Monitoring ยังควรใช้ SNMP, Syslog, Telemetry หรือ Monitoring Platform ตาม Architecture

Failover สำเร็จแล้วถือว่า High Availability สมบูรณ์หรือไม่?

ยังไม่พอ ต้องทดสอบ:

Gateway
+
Routing
+
NAT
+
Firewall
+
DNS
+
Application
+
Return Path

จึงจะทราบว่า Backup Path ใช้งานได้จริงแบบ End-to-End

บทสรุป

IP SLA, Object Tracking และ HSRP Tracking ช่วยยกระดับ Gateway Redundancy จากการตรวจเพียงสถานะ Local Interface ไปสู่การตรวจสอบ Network Path ที่สำคัญ

ลำดับการทำงานคือ:

IP SLA
   |
   | Active Probe
   v
Remote Target
   |
   v
Success / Failure
   |
   v
Object Tracking
   |
   v
UP / DOWN
   |
   v
HSRP Tracking
   |
   v
Priority Adjustment
   |
   v
Gateway Failover

ตัวอย่าง:

Normal

R1 = 110
R2 = 100

R1 ACTIVE


Remote path fails

Track DOWN


R1
110 - 30 = 80

R2
100


R2 becomes ACTIVE

แต่การออกแบบที่ดี ต้องมากกว่าเพียงทำให้ HSRP เปลี่ยน Active Router

Correct Probe Target
       +
Correct Routing Path
       +
Correct Track Logic
       +
Correct Priority Math
       +
Stable Failback
       +
Backup Routing
       +
Backup NAT / Firewall
       +
Monitoring
       =
Reliable Failover

เมื่อเข้าใจ IP SLA และ Object Tracking แล้ว เรามีองค์ประกอบสำคัญ สำหรับเข้าสู่การออกแบบ Network High Availability แบบเต็มระบบ

บทความถัดไป: Cisco High Availability Design: Dual Router, Dual Switch, HSRP, STP, EtherChannel และ Dynamic Routing

บทถัดไปจะนำเทคโนโลยี ที่เรียนมาก่อนหน้านี้ มารวมเป็น Architecture เดียว เพื่อดูว่า Layer 2, Layer 3, Gateway Redundancy และ Routing Redundancy ต้องทำงานร่วมกันอย่างไร ก่อนเดินหน้าสู่หัวข้อ IPv6 ในลำดับถัดไป

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.