Techerest

Cisco Network Troubleshooting: วิธีแก้ปัญหา VLAN, Trunk, DHCP, ARP, Routing และ ACL

เมื่อ Network ใช้งานไม่ได้ การแก้ปัญหาที่มีประสิทธิภาพไม่ควรเริ่มจาก การสุ่มเปลี่ยน Configuration แต่ควรใช้กระบวนการ Network Troubleshooting อย่างเป็นระบบ เพื่อตรวจสอบจากจุดพื้นฐาน ไปยังจุดที่ซับซ้อนขึ้น

บทความนี้รวบรวมความรู้จากชุด Cisco Network ก่อนหน้า ตั้งแต่ Physical Connection, Switch Port, VLAN, Trunk, STP, EtherChannel, DHCP, ARP, Inter-VLAN Routing, DHCP Snooping, DAI, IP Source Guard, Port Security ไปจนถึง ACL ให้อยู่ใน Troubleshooting Workflow เดียว

เป้าหมายคือเมื่อผู้ใช้แจ้งว่า “Network ใช้งานไม่ได้” เราจะสามารถค่อย ๆ แยกปัญหา จนระบุได้ว่าความผิดปกติ อยู่บริเวณใดของ Network

ภาค 1: วิธีคิดก่อนเริ่ม Troubleshooting

หลักการ Network Troubleshooting

ปัญหา Network หนึ่งอาการ สามารถเกิดได้จากหลายสาเหตุ

ตัวอย่าง:

User:

"เข้า Internet ไม่ได้"

Possible Causes:

Cable
 |
Switch Port
 |
Wrong VLAN
 |
Trunk
 |
STP
 |
DHCP
 |
IP Address
 |
Default Gateway
 |
ARP
 |
Routing
 |
ACL
 |
Firewall
 |
DNS
 |
Internet Connection
 |
Application

หากเริ่มแก้จาก Router, Firewall หรือ DNS ทันที โดยไม่ตรวจสอบว่า Client มี Link และ IP Address หรือไม่ อาจเสียเวลาโดยไม่จำเป็น

วิธีหนึ่งที่เหมาะกับการเรียนพื้นฐานคือ Bottom-Up Troubleshooting เริ่มจาก Layer ล่างขึ้นไป

Layer 7  Application
          ↑
Layer 4  TCP / UDP
          ↑
Layer 3  IP / Routing / ACL
          ↑
Layer 2  VLAN / MAC / STP / ARP Security
          ↑
Layer 1  Cable / Port / Signal
ในงานจริงไม่จำเป็นต้องใช้ Bottom-Up ทุกเหตุการณ์ หากมีหลักฐานชัดเจนว่า Problem Domain อยู่บริเวณใด สามารถเริ่มตรวจสอบบริเวณนั้นได้ แต่ควรใช้หลักฐานมากกว่าการคาดเดา

รู้ Normal State ก่อนแก้ปัญหา

Troubleshooting จะทำได้ง่ายขึ้นมาก หากรู้ว่า Network ในภาวะปกติ ควรมีลักษณะอย่างไร

ควรมีข้อมูล Baseline เช่น:

  • Network Diagram
  • IP Address Plan
  • VLAN List
  • Default Gateway
  • Trunk Links
  • STP Root Bridge
  • EtherChannel Members
  • DHCP Server
  • Routing Table
  • ACL Policy
  • Security Feature ที่เปิดใช้งาน

ตัวอย่าง Documentation:

VLAN 10 USERS
192.168.10.0/24
Gateway 192.168.10.1

VLAN 20 SERVERS
192.168.20.0/24
Gateway 192.168.20.1

VLAN 30 GUEST
192.168.30.0/24
Gateway 192.168.30.1

VLAN 99 MANAGEMENT
192.168.99.0/24
Gateway 192.168.99.1

ภาค 2: Layer 1 และ Layer 2 Troubleshooting

Step 1: ตรวจสอบ Physical Layer

ก่อนตรวจ Configuration ควรตรวจ Physical Connection ก่อน

ตรวจสอบ:

  • สาย Network เชื่อมต่อหรือไม่
  • Connector หลวมหรือเสียหายหรือไม่
  • Switch Port มี Link หรือไม่
  • NIC ของ Client ทำงานหรือไม่
  • อุปกรณ์มี Power หรือไม่
  • Transceiver / Fiber Link ทำงานหรือไม่

Cisco:

Switch# show interfaces status

ตัวอย่าง:

Port      Status       Vlan
Gi1/0/1   connected    10
Gi1/0/2   notconnect   10
Gi1/0/3   disabled     20

ถ้า Interface เป็น notconnect ควรตรวจ Physical Layer ก่อนแก้ VLAN หรือ Routing

Step 2: ตรวจสอบ Switch Interface

ตรวจ Interface โดยละเอียด:

Switch# show interfaces gigabitEthernet 1/0/5

ตรวจสอบข้อมูล เช่น:

  • Interface up/down
  • Line protocol
  • Speed
  • Duplex
  • Input/Output Errors
  • CRC Errors
  • Drops

ดู Running Configuration:

Switch# show running-config interface gigabitEthernet 1/0/5

ตรวจด้วยว่า Interface ถูก Administratively Shutdown หรือไม่

interface gigabitEthernet 1/0/5
 shutdown

หากต้องการเปิด Port ตาม Design:

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# no shutdown
อย่าใช้ no shutdown กับ Port ที่ถูกปิดโดยเจตนา โดยไม่ตรวจสอบ Network Design และ Change Control ก่อน

Step 3: ตรวจสอบ VLAN และ Access Port

หาก Physical Link ปกติ ให้ตรวจสอบ VLAN

Switch# show vlan brief

ตรวจสอบว่า:

  • VLAN มีอยู่จริงหรือไม่
  • Access Port อยู่ VLAN ถูกต้องหรือไม่
  • Port ถูกกำหนดเป็น Access หรือ Trunk ถูกต้องหรือไม่

ดู Switchport:

Switch# show interfaces gigabitEthernet 1/0/5 switchport

Configuration ที่คาดหวัง:

interface gigabitEthernet 1/0/5
 switchport mode access
 switchport access vlan 10

หาก PC ควรอยู่ VLAN 10 แต่ Port อยู่ VLAN 20 Client อาจได้รับ IP หรือ Gateway คนละ Network กับที่ออกแบบไว้

Step 4: ตรวจสอบ MAC Address Table

Switch ต้องเรียนรู้ Source MAC Address ของ Endpoint บน Interface ที่เหมาะสม

Switch# show mac address-table

หรือค้นหา MAC เฉพาะ:

Switch# show mac address-table address aaaa.bbbb.cccc

แนวคิด:

PC
MAC AAAA.BBBB.CCCC
       |
       v
     Gi1/0/5
       |
       v
MAC Address Table

VLAN 10
AAAA.BBBB.CCCC
Gi1/0/5

หากไม่พบ MAC ควรย้อนกลับไปตรวจ Physical Connection, NIC, VLAN และ Interface State

หาก MAC Address เดียวกัน ปรากฏสลับไปมาระหว่าง Ports อาจต้องตรวจสอบ Layer 2 Loop หรือ Topology เพิ่มเติม

Step 5: ตรวจสอบ Trunk

ถ้า Client อยู่บน Access Switch แต่ Gateway อยู่บน Layer 3 Switch อีกตัว Traffic ของ VLAN อาจต้องผ่าน Trunk

Access Switch
      |
      | Trunk
      |
Layer 3 Switch

ตรวจสอบ:

Switch# show interfaces trunk

ดูว่า:

  • Port เป็น Trunk จริงหรือไม่
  • VLAN ที่ต้องการถูก Allow หรือไม่
  • Native VLAN สอดคล้องกันหรือไม่
  • Trunk Operational State ถูกต้องหรือไม่

ตัวอย่าง:

interface gigabitEthernet 1/0/24
 switchport mode trunk
 switchport trunk allowed vlan 10,20,30,99

หาก VLAN 10 ไม่ได้อยู่ใน Allowed VLAN List Traffic ของ VLAN 10 จะไม่เดินทางผ่าน Trunk ตามที่คาด

Step 6: ตรวจสอบ STP / RSTP

Spanning Tree อาจทำให้ Port บางเส้นทาง ไม่อยู่ใน Forwarding State เพื่อป้องกัน Layer 2 Loop

Switch# show spanning-tree

หรือ:

Switch# show spanning-tree vlan 10

ตรวจสอบ:

  • Root Bridge
  • Root Port
  • Designated Port
  • Alternate/Blocking หรือ Discarding Path
  • Topology Change
Port ที่ STP ไม่ Forward ไม่ได้หมายความว่า Network เสียเสมอไป อาจเป็นพฤติกรรมที่ถูกต้อง เพื่อป้องกัน Layer 2 Loop

Step 7: ตรวจสอบ EtherChannel

หาก Uplink ใช้ EtherChannel ควรตรวจสอบว่า Member Links รวมเป็น Port-Channel ถูกต้องหรือไม่

Switch# show etherchannel summary

ตรวจสอบ Configuration ของ Physical Interfaces และ Port-Channel:

Switch# show running-config interface port-channel 1

และ:

Switch# show interfaces port-channel 1

ปัญหาที่ควรตรวจสอบ ได้แก่:

  • LACP/PAgP Mode ไม่เข้ากัน
  • Trunk Configuration ไม่สอดคล้อง
  • Allowed VLAN ไม่ตรงกัน
  • Physical Member มีปัญหา

ภาค 3: IP Address และ Layer 3 Troubleshooting

Step 8: ตรวจสอบ DHCP

หลัง Layer 1 และ Layer 2 ดูปกติแล้ว ตรวจสอบ IP Configuration ของ Client

Windows:

ipconfig /all

ตรวจสอบ:

  • IPv4 Address
  • Subnet Mask
  • Default Gateway
  • DHCP Server
  • DNS Server

หาก Windows Client มี Address ลักษณะ:

169.254.x.x

อาจเป็น APIPA ซึ่งเป็นหนึ่งในสัญญาณว่า Client ไม่ได้รับ IPv4 Configuration จาก DHCP ตามที่คาด

ทดสอบ Renew:

ipconfig /release
ipconfig /renew

Cisco:

Switch# show ip dhcp snooping
Switch# show ip dhcp snooping binding

หาก Cisco Device ทำ DHCP Server:

Router# show ip dhcp binding
Router# show ip dhcp pool

หากใช้ DHCP Relay ตรวจ SVI:

Switch# show running-config interface vlan 10

ควรพบ Configuration ที่เหมาะสม เช่น:

interface vlan 10
 ip address 192.168.10.1 255.255.255.0
 ip helper-address 10.10.10.20

Step 9: ตรวจสอบ ARP

Client มี IP ถูกต้อง แต่ติดต่อ Gateway ไม่ได้ ควรตรวจ ARP

Windows:

arp -a

Cisco Layer 3 Device:

Switch# show ip arp

ตรวจว่า IP ของ Gateway สัมพันธ์กับ MAC Address ที่คาดไว้หรือไม่

หากเปิด DAI:

Switch# show ip arp inspection
Switch# show ip arp inspection statistics

และตรวจ DHCP Snooping Binding:

Switch# show ip dhcp snooping binding

Step 10: ตรวจสอบ Default Gateway

สมมติ Client:

IP
192.168.10.100

Mask
255.255.255.0

Gateway
192.168.10.1

เริ่มทดสอบ Gateway:

ping 192.168.10.1

หาก Ping Gateway ไม่ผ่าน ควรเน้นตรวจ:

  • VLAN
  • Trunk
  • SVI
  • ARP
  • STP
  • IPSG
  • DAI
  • ACL

แต่ต้องระวังว่า บางอุปกรณ์หรือ Security Policy อาจ Block ICMP ดังนั้น Ping Failure ไม่สามารถพิสูจน์เพียงอย่างเดียว ว่า Destination ล่ม

Step 11: ตรวจสอบ Routing

ตรวจ Routing Table:

Switch# show ip route

ตรวจว่า:

  • Connected Route มีหรือไม่
  • Route ไป Destination มีหรือไม่
  • Default Route มีหรือไม่ หาก Design ต้องใช้
  • Next Hop ถูกต้องหรือไม่

ตัวอย่าง:

C    192.168.10.0/24 is directly connected, Vlan10
C    192.168.20.0/24 is directly connected, Vlan20

หากใช้ Layer 3 Switch สำหรับ Inter-VLAN Routing ตรวจว่าเปิด Routing ตาม Design:

Switch# show running-config | include ip routing

Configuration:

ip routing

ภาค 4: Security Feature Troubleshooting

Step 12: ตรวจสอบ Layer 2 Security

Network อาจมี Physical, VLAN และ Routing ถูกต้อง แต่ Security Feature กำลัง Block Traffic

DHCP Snooping

show ip dhcp snooping
show ip dhcp snooping binding

Dynamic ARP Inspection

show ip arp inspection
show ip arp inspection statistics

IP Source Guard

show ip source binding

ตรวจ Interface:

show running-config interface gigabitEthernet 1/0/5

Port Security

show port-security
show port-security interface gigabitEthernet 1/0/5
show port-security address

802.1X

ขึ้นอยู่กับ Platform เช่น:

show authentication sessions

หรือ:

show access-session
อย่าแก้ปัญหาโดยปิด Security Feature ทั้งหมดทันทีใน Production เพราะอาจเปิดช่องทางที่ Policy ตั้งใจป้องกันไว้ ควรตรวจ Log, Binding และ Policy เพื่อหาสาเหตุที่แท้จริงก่อน

Step 13: ตรวจสอบ ACL

หาก Routing ถูกต้อง แต่ Service บางประเภทใช้งานไม่ได้ ACL เป็นอีกจุดที่ควรตรวจสอบ

Switch# show ip access-lists

ตรวจ Interface:

Switch# show ip interface vlan 10

ดูว่า ACL ถูก Apply:

Inbound?

Outbound?

Interface ถูกต้อง?

ตรวจ ACE:

Rule Order
 |
 +-- Permit?
 |
 +-- Deny?
 |
 +-- Wildcard correct?
 |
 +-- Protocol correct?
 |
 +-- Port correct?
 |
 +-- Implicit Deny?

ตัวอย่างปัญหา:

deny ip 192.168.10.0 0.0.0.255 any

permit tcp 192.168.10.0 0.0.0.255 host 192.168.20.10 eq 443

Permit Rule ด้านล่าง จะไม่ช่วย HTTPS Traffic ที่ถูก Match และ Deny โดย Rule ด้านบนไปแล้ว

ภาค 5: DNS และ Application Troubleshooting

Step 14: ตรวจสอบ DNS และ Application

กรณีที่:

ping 8.8.8.8

ใช้งานได้

แต่

เข้าเว็บไซต์ด้วยชื่อไม่ได้

ควรตรวจสอบ DNS เป็นหนึ่งในลำดับต้น ๆ

Windows:

ipconfig /all
nslookup example.com

หาก DNS Resolution ล้มเหลว แต่ IP Connectivity ใช้งานได้ ปัญหาอาจอยู่ที่:

  • DNS Server
  • DNS Configuration
  • ACL / Firewall สำหรับ DNS
  • DNS Service
  • Application Configuration

ในทางกลับกัน หาก DNS Resolve ได้ แต่ Application ยังใช้งานไม่ได้ ควรตรวจสอบ TCP/UDP Port, Firewall, Proxy, TLS, Application Server และ Service Health ต่อ

ใช้ Ping อย่างถูกวิธี

แทนที่จะ Ping Destination ไกล ๆ ทันที ควรทดสอบเป็นลำดับ

Step 1
127.0.0.1
   |
   v
Local TCP/IP Stack

Step 2
Own IP
   |
   v
Local Interface

Step 3
Default Gateway
   |
   v
Local Network

Step 4
Remote IP
   |
   v
Routing / Upstream

Step 5
Domain Name
   |
   v
DNS + Connectivity

ตัวอย่าง:

ping 127.0.0.1

ping 192.168.10.100

ping 192.168.10.1

ping 8.8.8.8

ping example.com
ICMP อาจถูก Block โดย Firewall หรือ Security Policy ดังนั้น Ping เป็น Diagnostic Signal ไม่ใช่ข้อพิสูจน์เพียงอย่างเดียว ของ Service Availability

Traceroute / Tracert ใช้เมื่อไร?

เมื่อ Destination อยู่หลาย Hop Traceroute ช่วยให้เห็นเส้นทาง ในระดับหนึ่ง

Windows:

tracert 8.8.8.8

Cisco:

Router# traceroute 8.8.8.8

แนวคิด:

PC
 |
 v
Gateway
 |
 v
Router A
 |
 v
Router B
 |
 v
Destination

หากบาง Hop ไม่ตอบ ไม่ได้แปลว่า Hop นั้นเสียเสมอไป เพราะอุปกรณ์อาจจำกัด หรือไม่ตอบ Probe แต่ยัง Forward Traffic ได้

ภาค 6: Troubleshooting Scenario

สถานการณ์: PC ใน VLAN 10 เข้า Server ไม่ได้

Topology:

PC-A
192.168.10.100
VLAN 10
   |
   |
Access Switch
   |
   | Trunk
   |
Layer 3 Switch
   |
   |
VLAN 20
   |
Server
192.168.20.10

อาการ:

PC-A

เข้า Server
192.168.20.10

ไม่ได้

Step A — ตรวจ PC

ipconfig /all

ควรตรวจ:

IP       192.168.10.100
Mask     255.255.255.0
Gateway  192.168.10.1

Step B — ตรวจ Physical Port

show interfaces status

Step C — ตรวจ VLAN

show vlan brief

PC Port ต้องอยู่ VLAN 10

Step D — ตรวจ MAC

show mac address-table

ควรพบ MAC ของ PC ใน VLAN 10 บน Port ที่ถูกต้อง

Step E — ตรวจ Trunk

show interfaces trunk

VLAN 10 และ VLAN 20 ต้องผ่านเส้นทางที่ Design กำหนด

Step F — Ping Gateway

ping 192.168.10.1

Step G — ตรวจ SVI

show ip interface brief

ควรเห็น:

Vlan10  192.168.10.1
Vlan20  192.168.20.1

Step H — ตรวจ Routing

show ip route

Step I — ตรวจ ARP

show ip arp

Step J — ตรวจ Security Bindings

show ip dhcp snooping binding
show ip arp inspection
show ip source binding

Step K — ตรวจ ACL

show ip access-lists
show ip interface vlan 10
show ip interface vlan 20

Step L — ตรวจ Server

หาก Network Path ถูกต้อง ให้ตรวจ:

  • Server IP
  • Server Gateway
  • Host Firewall
  • Application Service
  • TCP/UDP Port

นี่คือประโยชน์ของ Structured Troubleshooting: เราไม่ต้องเดาว่า “Switch เสียหรือ Server เสีย” แต่ค่อย ๆ ตัด Possible Causes ออกทีละส่วน

Cisco Network Troubleshooting Commands

สิ่งที่ตรวจสอบ Command
Interface Status show interfaces status
Interface Detail show interfaces
IP Interface show ip interface brief
VLAN show vlan brief
Switchport show interfaces ... switchport
MAC Table show mac address-table
Trunk show interfaces trunk
STP show spanning-tree
EtherChannel show etherchannel summary
DHCP Snooping show ip dhcp snooping
DHCP Binding show ip dhcp snooping binding
Cisco DHCP Server show ip dhcp binding
ARP show ip arp
DAI show ip arp inspection
IP Source Binding show ip source binding
Port Security show port-security
Routing show ip route
ACL show ip access-lists
Configuration show running-config
Logs show logging
Connectivity ping
Path traceroute

Network Troubleshooting Checklist

เมื่อต้องแก้ปัญหา สามารถใช้ Checklist นี้ เป็นลำดับเริ่มต้น:

[01] Physical cable / link OK?
             |
             v
[02] Interface up?
             |
             v
[03] Correct VLAN?
             |
             v
[04] MAC learned?
             |
             v
[05] Trunk carries VLAN?
             |
             v
[06] STP path correct?
             |
             v
[07] EtherChannel healthy?
             |
             v
[08] Correct IP / Mask?
             |
             v
[09] DHCP working?
             |
             v
[10] ARP correct?
             |
             v
[11] Gateway reachable?
             |
             v
[12] Route exists?
             |
             v
[13] DHCP Snooping / DAI / IPSG OK?
             |
             v
[14] Port Security / 802.1X OK?
             |
             v
[15] ACL permits traffic?
             |
             v
[16] Firewall permits traffic?
             |
             v
[17] DNS working?
             |
             v
[18] Application service running?
หลักสำคัญ: ทุกครั้งที่พบจุดผิดปกติ ควรพิสูจน์ให้ได้ว่าจุดนั้น สัมพันธ์กับอาการจริงหรือไม่ ก่อนเปลี่ยน Configuration

แก้ Configuration อย่างไรให้ปลอดภัย?

การ Troubleshoot ที่ดี ไม่ได้หมายถึงเพียงหาสาเหตุได้ แต่ต้องลดความเสี่ยง จากการแก้ไขด้วย

ก่อน Change ควรบันทึก:

1. Problem
2. Current State
3. Evidence
4. Suspected Cause
5. Planned Change
6. Expected Result
7. Verification
8. Rollback Plan

ตัวอย่าง:

Problem:
VLAN 10 ใช้งาน Server ไม่ได้

Evidence:
VLAN 10 missing from trunk allowed list

Change:
Add VLAN 10 to intended trunk

Expected:
VLAN 10 reaches L3 switch

Verify:
show interfaces trunk
ping gateway
test application

Rollback:
Restore previous allowed VLAN configuration
บน Production Network ควรหลีกเลี่ยงการใช้คำสั่ง ที่เปลี่ยน Configuration เพียงเพื่อ “ลองดูว่าจะหายหรือไม่” โดยไม่มี Baseline, Impact Assessment และ Rollback Plan

คำถามที่พบบ่อย — FAQ

Network ใช้งานไม่ได้ ควรตรวจอะไรเป็นอย่างแรก?

หากยังไม่มีหลักฐานชี้ไปยังสาเหตุเฉพาะ เริ่มจาก Physical Connection, Interface State และ IP Configuration เป็นจุดเริ่มต้นที่เหมาะสม ก่อนขยับไปยัง VLAN, Routing และ Security Policy

ทำไมต้องตรวจ VLAN ก่อน Routing?

เพราะหาก Endpoint อยู่ผิด VLAN Traffic อาจไม่ไปถึง Layer 3 Gateway ที่ถูกต้องตั้งแต่แรก

Client ได้ 169.254.x.x หมายความว่าอะไร?

บน Windows IPv4 อาจเป็น APIPA ซึ่งมักพบเมื่อ Client ไม่ได้รับ DHCP Configuration ตามที่คาด จึงควรตรวจ DHCP Path, VLAN, Trunk, Relay และ DHCP Snooping

Ping Gateway ไม่ได้ แปลว่า Gateway เสียหรือไม่?

ไม่จำเป็น สาเหตุอาจอยู่ที่ VLAN, Trunk, ARP, SVI, STP, Security Feature, ACL หรือ ICMP Policy จึงต้องตรวจสอบข้อมูลอื่นประกอบ

Ping IP ได้ แต่เข้าเว็บไซต์ไม่ได้ เกิดจากอะไร?

อาจเกี่ยวข้องกับ DNS, Firewall, Proxy, TCP/UDP Port, TLS หรือ Application Service ขึ้นอยู่กับอาการจริง

MAC Address Table กับ ARP Table ต่างกันอย่างไร?

MAC Address Table ใช้ Mapping MAC Address กับ Switch Port ส่วน ARP Table ใช้ Mapping IPv4 Address กับ MAC Address ของ Neighbor/Next Hop

Trunk Up แต่ VLAN ใช้งานไม่ได้ เกิดจากอะไร?

ควรตรวจ Allowed VLAN, VLAN existence, STP State, Native VLAN, VLAN Configuration ที่ปลายทั้งสองด้าน และ Topology ที่เกี่ยวข้อง

Routing Table มี Route แล้ว แต่ยังเข้าไม่ได้ เกิดจากอะไร?

อาจเกิดจาก Return Route, ARP, ACL, Firewall, Security Policy, Destination Host หรือ Application Service จึงไม่ควรสรุปจาก Routing Table เพียงอย่างเดียว

ควรปิด ACL หรือ Security Feature เพื่อทดสอบหรือไม่?

บน Production Network ไม่ควรปิด Security Control แบบกว้างโดยไม่มีการประเมินผลกระทบ ควรตรวจ Counter, Log, Binding และ Configuration เพื่อหาจุดที่ Block Traffic ก่อน

คำสั่ง Cisco ที่ควรจำมากที่สุดสำหรับ Troubleshooting คืออะไร?

กลุ่มคำสั่งพื้นฐานที่ใช้บ่อย ได้แก่ show interfaces status, show vlan brief, show mac address-table, show interfaces trunk, show spanning-tree, show ip interface brief, show ip arp, show ip route และ show ip access-lists

สรุป

การแก้ปัญหา Network ไม่ควรเริ่มจากการเดาว่า Switch, Router, Firewall หรือ Server ตัวใดเสีย แต่ควรเริ่มจากการรวบรวมอาการ และตรวจสอบ Network อย่างเป็นลำดับ

สำหรับ Cisco Network พื้นฐาน สามารถใช้ Workflow:

Physical
   |
   v
Interface
   |
   v
VLAN
   |
   v
MAC Table
   |
   v
Trunk
   |
   v
STP / EtherChannel
   |
   v
DHCP
   |
   v
ARP
   |
   v
Gateway
   |
   v
Routing
   |
   v
Layer 2 Security
   |
   v
ACL / Firewall
   |
   v
DNS
   |
   v
Application

เมื่อพบความผิดปกติ ควรเก็บ Evidence เปรียบเทียบกับ Baseline ระบุ Possible Cause และทดสอบสมมติฐาน ก่อนเปลี่ยน Configuration

แนวทางนี้ทำให้ความรู้จาก VLAN, Trunk, STP, EtherChannel, DHCP, ARP, DAI, IP Source Guard, Port Security, 802.1X, Routing และ ACL ไม่ได้เป็นหัวข้อแยกจากกัน แต่กลายเป็น Network Troubleshooting Workflow ที่นำไปใช้แก้ปัญหาได้จริง

หลังจากจบบทนี้ ลำดับต่อไปเหมาะกับการขยับจาก Switching & LAN Security เข้าสู่ Routing Fundamentals: Static Route, Default Route และ Dynamic Routing เพื่อเรียนรู้การเชื่อมต่อ หลาย Network และหลาย Router ในระดับที่สูงขึ้น

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.