Techerest

HSRP Tracking, IP SLA และ Object Tracking บน Cisco คืออะไร? พร้อม Lab

HSRP สามารถสร้าง Default Gateway สำรองได้ แต่การมี Router สองตัวไม่ได้หมายความว่า ระบบจะตรวจพบความเสียหายของเส้นทางทุกประเภท โดยอัตโนมัติ เพราะบางครั้ง Active Router และ Interface ยัง Up แต่เส้นทางไป Core, WAN หรือ Internet ใช้งานไม่ได้ จึงต้องใช้ Tracking, IP SLA และ Object Tracking ช่วยตรวจสอบความพร้อมใช้งานของ Path

บทความนี้ต่อยอดจากพื้นฐาน HSRP และ VRRP โดยอธิบายตั้งแต่ Interface Tracking, Object Tracking, IP SLA, HSRP Priority Decrement, Failover และ Failback ไปจนถึง Cisco Lab และ Troubleshooting สำหรับออกแบบ Gateway Redundancy ให้ตรวจสอบได้มากกว่าแค่สถานะ Interface

ภาค 1: ทำไม HSRP ต้องมี Tracking?

ปัญหาที่ HSRP พื้นฐานอาจตรวจไม่พบ

จากบทความก่อนหน้า สมมติเรามี Router สองตัว:

                Internet
                /      \
               /        \
             R1          R2
              \          /
               \        /
                Switch
                  |
                Hosts

Virtual Gateway
192.168.10.1

กำหนด:

R1
LAN IP     = 192.168.10.2
Priority   = 110
Role       = Active

R2
LAN IP     = 192.168.10.3
Priority   = 100
Role       = Standby

Virtual IP = 192.168.10.1

หาก R1 ดับทั้งเครื่อง หรือ LAN Interface ของ R1 Down HSRP สามารถเปลี่ยนบทบาท ไปยัง R2 ได้ตามเงื่อนไข

แต่ลองเปลี่ยน Failure Scenario:

                    Internet
                       |
                       X
                       |
                 Upstream/Core
                       |
                       |
                  Gi0/1 = UP
                       |
                      R1
                 HSRP Active
                       |
                  Gi0/0 = UP
                       |
                     LAN

Physical Interface ของ R1 อาจยังรายงานว่า up/up

HSRP ฝั่ง LAN จึงอาจยังเห็น R1 เป็น Active Router ทั้งที่ R1 ไม่สามารถส่ง Traffic ไปยังปลายทางสำคัญได้จริง

Interface Up ไม่เท่ากับ Path Reachable
Link Layer สามารถทำงานปกติ ในขณะที่ปัญหาเกิดอยู่ถัดออกไป หลาย Hop ได้

Tracking คืออะไร?

Tracking คือกลไกที่ใช้ติดตาม สถานะของ Resource หรือเงื่อนไขบางอย่าง แล้วนำผลลัพธ์นั้นไปมีอิทธิพล ต่อ Feature อื่น

แนวคิดทั่วไป:

Something being monitored
          |
          v
       Tracking
          |
          v
     UP or DOWN
          |
          v
Another feature reacts

สำหรับ HSRP:

Track condition
      |
      v
UP -------- DOWN
             |
             v
       Reduce HSRP
         Priority
             |
             v
      Another router
      may become Active

ภาค 2: Interface Tracking

Interface Tracking คืออะไร?

วิธีพื้นฐานคือ ให้ HSRP ติดตามสถานะ ของ Uplink Interface

ตัวอย่าง:

                Core
                 |
                 |
               Gi0/1
                 |
                R1
           Priority 110
                 |
               Gi0/0
                 |
                LAN

หาก Gi0/1 Down ให้ลด Priority ของ R1

Normal:

R1 Priority = 110
R2 Priority = 100

R1 = Active


Gi0/1 DOWN:

R1 Priority
110 - 20 = 90

R2 Priority = 100

R2 now has
higher priority

ตัวอย่าง Configuration

interface GigabitEthernet0/0
 ip address 192.168.10.2 255.255.255.0
 standby 10 ip 192.168.10.1
 standby 10 priority 110
 standby 10 preempt
 standby 10 track GigabitEthernet0/1 20

เมื่อ Uplink ที่ Track เปลี่ยนเป็น Down HSRP Priority ของ R1 จะถูกลดตามค่าที่กำหนด

รูปแบบคำสั่ง Tracking แตกต่างได้ตาม Cisco Platform และ IOS/IOS XE Release บาง Platform ใช้ Track Object แทนการอ้าง Interface จากคำสั่ง HSRP โดยตรง

ข้อจำกัดของ Interface Tracking

Interface Tracking เหมาะกับ Failure ที่ทำให้ Interface State เปลี่ยนจริง

เช่น:

Cable disconnected

Transceiver failure

Physical link down

Directly connected device down

แต่มี Failure อีกประเภท:

R1
 |
 | Gi0/1 = UP
 |
SW1
 |
 | Link = UP
 |
Core
 |
 X
 |
Internet

R1 ยังเห็น:

GigabitEthernet0/1
Status: up
Protocol: up

Interface Tracking จึงอาจไม่ตรวจพบ ปัญหาที่เกิดลึกเข้าไปใน Network

จุดนี้เป็นเหตุผลที่ต้องมี IP SLA

ภาค 3: Object Tracking และ IP SLA

Object Tracking คืออะไร?

Object Tracking ช่วยสร้าง Tracking Object ที่ Feature อื่นสามารถนำไปใช้ได้

แนวคิด:

Interface
Route
IP SLA
Other supported condition
        |
        v
   Track Object
        |
        v
      State
    UP / DOWN
        |
        +----------------+
        |                |
        v                v
      HSRP          Other features

แทนที่จะให้ HSRP ตรวจ Interface เพียงอย่างเดียว เราสามารถให้ HSRP อ้างอิง Track Object ที่สะท้อน Reachability ของ Network ได้

IP SLA คืออะไร?

IP SLA เป็นความสามารถบน Cisco สำหรับสร้าง Active Probe เพื่อวัดหรือตรวจสอบ Network Reachability และ Performance ตาม Operation ที่ Platform รองรับ

ตัวอย่างง่ายคือ ICMP Echo:

R1
 |
 | ICMP Echo Probe
 |
 +--------------------> Target
                         10.0.0.1

Response?
   |
   +-- YES --> Reachable
   |
   +-- NO  --> Probe failure

จากนั้นนำผลของ IP SLA ไปผูกกับ Object Tracking

IP SLA
  |
  v
Track Object
  |
  v
HSRP

IP SLA + Track + HSRP ทำงานอย่างไร?

ลำดับการทำงาน:

Step 1
IP SLA sends probe
       |
       v
Step 2
Target reachable?
       |
    +--+--+
    |     |
   YES    NO
    |     |
    v     v
Track    Track
 UP      DOWN
           |
           v
Step 3
HSRP sees Track DOWN
           |
           v
Step 4
Priority decreases
           |
           v
Step 5
Standby has higher priority
           |
           v
Step 6
Failover can occur

ทำให้ Failover Decision ไม่ได้อาศัยเพียง Physical Interface State

Priority Decrement ต้องคำนวณให้ถูก

สมมติ:

R1 Priority = 110
R2 Priority = 100

ถ้า Track Down แล้วลด R1 เพียง 5:

110 - 5 = 105

ผลคือ:

R1 = 105
R2 = 100

R1 ยังมี Priority สูงกว่า R2 ดังนั้น Design อาจไม่ทำงาน ตามที่ต้องการ

ถ้าลด 20:

110 - 20 = 90

จะได้:

R1 = 90
R2 = 100

R2 จึงมี Priority สูงกว่า หลัง Track Failure

หลักสำคัญ:
Priority Decrement ต้องมากพอที่จะทำให้ Priority หลัง Failure ต่ำกว่า Router สำรอง หากนั่นคือ Failover Behavior ที่ออกแบบไว้

ภาค 4: Cisco Lab — Interface Tracking

Lab 1: HSRP Interface Tracking

Topology:

                  Core
                 /    \
                /      \
             Gi0/1    Gi0/1
               |        |
              R1        R2
               |        |
             Gi0/0    Gi0/0
                \      /
                 \    /
                 SW1
                  |
                PC-A

Addressing:

LAN:
192.168.10.0/24

Virtual Gateway:
192.168.10.1

R1:
192.168.10.2

R2:
192.168.10.3

R1

interface GigabitEthernet0/0
 description LAN
 ip address 192.168.10.2 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 110
 standby 10 preempt
 standby 10 track GigabitEthernet0/1 20
 no shutdown

R2

interface GigabitEthernet0/0
 description LAN
 ip address 192.168.10.3 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 100
 standby 10 preempt
 no shutdown

ตรวจสถานะ

show standby brief
show standby
show ip interface brief

Normal:

R1 Priority 110
Active

R2 Priority 100
Standby

เมื่อ R1 Uplink Down:

R1 Priority
110 - 20
= 90

R2 Priority
= 100

R2 สามารถรับ Active Role ตาม Election และ Preemption ที่กำหนด

ภาค 5: Cisco Lab — IP SLA + Object Tracking

Lab 2: ตรวจ Remote Reachability

Topology:

                   Target
                  10.0.0.1
                     |
                  Network
                  /      \
                 /        \
                R1        R2
                 \        /
                  \      /
                   SW1
                    |
                  PC-A

Virtual Gateway:
192.168.10.1

ต้องการให้ R1 เป็น Active เฉพาะเมื่อ R1 สามารถ Reach Target 10.0.0.1 ตามเงื่อนไข Probe

Step 1 — สร้าง IP SLA

ip sla 10
 icmp-echo 10.0.0.1 source-interface GigabitEthernet0/1
 frequency 5

Step 2 — เริ่ม Schedule

ip sla schedule 10 life forever start-time now

Step 3 — สร้าง Track Object

track 10 ip sla 10 reachability

Step 4 — ผูก Track กับ HSRP

interface GigabitEthernet0/0
 ip address 192.168.10.2 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 110
 standby 10 preempt
 standby 10 track 10 decrement 20
 no shutdown

Flow ที่เกิดขึ้น

IP SLA 10
ICMP Echo 10.0.0.1
       |
       v
Target responds?
       |
  +----+----+
  |         |
 YES        NO
  |         |
  v         v
Track 10   Track 10
UP         DOWN
             |
             v
HSRP Priority
110 -> 90
             |
             v
R2 Priority 100
becomes preferred

ตรวจ IP SLA และ Track Object

คำสั่งสำคัญ:

show ip sla configuration
show ip sla statistics
show track
show standby brief
show standby

การ Troubleshoot ควรตรวจ จากต้นเหตุไปปลายเหตุ:

IP SLA working?
       |
       v
Track state correct?
       |
       v
Priority changed?
       |
       v
HSRP state changed?
       |
       v
Traffic changed path?

เลือก IP SLA Target อย่างไร?

Target ที่เลือกมีผลโดยตรง ต่อความหมายของคำว่า “Path ใช้งานได้”

ตัวอย่าง:

Target สิ่งที่ตรวจได้ ข้อจำกัด
Next-Hop Router ตรวจ First Upstream Hop ไม่ได้พิสูจน์ว่า Remote Network ใช้งานได้
Core Router ตรวจเส้นทางลึกขึ้นในองค์กร ไม่ได้พิสูจน์ Internet/Application ทั้งหมด
Remote Site Router ตรวจ WAN Reachability ไป Site นั้น ขึ้นกับความเสถียรของ Remote Target
External IP ตรวจ Reachability ออกนอกระบบบางส่วน Target ภายนอกอาจล่มหรือ Filter ICMP เอง
อย่าเลือก Public Server แบบสุ่มมาเป็น Critical IP SLA Target เพราะ Failover ของ Network ไม่ควรขึ้นอยู่กับบริการภายนอก ที่เราไม่ได้ควบคุม

ภาค 6: ป้องกัน Route และ Gateway Flapping

Tracking Delay สำคัญอย่างไร?

สมมติ WAN Link มี Packet Loss ชั่วคราว:

UP
 |
DOWN
 |
UP
 |
DOWN
 |
UP

หาก Tracking เปลี่ยน State ทันทีทุกครั้ง HSRP อาจเกิด:

R1 Active
   |
   v
R2 Active
   |
   v
R1 Active
   |
   v
R2 Active

เรียกว่า Gateway Flapping ซึ่งอาจสร้างผลกระทบ มากกว่าความเสียหายระยะสั้น ที่กำลังตรวจพบ

Object Tracking บน Platform ที่รองรับสามารถมีแนวคิด Delay Up/Down เพื่อป้องกันการเปลี่ยน State จากเหตุการณ์ชั่วคราว

ตัวอย่างแนวคิด:

track 10 ip sla 10 reachability
 delay down 10 up 30

ความหมายเชิงออกแบบ:

Failure detected
      |
      v
Wait before declaring DOWN
      |
      v
Persistent?
  |
 YES
  |
  v
DOWN


Recovery detected
      |
      v
Wait longer
      |
      v
Stable?
  |
 YES
  |
  v
UP
Syntax และ Delay Support ขึ้นอยู่กับ Cisco Platform และ Software Release ควรตรวจ Documentation ของอุปกรณ์จริงก่อนนำไปใช้

Preempt Delay

อีกแนวคิดหนึ่งคือ ไม่ควรให้ Router รีบกลับมา Active ทันทีหลัง Boot

Router boots
     |
     v
LAN interface UP
     |
     v
Routing still converging
     |
     v
HSRP preempts too early
     |
     v
Possible traffic loss

ในบาง Design สามารถใช้ Preempt Delay เพื่อให้เวลา Routing, Interfaces และ Services เข้าสู่สภาวะพร้อมก่อน

ตัวอย่าง:

standby 10 preempt delay minimum 60

แนวคิดคือรอช่วงเวลาที่กำหนด ก่อน Preempt แทนการกลับมา Active ทันที

ภาค 7: HSRP Tracking กับ OSPF

HSRP และ OSPF มอง Failure คนละมุม

Topology:

              Core Network
              /          \
             /            \
           R1 ------------ R2
            \              /
             \            /
              ---- LAN ----
                   |
             Virtual Gateway

OSPF รับผิดชอบ Router-to-Router Routing

HSRP รับผิดชอบ Host-to-Gateway Redundancy

OSPF
 |
 +-- Which route should router use?


HSRP
 |
 +-- Which router should host use
     through the Virtual Gateway?

Tracking ทำหน้าที่เชื่อม Operational State บางส่วน เข้ากับ HSRP Decision

ตัวอย่าง Failure

          Core
         /    \
        X      |
        |      |
       R1     R2
        \      /
         \    /
          LAN

OSPF บน R1 อาจเปลี่ยน Routing Table เมื่อเส้นทางหนึ่งหาย

แต่ถ้า R1 ยังสามารถ Forward ผ่านเส้นทางสำรองได้ อาจไม่มีเหตุผลให้ HSRP ต้อง Failover

ไม่ควรออกแบบให้ “Uplink ใด Uplink หนึ่งเสีย = HSRP ต้อง Failover” โดยอัตโนมัติเสมอไป หาก Router ยังมี Alternate Route ที่ใช้งานได้ การ Failover Gateway อาจไม่จำเป็น

ควร Track Interface, Route หรือ Reachability?

วิธี เหมาะกับ ข้อจำกัด
Interface Tracking ตรวจ Direct Link Failure มองไม่เห็น Failure ที่อยู่ไกลออกไป
Route Tracking ตรวจว่ามี Route สำคัญอยู่หรือไม่ Route มีอยู่ไม่ได้รับประกัน End-to-End Reachability
IP SLA Tracking ตรวจ Active Reachability ต้องเลือก Probe/Target ให้เหมาะสม

ไม่มีวิธีใดดีที่สุด สำหรับทุก Network

ต้องเลือกตาม Failure Condition ที่ต้องการตรวจจริง

ภาค 8: ทดสอบ Failover อย่างเป็นระบบ

Failover Test Plan

ก่อนทดสอบควรบันทึก Baseline:

show standby brief
show track
show ip sla statistics
show ip route
show ip interface brief

Test 1 — Normal State

คาดหวัง:

IP SLA = OK
Track 10 = UP

R1 Priority = 110
R1 = Active

R2 Priority = 100
R2 = Standby

Test 2 — Uplink Interface Failure

ใน Lab จำลอง Uplink Down

ตรวจ:

show track
show standby brief

Test 3 — Remote Path Failure

จำลองให้ IP SLA Target ไม่สามารถ Reach ได้ โดยที่ Local Interface ยังคง Up

คาดหวัง:

Interface = UP

but

IP SLA = Failure
       |
       v
Track = DOWN
       |
       v
Priority = 90
       |
       v
R2 becomes preferred

Test 4 — Recovery

คืน Path กลับ:

IP SLA succeeds
       |
       v
Track UP
       |
       v
R1 Priority 110
       |
       v
Preempt conditions
       |
       v
R1 may become Active again

ต้องตรวจด้วยว่า Traffic ใช้งานได้จริง ไม่ใช่ดูเพียง HSRP State

ภาค 9: Troubleshooting

IP SLA ทำงาน แต่ HSRP ไม่ Failover

ตรวจตามลำดับ:

show ip sla statistics
        |
        v
IP SLA failed?
        |
        v
show track
        |
        v
Track DOWN?
        |
        v
show standby
        |
        v
Priority decreased?
        |
        v
Is new priority below peer?
        |
        v
Preemption/election conditions correct?

ปัญหา 1 — IP SLA ยัง Success ทั้งที่คิดว่า Path เสีย

ตรวจ:

  • Target ถูกต้องหรือไม่
  • Source Interface ถูกต้องหรือไม่
  • มี Alternate Path หรือไม่
  • Probe วิ่งออก Path ที่คาดหรือไม่
  • Target ตอบ Probe จริงหรือไม่

ปัญหา 2 — Track DOWN แต่ Priority ยังสูงกว่า Standby

ตัวอย่าง:

R1:
110 - 5 = 105

R2:
100

แม้ Tracking ทำงานถูกต้อง แต่ Decrement ไม่เพียงพอ

ปัญหา 3 — Priority ต่ำกว่าแล้ว แต่ Role ไม่เปลี่ยนตามที่คาด

ตรวจ:

  • Preempt Configuration
  • HSRP Group
  • HSRP Version
  • Peer State
  • Current Priority
  • Timers
  • Layer 2 Connectivity

ปัญหา 4 — HSRP Failover สำเร็จ แต่ Internet ยังไม่ได้

แสดงว่า FHRP อาจไม่ได้เป็น Root Cause ทั้งหมด

New Active
   |
   v
Routing Table?
   |
   v
Default Route?
   |
   v
NAT?
   |
   v
Firewall?
   |
   v
WAN?
   |
   v
Return Path?

ปัญหา 5 — Failover ไปมา

ตรวจ:

  • Packet Loss
  • IP SLA Frequency
  • Timeout/Threshold
  • Tracking Delay
  • Preempt Behavior
  • WAN Stability
  • Target Stability
อย่าแก้ Gateway Flapping ด้วยการเพิ่ม Timer แบบสุ่มอย่างเดียว ต้องหาว่า Probe Failure เกิดจาก Network จริง หรือเกิดจาก Target/Probe Design ที่ไม่เหมาะสม

ภาค 10: Production Design

แนวทางออกแบบ HSRP Tracking

ก่อนสร้าง Tracking ควรตอบคำถามต่อไปนี้:

  1. Failure แบบใดที่ต้องการตรวจ?
  2. Failure นั้นทำให้ Router ใช้งานไม่ได้จริงหรือไม่?
  3. Router มี Alternate Route อยู่แล้วหรือไม่?
  4. ควร Track Interface, Route หรือ IP SLA?
  5. Target อยู่ภายใต้การควบคุมของเราหรือไม่?
  6. ต้องการ Failover เร็วเพียงใด?
  7. ยอมรับ False Positive ได้แค่ไหน?
  8. Recovery ควรรอกี่วินาทีก่อน Failback?
  9. มี Preempt หรือไม่?
  10. มี Rollback Plan หรือไม่?

อย่า Track มากเกินไป

สมมติ R1 Track:

ISP Gateway
DNS Server
Cloud Server
Remote Branch
Public Website
Application Server
Core Router

ถ้า Resource ใด Resource หนึ่ง เกิดปัญหาแล้วทำให้ Gateway Failover ทั้งหมด ระบบอาจซับซ้อน และไม่เสถียร

ควร Track เฉพาะ Condition ที่สะท้อนว่า Router ตัวนี้ไม่ควรเป็น Active Gateway จริง ๆ

HSRP Tracking ไม่ใช่ Application Monitoring

หาก Web Server Down ไม่ได้หมายความว่า Default Gateway ต้องเปลี่ยน

Application Failure
        !=
Gateway Failure

แต่ละ Layer ควรมี Monitoring และ Redundancy ที่เหมาะกับหน้าที่ของตน

เลือก Tracking ให้ตรง Failure

Failure วิธีที่ควรพิจารณา
Physical Uplink Down Interface Tracking
Next-Hop ไม่ Reach IP SLA / Route Tracking ตาม Design
Remote WAN Path หาย IP SLA หรือ Dynamic Routing State ตาม Architecture
Default Route หาย Route Tracking หรือ Routing Protocol Design
Public Website Down Application Monitoring ไม่ควรผูก HSRP โดยอัตโนมัติ
ISP Path Failure แต่ Ethernet Up IP SLA/Object Tracking อาจเหมาะสม
Router ดับ HSRP พื้นฐานสามารถตรวจ Peer Loss ได้

Cisco Command Cheat Sheet

Command หน้าที่
show standby brief ตรวจ HSRP State และ Priority แบบย่อ
show standby ดูรายละเอียด HSRP และ Tracking
show track ตรวจ Track Object
show ip sla configuration ตรวจ IP SLA Configuration
show ip sla statistics ตรวจผลของ IP SLA Operation
show ip interface brief ตรวจ Interface State และ IP
show interfaces ตรวจ Physical/Logical Interface Details
show ip route ตรวจ Routing Table
show ip route <destination> ตรวจ Route ไปยัง Target
show arp ตรวจ ARP Information
ping ทดสอบ Reachability
traceroute ตรวจ Path โดยประมาณ
IP SLA, Object Tracking และ HSRP มีรายละเอียด Syntax แตกต่างกันตาม Cisco Platform, IOS/IOS XE Release และ License/Feature Set จึงควรตรวจ Documentation ของอุปกรณ์จริงก่อน Deploy

HSRP Tracking Troubleshooting Workflow

START
  |
  v
Physical interfaces OK?
  |
  +-- NO --> Fix interface/link
  |
 YES
  |
  v
HSRP peers healthy?
  |
  +-- NO --> Fix HSRP first
  |
 YES
  |
  v
IP SLA configured?
  |
  v
Probe running?
  |
  v
Target reachable?
  |
  +---------+
  |         |
 YES        NO
  |         |
  v         v
Track UP   Track DOWN
            |
            v
Priority decremented?
            |
            v
Below peer priority?
            |
            v
Election/preempt works?
            |
            v
New Active has valid routing?
            |
            v
Traffic reaches destination?
            |
            v
Return path works?
            |
            v
PASS

คำถามที่พบบ่อย — FAQ

HSRP Tracking คืออะไร?

เป็นการให้ HSRP นำสถานะของ Interface หรือ Track Object มาใช้ประกอบการปรับ Priority เพื่อให้ Gateway Role เปลี่ยนตามสภาวะ Network ที่ออกแบบไว้

IP SLA คืออะไร?

IP SLA เป็นความสามารถ สำหรับสร้าง Active Probe เพื่อตรวจ Reachability หรือวัด Network Characteristics ตาม Operation ที่อุปกรณ์รองรับ

IP SLA กับ Ping เหมือนกันหรือไม่?

ICMP Echo เป็นหนึ่งใน Operation ที่ IP SLA สามารถใช้ได้ แต่ IP SLA เป็น Framework ที่รองรับ Operation และ Measurement ได้มากกว่าการ Ping แบบ Manual เพียงครั้งเดียว ขึ้นอยู่กับ Platform

ทำไมไม่ Track Interface อย่างเดียว?

เพราะ Interface สามารถ up/up ในขณะที่ Failure เกิดอยู่ไกลออกไปใน Network Interface Tracking จึงมองไม่เห็น Failure ทุกประเภท

ทำไมต้องมี Object Tracking?

Object Tracking ทำหน้าที่แปลงสถานะ ของสิ่งที่กำลังตรวจสอบ ให้ Feature อื่น เช่น HSRP สามารถนำไปใช้ตัดสินใจได้

Priority Decrement ตั้งเท่าไรดี?

ต้องคำนวณจาก Priority ของทุก Router ใน HSRP Group และ Desired Failover Behavior ไม่ควรกำหนดตัวเลขเดียว ใช้กับทุก Network

ถ้า R1 Priority 110 และ R2 Priority 100 ลด 5 เพียงพอหรือไม่?

หากเป้าหมายคือต้องการให้ R2 มี Priority สูงกว่า R1 หลัง Failure จะไม่เพียงพอ เพราะ R1 จะเหลือ 105 ซึ่งยังสูงกว่า R2 ที่ 100

IP SLA ควร Ping 8.8.8.8 หรือ Public IP หรือไม่?

ไม่ควรเลือก Public Target โดยไม่มีเหตุผลด้าน Architecture เพราะ Target ภายนอก อยู่นอกการควบคุมขององค์กร และ Failure ของ Target อาจทำให้เกิด False Failover ได้

ถ้า OSPF มีเส้นทางสำรองอยู่แล้วต้อง HSRP Failover หรือไม่?

ไม่จำเป็นเสมอไป หาก Active Router ยังมี Alternate Route และสามารถ Forward Traffic ได้อย่างถูกต้อง การเปลี่ยน Default Gateway อาจไม่จำเป็น

Preempt กับ Tracking ต่างกันอย่างไร?

Tracking ใช้เปลี่ยน Operational Priority ตามสถานะที่ตรวจสอบ ส่วน Preempt เกี่ยวข้องกับ ความสามารถของ Router ที่มี Priority เหมาะสมกว่า ในการกลับมารับ Active Role ตามเงื่อนไข HSRP

Failover เร็วที่สุดดีที่สุดหรือไม่?

ไม่เสมอไป Detection ที่ไวเกินไป อาจทำให้ Packet Loss เพียงช่วงสั้น ๆ กลายเป็น Gateway Failover และสร้าง Flapping จึงต้องสมดุลระหว่าง Detection Speed กับ Stability

HSRP Failover สำเร็จแล้วทำไม User ยังใช้งานไม่ได้?

ต้องตรวจต่อว่า New Active Router มี Routing Table, NAT, ACL, Firewall, WAN Path และ Return Route ที่ถูกต้องหรือไม่ HSRP State เพียงอย่างเดียว ไม่ได้รับประกัน End-to-End Connectivity

บทสรุป

HSRP พื้นฐานแก้ปัญหา Default Gateway Redundancy แต่ Network Failure ไม่ได้เกิดเฉพาะตอน Router หรือ Interface Down

Router UP
Interface UP
     |
     v
Does not always mean
     |
     v
Path is usable

Interface Tracking ช่วยตรวจ Direct Link:

Interface
   |
   v
Track
   |
   v
HSRP Priority

สำหรับ Failure ที่อยู่ไกลกว่า Direct Link สามารถใช้แนวคิด:

IP SLA
   |
   v
Active Probe
   |
   v
Object Tracking
   |
   v
HSRP Priority
   |
   v
Gateway Failover

แต่การสร้าง Tracking ไม่ควรมีเป้าหมายว่า “เจอปัญหาอะไรก็ Failover”

สิ่งที่ควรถามคือ:

Is this router still capable
of forwarding traffic correctly?

          |
      +---+---+
      |       |
     YES      NO
      |       |
      v       v
Remain      Consider
Active      Failover

Network ที่ออกแบบดี จึงต้องพิจารณาร่วมกันทั้ง:

HSRP / VRRP
     +
Tracking
     +
Dynamic Routing
     +
Layer 2 Redundancy
     +
WAN Redundancy
     +
Firewall / NAT
     +
Return Path
     +
Monitoring

หลังจากเข้าใจ Gateway Redundancy และ Path Tracking แล้ว บทความถัดไปควรเข้าสู่ NAT และ PAT บน Cisco เพื่ออธิบายการแปลง Private IP ไปสู่ Public IP, Inside Local/Global, Static NAT, Dynamic NAT, PAT/Overload และการเชื่อม LAN ออกสู่ Internet

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.