HSRP สามารถสร้าง Default Gateway สำรองได้ แต่การมี Router สองตัวไม่ได้หมายความว่า ระบบจะตรวจพบความเสียหายของเส้นทางทุกประเภท โดยอัตโนมัติ เพราะบางครั้ง Active Router และ Interface ยัง Up แต่เส้นทางไป Core, WAN หรือ Internet ใช้งานไม่ได้ จึงต้องใช้ Tracking, IP SLA และ Object Tracking ช่วยตรวจสอบความพร้อมใช้งานของ Path
บทความนี้ต่อยอดจากพื้นฐาน HSRP และ VRRP โดยอธิบายตั้งแต่ Interface Tracking, Object Tracking, IP SLA, HSRP Priority Decrement, Failover และ Failback ไปจนถึง Cisco Lab และ Troubleshooting สำหรับออกแบบ Gateway Redundancy ให้ตรวจสอบได้มากกว่าแค่สถานะ Interface
สารบัญ
- ปัญหาที่ HSRP พื้นฐานอาจตรวจไม่พบ
- Tracking คืออะไร?
- Interface Tracking
- ข้อจำกัดของ Interface Tracking
- Object Tracking คืออะไร?
- IP SLA คืออะไร?
- IP SLA + Track + HSRP ทำงานอย่างไร?
- Priority Decrement
- Lab 1: HSRP Interface Tracking
- Lab 2: HSRP + IP SLA + Object Tracking
- Tracking Delay และ Route Flapping
- ทำงานร่วมกับ OSPF อย่างไร?
- ทดสอบ Failover
- Troubleshooting
- แนวทางออกแบบ Production
- Cisco Command Cheat Sheet
- FAQ
- บทสรุป
ภาค 1: ทำไม HSRP ต้องมี Tracking?
ปัญหาที่ HSRP พื้นฐานอาจตรวจไม่พบ
จากบทความก่อนหน้า สมมติเรามี Router สองตัว:
Internet
/ \
/ \
R1 R2
\ /
\ /
Switch
|
Hosts
Virtual Gateway
192.168.10.1
กำหนด:
R1
LAN IP = 192.168.10.2
Priority = 110
Role = Active
R2
LAN IP = 192.168.10.3
Priority = 100
Role = Standby
Virtual IP = 192.168.10.1
หาก R1 ดับทั้งเครื่อง หรือ LAN Interface ของ R1 Down HSRP สามารถเปลี่ยนบทบาท ไปยัง R2 ได้ตามเงื่อนไข
แต่ลองเปลี่ยน Failure Scenario:
Internet
|
X
|
Upstream/Core
|
|
Gi0/1 = UP
|
R1
HSRP Active
|
Gi0/0 = UP
|
LAN
Physical Interface ของ R1
อาจยังรายงานว่า
up/up
HSRP ฝั่ง LAN จึงอาจยังเห็น R1 เป็น Active Router ทั้งที่ R1 ไม่สามารถส่ง Traffic ไปยังปลายทางสำคัญได้จริง
Link Layer สามารถทำงานปกติ ในขณะที่ปัญหาเกิดอยู่ถัดออกไป หลาย Hop ได้
Tracking คืออะไร?
Tracking คือกลไกที่ใช้ติดตาม สถานะของ Resource หรือเงื่อนไขบางอย่าง แล้วนำผลลัพธ์นั้นไปมีอิทธิพล ต่อ Feature อื่น
แนวคิดทั่วไป:
Something being monitored
|
v
Tracking
|
v
UP or DOWN
|
v
Another feature reacts
สำหรับ HSRP:
Track condition
|
v
UP -------- DOWN
|
v
Reduce HSRP
Priority
|
v
Another router
may become Active
ภาค 2: Interface Tracking
Interface Tracking คืออะไร?
วิธีพื้นฐานคือ ให้ HSRP ติดตามสถานะ ของ Uplink Interface
ตัวอย่าง:
Core
|
|
Gi0/1
|
R1
Priority 110
|
Gi0/0
|
LAN
หาก Gi0/1 Down
ให้ลด Priority ของ R1
Normal:
R1 Priority = 110
R2 Priority = 100
R1 = Active
Gi0/1 DOWN:
R1 Priority
110 - 20 = 90
R2 Priority = 100
R2 now has
higher priority
ตัวอย่าง Configuration
interface GigabitEthernet0/0
ip address 192.168.10.2 255.255.255.0
standby 10 ip 192.168.10.1
standby 10 priority 110
standby 10 preempt
standby 10 track GigabitEthernet0/1 20
เมื่อ Uplink ที่ Track เปลี่ยนเป็น Down HSRP Priority ของ R1 จะถูกลดตามค่าที่กำหนด
ข้อจำกัดของ Interface Tracking
Interface Tracking เหมาะกับ Failure ที่ทำให้ Interface State เปลี่ยนจริง
เช่น:
Cable disconnected
Transceiver failure
Physical link down
Directly connected device down
แต่มี Failure อีกประเภท:
R1
|
| Gi0/1 = UP
|
SW1
|
| Link = UP
|
Core
|
X
|
Internet
R1 ยังเห็น:
GigabitEthernet0/1
Status: up
Protocol: up
Interface Tracking จึงอาจไม่ตรวจพบ ปัญหาที่เกิดลึกเข้าไปใน Network
จุดนี้เป็นเหตุผลที่ต้องมี IP SLA
ภาค 3: Object Tracking และ IP SLA
Object Tracking คืออะไร?
Object Tracking ช่วยสร้าง Tracking Object ที่ Feature อื่นสามารถนำไปใช้ได้
แนวคิด:
Interface
Route
IP SLA
Other supported condition
|
v
Track Object
|
v
State
UP / DOWN
|
+----------------+
| |
v v
HSRP Other features
แทนที่จะให้ HSRP ตรวจ Interface เพียงอย่างเดียว เราสามารถให้ HSRP อ้างอิง Track Object ที่สะท้อน Reachability ของ Network ได้
IP SLA คืออะไร?
IP SLA เป็นความสามารถบน Cisco สำหรับสร้าง Active Probe เพื่อวัดหรือตรวจสอบ Network Reachability และ Performance ตาม Operation ที่ Platform รองรับ
ตัวอย่างง่ายคือ ICMP Echo:
R1
|
| ICMP Echo Probe
|
+--------------------> Target
10.0.0.1
Response?
|
+-- YES --> Reachable
|
+-- NO --> Probe failure
จากนั้นนำผลของ IP SLA ไปผูกกับ Object Tracking
IP SLA
|
v
Track Object
|
v
HSRP
IP SLA + Track + HSRP ทำงานอย่างไร?
ลำดับการทำงาน:
Step 1
IP SLA sends probe
|
v
Step 2
Target reachable?
|
+--+--+
| |
YES NO
| |
v v
Track Track
UP DOWN
|
v
Step 3
HSRP sees Track DOWN
|
v
Step 4
Priority decreases
|
v
Step 5
Standby has higher priority
|
v
Step 6
Failover can occur
ทำให้ Failover Decision ไม่ได้อาศัยเพียง Physical Interface State
Priority Decrement ต้องคำนวณให้ถูก
สมมติ:
R1 Priority = 110
R2 Priority = 100
ถ้า Track Down แล้วลด R1 เพียง 5:
110 - 5 = 105
ผลคือ:
R1 = 105
R2 = 100
R1 ยังมี Priority สูงกว่า R2 ดังนั้น Design อาจไม่ทำงาน ตามที่ต้องการ
ถ้าลด 20:
110 - 20 = 90
จะได้:
R1 = 90
R2 = 100
R2 จึงมี Priority สูงกว่า หลัง Track Failure
Priority Decrement ต้องมากพอที่จะทำให้ Priority หลัง Failure ต่ำกว่า Router สำรอง หากนั่นคือ Failover Behavior ที่ออกแบบไว้
ภาค 4: Cisco Lab — Interface Tracking
Lab 1: HSRP Interface Tracking
Topology:
Core
/ \
/ \
Gi0/1 Gi0/1
| |
R1 R2
| |
Gi0/0 Gi0/0
\ /
\ /
SW1
|
PC-A
Addressing:
LAN:
192.168.10.0/24
Virtual Gateway:
192.168.10.1
R1:
192.168.10.2
R2:
192.168.10.3
R1
interface GigabitEthernet0/0
description LAN
ip address 192.168.10.2 255.255.255.0
standby version 2
standby 10 ip 192.168.10.1
standby 10 priority 110
standby 10 preempt
standby 10 track GigabitEthernet0/1 20
no shutdown
R2
interface GigabitEthernet0/0
description LAN
ip address 192.168.10.3 255.255.255.0
standby version 2
standby 10 ip 192.168.10.1
standby 10 priority 100
standby 10 preempt
no shutdown
ตรวจสถานะ
show standby brief
show standby
show ip interface brief
Normal:
R1 Priority 110
Active
R2 Priority 100
Standby
เมื่อ R1 Uplink Down:
R1 Priority
110 - 20
= 90
R2 Priority
= 100
R2 สามารถรับ Active Role ตาม Election และ Preemption ที่กำหนด
ภาค 5: Cisco Lab — IP SLA + Object Tracking
Lab 2: ตรวจ Remote Reachability
Topology:
Target
10.0.0.1
|
Network
/ \
/ \
R1 R2
\ /
\ /
SW1
|
PC-A
Virtual Gateway:
192.168.10.1
ต้องการให้ R1 เป็น Active
เฉพาะเมื่อ R1
สามารถ Reach Target
10.0.0.1
ตามเงื่อนไข Probe
Step 1 — สร้าง IP SLA
ip sla 10
icmp-echo 10.0.0.1 source-interface GigabitEthernet0/1
frequency 5
Step 2 — เริ่ม Schedule
ip sla schedule 10 life forever start-time now
Step 3 — สร้าง Track Object
track 10 ip sla 10 reachability
Step 4 — ผูก Track กับ HSRP
interface GigabitEthernet0/0
ip address 192.168.10.2 255.255.255.0
standby version 2
standby 10 ip 192.168.10.1
standby 10 priority 110
standby 10 preempt
standby 10 track 10 decrement 20
no shutdown
Flow ที่เกิดขึ้น
IP SLA 10
ICMP Echo 10.0.0.1
|
v
Target responds?
|
+----+----+
| |
YES NO
| |
v v
Track 10 Track 10
UP DOWN
|
v
HSRP Priority
110 -> 90
|
v
R2 Priority 100
becomes preferred
ตรวจ IP SLA และ Track Object
คำสั่งสำคัญ:
show ip sla configuration
show ip sla statistics
show track
show standby brief
show standby
การ Troubleshoot ควรตรวจ จากต้นเหตุไปปลายเหตุ:
IP SLA working?
|
v
Track state correct?
|
v
Priority changed?
|
v
HSRP state changed?
|
v
Traffic changed path?
เลือก IP SLA Target อย่างไร?
Target ที่เลือกมีผลโดยตรง ต่อความหมายของคำว่า “Path ใช้งานได้”
ตัวอย่าง:
| Target | สิ่งที่ตรวจได้ | ข้อจำกัด |
|---|---|---|
| Next-Hop Router | ตรวจ First Upstream Hop | ไม่ได้พิสูจน์ว่า Remote Network ใช้งานได้ |
| Core Router | ตรวจเส้นทางลึกขึ้นในองค์กร | ไม่ได้พิสูจน์ Internet/Application ทั้งหมด |
| Remote Site Router | ตรวจ WAN Reachability ไป Site นั้น | ขึ้นกับความเสถียรของ Remote Target |
| External IP | ตรวจ Reachability ออกนอกระบบบางส่วน | Target ภายนอกอาจล่มหรือ Filter ICMP เอง |
ภาค 6: ป้องกัน Route และ Gateway Flapping
Tracking Delay สำคัญอย่างไร?
สมมติ WAN Link มี Packet Loss ชั่วคราว:
UP
|
DOWN
|
UP
|
DOWN
|
UP
หาก Tracking เปลี่ยน State ทันทีทุกครั้ง HSRP อาจเกิด:
R1 Active
|
v
R2 Active
|
v
R1 Active
|
v
R2 Active
เรียกว่า Gateway Flapping ซึ่งอาจสร้างผลกระทบ มากกว่าความเสียหายระยะสั้น ที่กำลังตรวจพบ
Object Tracking บน Platform ที่รองรับสามารถมีแนวคิด Delay Up/Down เพื่อป้องกันการเปลี่ยน State จากเหตุการณ์ชั่วคราว
ตัวอย่างแนวคิด:
track 10 ip sla 10 reachability
delay down 10 up 30
ความหมายเชิงออกแบบ:
Failure detected
|
v
Wait before declaring DOWN
|
v
Persistent?
|
YES
|
v
DOWN
Recovery detected
|
v
Wait longer
|
v
Stable?
|
YES
|
v
UP
Preempt Delay
อีกแนวคิดหนึ่งคือ ไม่ควรให้ Router รีบกลับมา Active ทันทีหลัง Boot
Router boots
|
v
LAN interface UP
|
v
Routing still converging
|
v
HSRP preempts too early
|
v
Possible traffic loss
ในบาง Design สามารถใช้ Preempt Delay เพื่อให้เวลา Routing, Interfaces และ Services เข้าสู่สภาวะพร้อมก่อน
ตัวอย่าง:
standby 10 preempt delay minimum 60
แนวคิดคือรอช่วงเวลาที่กำหนด ก่อน Preempt แทนการกลับมา Active ทันที
ภาค 7: HSRP Tracking กับ OSPF
HSRP และ OSPF มอง Failure คนละมุม
Topology:
Core Network
/ \
/ \
R1 ------------ R2
\ /
\ /
---- LAN ----
|
Virtual Gateway
OSPF รับผิดชอบ Router-to-Router Routing
HSRP รับผิดชอบ Host-to-Gateway Redundancy
OSPF
|
+-- Which route should router use?
HSRP
|
+-- Which router should host use
through the Virtual Gateway?
Tracking ทำหน้าที่เชื่อม Operational State บางส่วน เข้ากับ HSRP Decision
ตัวอย่าง Failure
Core
/ \
X |
| |
R1 R2
\ /
\ /
LAN
OSPF บน R1 อาจเปลี่ยน Routing Table เมื่อเส้นทางหนึ่งหาย
แต่ถ้า R1 ยังสามารถ Forward ผ่านเส้นทางสำรองได้ อาจไม่มีเหตุผลให้ HSRP ต้อง Failover
ควร Track Interface, Route หรือ Reachability?
| วิธี | เหมาะกับ | ข้อจำกัด |
|---|---|---|
| Interface Tracking | ตรวจ Direct Link Failure | มองไม่เห็น Failure ที่อยู่ไกลออกไป |
| Route Tracking | ตรวจว่ามี Route สำคัญอยู่หรือไม่ | Route มีอยู่ไม่ได้รับประกัน End-to-End Reachability |
| IP SLA Tracking | ตรวจ Active Reachability | ต้องเลือก Probe/Target ให้เหมาะสม |
ไม่มีวิธีใดดีที่สุด สำหรับทุก Network
ต้องเลือกตาม Failure Condition ที่ต้องการตรวจจริง
ภาค 8: ทดสอบ Failover อย่างเป็นระบบ
Failover Test Plan
ก่อนทดสอบควรบันทึก Baseline:
show standby brief
show track
show ip sla statistics
show ip route
show ip interface brief
Test 1 — Normal State
คาดหวัง:
IP SLA = OK
Track 10 = UP
R1 Priority = 110
R1 = Active
R2 Priority = 100
R2 = Standby
Test 2 — Uplink Interface Failure
ใน Lab จำลอง Uplink Down
ตรวจ:
show track
show standby brief
Test 3 — Remote Path Failure
จำลองให้ IP SLA Target ไม่สามารถ Reach ได้ โดยที่ Local Interface ยังคง Up
คาดหวัง:
Interface = UP
but
IP SLA = Failure
|
v
Track = DOWN
|
v
Priority = 90
|
v
R2 becomes preferred
Test 4 — Recovery
คืน Path กลับ:
IP SLA succeeds
|
v
Track UP
|
v
R1 Priority 110
|
v
Preempt conditions
|
v
R1 may become Active again
ต้องตรวจด้วยว่า Traffic ใช้งานได้จริง ไม่ใช่ดูเพียง HSRP State
ภาค 9: Troubleshooting
IP SLA ทำงาน แต่ HSRP ไม่ Failover
ตรวจตามลำดับ:
show ip sla statistics
|
v
IP SLA failed?
|
v
show track
|
v
Track DOWN?
|
v
show standby
|
v
Priority decreased?
|
v
Is new priority below peer?
|
v
Preemption/election conditions correct?
ปัญหา 1 — IP SLA ยัง Success ทั้งที่คิดว่า Path เสีย
ตรวจ:
- Target ถูกต้องหรือไม่
- Source Interface ถูกต้องหรือไม่
- มี Alternate Path หรือไม่
- Probe วิ่งออก Path ที่คาดหรือไม่
- Target ตอบ Probe จริงหรือไม่
ปัญหา 2 — Track DOWN แต่ Priority ยังสูงกว่า Standby
ตัวอย่าง:
R1:
110 - 5 = 105
R2:
100
แม้ Tracking ทำงานถูกต้อง แต่ Decrement ไม่เพียงพอ
ปัญหา 3 — Priority ต่ำกว่าแล้ว แต่ Role ไม่เปลี่ยนตามที่คาด
ตรวจ:
- Preempt Configuration
- HSRP Group
- HSRP Version
- Peer State
- Current Priority
- Timers
- Layer 2 Connectivity
ปัญหา 4 — HSRP Failover สำเร็จ แต่ Internet ยังไม่ได้
แสดงว่า FHRP อาจไม่ได้เป็น Root Cause ทั้งหมด
New Active
|
v
Routing Table?
|
v
Default Route?
|
v
NAT?
|
v
Firewall?
|
v
WAN?
|
v
Return Path?
ปัญหา 5 — Failover ไปมา
ตรวจ:
- Packet Loss
- IP SLA Frequency
- Timeout/Threshold
- Tracking Delay
- Preempt Behavior
- WAN Stability
- Target Stability
ภาค 10: Production Design
แนวทางออกแบบ HSRP Tracking
ก่อนสร้าง Tracking ควรตอบคำถามต่อไปนี้:
- Failure แบบใดที่ต้องการตรวจ?
- Failure นั้นทำให้ Router ใช้งานไม่ได้จริงหรือไม่?
- Router มี Alternate Route อยู่แล้วหรือไม่?
- ควร Track Interface, Route หรือ IP SLA?
- Target อยู่ภายใต้การควบคุมของเราหรือไม่?
- ต้องการ Failover เร็วเพียงใด?
- ยอมรับ False Positive ได้แค่ไหน?
- Recovery ควรรอกี่วินาทีก่อน Failback?
- มี Preempt หรือไม่?
- มี Rollback Plan หรือไม่?
อย่า Track มากเกินไป
สมมติ R1 Track:
ISP Gateway
DNS Server
Cloud Server
Remote Branch
Public Website
Application Server
Core Router
ถ้า Resource ใด Resource หนึ่ง เกิดปัญหาแล้วทำให้ Gateway Failover ทั้งหมด ระบบอาจซับซ้อน และไม่เสถียร
ควร Track เฉพาะ Condition ที่สะท้อนว่า Router ตัวนี้ไม่ควรเป็น Active Gateway จริง ๆ
HSRP Tracking ไม่ใช่ Application Monitoring
หาก Web Server Down ไม่ได้หมายความว่า Default Gateway ต้องเปลี่ยน
Application Failure
!=
Gateway Failure
แต่ละ Layer ควรมี Monitoring และ Redundancy ที่เหมาะกับหน้าที่ของตน
เลือก Tracking ให้ตรง Failure
| Failure | วิธีที่ควรพิจารณา |
|---|---|
| Physical Uplink Down | Interface Tracking |
| Next-Hop ไม่ Reach | IP SLA / Route Tracking ตาม Design |
| Remote WAN Path หาย | IP SLA หรือ Dynamic Routing State ตาม Architecture |
| Default Route หาย | Route Tracking หรือ Routing Protocol Design |
| Public Website Down | Application Monitoring ไม่ควรผูก HSRP โดยอัตโนมัติ |
| ISP Path Failure แต่ Ethernet Up | IP SLA/Object Tracking อาจเหมาะสม |
| Router ดับ | HSRP พื้นฐานสามารถตรวจ Peer Loss ได้ |
Cisco Command Cheat Sheet
| Command | หน้าที่ |
|---|---|
show standby brief |
ตรวจ HSRP State และ Priority แบบย่อ |
show standby |
ดูรายละเอียด HSRP และ Tracking |
show track |
ตรวจ Track Object |
show ip sla configuration |
ตรวจ IP SLA Configuration |
show ip sla statistics |
ตรวจผลของ IP SLA Operation |
show ip interface brief |
ตรวจ Interface State และ IP |
show interfaces |
ตรวจ Physical/Logical Interface Details |
show ip route |
ตรวจ Routing Table |
show ip route <destination> |
ตรวจ Route ไปยัง Target |
show arp |
ตรวจ ARP Information |
ping |
ทดสอบ Reachability |
traceroute |
ตรวจ Path โดยประมาณ |
HSRP Tracking Troubleshooting Workflow
START
|
v
Physical interfaces OK?
|
+-- NO --> Fix interface/link
|
YES
|
v
HSRP peers healthy?
|
+-- NO --> Fix HSRP first
|
YES
|
v
IP SLA configured?
|
v
Probe running?
|
v
Target reachable?
|
+---------+
| |
YES NO
| |
v v
Track UP Track DOWN
|
v
Priority decremented?
|
v
Below peer priority?
|
v
Election/preempt works?
|
v
New Active has valid routing?
|
v
Traffic reaches destination?
|
v
Return path works?
|
v
PASS
คำถามที่พบบ่อย — FAQ
HSRP Tracking คืออะไร?
เป็นการให้ HSRP นำสถานะของ Interface หรือ Track Object มาใช้ประกอบการปรับ Priority เพื่อให้ Gateway Role เปลี่ยนตามสภาวะ Network ที่ออกแบบไว้
IP SLA คืออะไร?
IP SLA เป็นความสามารถ สำหรับสร้าง Active Probe เพื่อตรวจ Reachability หรือวัด Network Characteristics ตาม Operation ที่อุปกรณ์รองรับ
IP SLA กับ Ping เหมือนกันหรือไม่?
ICMP Echo เป็นหนึ่งใน Operation ที่ IP SLA สามารถใช้ได้ แต่ IP SLA เป็น Framework ที่รองรับ Operation และ Measurement ได้มากกว่าการ Ping แบบ Manual เพียงครั้งเดียว ขึ้นอยู่กับ Platform
ทำไมไม่ Track Interface อย่างเดียว?
เพราะ Interface สามารถ
up/up
ในขณะที่ Failure
เกิดอยู่ไกลออกไปใน Network
Interface Tracking
จึงมองไม่เห็น Failure
ทุกประเภท
ทำไมต้องมี Object Tracking?
Object Tracking ทำหน้าที่แปลงสถานะ ของสิ่งที่กำลังตรวจสอบ ให้ Feature อื่น เช่น HSRP สามารถนำไปใช้ตัดสินใจได้
Priority Decrement ตั้งเท่าไรดี?
ต้องคำนวณจาก Priority ของทุก Router ใน HSRP Group และ Desired Failover Behavior ไม่ควรกำหนดตัวเลขเดียว ใช้กับทุก Network
ถ้า R1 Priority 110 และ R2 Priority 100 ลด 5 เพียงพอหรือไม่?
หากเป้าหมายคือต้องการให้ R2 มี Priority สูงกว่า R1 หลัง Failure จะไม่เพียงพอ เพราะ R1 จะเหลือ 105 ซึ่งยังสูงกว่า R2 ที่ 100
IP SLA ควร Ping 8.8.8.8 หรือ Public IP หรือไม่?
ไม่ควรเลือก Public Target โดยไม่มีเหตุผลด้าน Architecture เพราะ Target ภายนอก อยู่นอกการควบคุมขององค์กร และ Failure ของ Target อาจทำให้เกิด False Failover ได้
ถ้า OSPF มีเส้นทางสำรองอยู่แล้วต้อง HSRP Failover หรือไม่?
ไม่จำเป็นเสมอไป หาก Active Router ยังมี Alternate Route และสามารถ Forward Traffic ได้อย่างถูกต้อง การเปลี่ยน Default Gateway อาจไม่จำเป็น
Preempt กับ Tracking ต่างกันอย่างไร?
Tracking ใช้เปลี่ยน Operational Priority ตามสถานะที่ตรวจสอบ ส่วน Preempt เกี่ยวข้องกับ ความสามารถของ Router ที่มี Priority เหมาะสมกว่า ในการกลับมารับ Active Role ตามเงื่อนไข HSRP
Failover เร็วที่สุดดีที่สุดหรือไม่?
ไม่เสมอไป Detection ที่ไวเกินไป อาจทำให้ Packet Loss เพียงช่วงสั้น ๆ กลายเป็น Gateway Failover และสร้าง Flapping จึงต้องสมดุลระหว่าง Detection Speed กับ Stability
HSRP Failover สำเร็จแล้วทำไม User ยังใช้งานไม่ได้?
ต้องตรวจต่อว่า New Active Router มี Routing Table, NAT, ACL, Firewall, WAN Path และ Return Route ที่ถูกต้องหรือไม่ HSRP State เพียงอย่างเดียว ไม่ได้รับประกัน End-to-End Connectivity
บทสรุป
HSRP พื้นฐานแก้ปัญหา Default Gateway Redundancy แต่ Network Failure ไม่ได้เกิดเฉพาะตอน Router หรือ Interface Down
Router UP
Interface UP
|
v
Does not always mean
|
v
Path is usable
Interface Tracking ช่วยตรวจ Direct Link:
Interface
|
v
Track
|
v
HSRP Priority
สำหรับ Failure ที่อยู่ไกลกว่า Direct Link สามารถใช้แนวคิด:
IP SLA
|
v
Active Probe
|
v
Object Tracking
|
v
HSRP Priority
|
v
Gateway Failover
แต่การสร้าง Tracking ไม่ควรมีเป้าหมายว่า “เจอปัญหาอะไรก็ Failover”
สิ่งที่ควรถามคือ:
Is this router still capable
of forwarding traffic correctly?
|
+---+---+
| |
YES NO
| |
v v
Remain Consider
Active Failover
Network ที่ออกแบบดี จึงต้องพิจารณาร่วมกันทั้ง:
HSRP / VRRP
+
Tracking
+
Dynamic Routing
+
Layer 2 Redundancy
+
WAN Redundancy
+
Firewall / NAT
+
Return Path
+
Monitoring
หลังจากเข้าใจ Gateway Redundancy และ Path Tracking แล้ว บทความถัดไปควรเข้าสู่ NAT และ PAT บน Cisco เพื่ออธิบายการแปลง Private IP ไปสู่ Public IP, Inside Local/Global, Static NAT, Dynamic NAT, PAT/Overload และการเชื่อม LAN ออกสู่ Internet
Share your thoughts here
Join the conversation and share your perspective on this article.