Techerest

HSRP และ VRRP คืออะไร? สร้าง Default Gateway Redundancy บน Cisco

ต่อให้ Network มี OSPF และมี Router หลายตัว ระบบก็ยังอาจหยุดทำงานได้ หาก Default Gateway ที่เครื่องผู้ใช้ใช้งาน มีเพียง Router เดียว First Hop Redundancy Protocol หรือ FHRP จึงถูกนำมาใช้สร้าง Virtual Gateway เพื่อให้ Router หลายตัวสามารถทำงานร่วมกัน และมี Gateway สำรองเมื่ออุปกรณ์หลักเกิดปัญหา

บทความนี้จะอธิบายแนวคิด Gateway Redundancy, HSRP, VRRP, Virtual IP, Active/Standby, Priority, Preempt, Interface Tracking และ Failover พร้อมตัวอย่าง Cisco Configuration และ Lab สำหรับสร้าง Default Gateway ที่มี Redundancy

ภาค 1: ทำไม Default Gateway ต้องมี Redundancy?

ปัญหาของ Default Gateway แบบ Router เดียว

สมมติ VLAN 10 ใช้ Network:

Network:
192.168.10.0/24

Default Gateway:
192.168.10.1

Topology:

PC-A ----+
         |
PC-B ----+---- Switch ---- R1 ---- Network / Internet
         |
PC-C ----+

Default Gateway
192.168.10.1

ถ้า R1 หรือ Interface 192.168.10.1 หยุดทำงาน:

PC-A ----+
         |
PC-B ----+---- Switch ---- X R1
         |
PC-C ----+

Gateway unavailable

แม้ Switch, PC และ Network ภายใน VLAN ยังทำงานอยู่ เครื่องปลายทางก็ไม่สามารถ ส่ง Traffic ไปยัง Remote Network ผ่าน Gateway เดิมได้

นี่คือ Single Point of Failure ของ First Hop

First Hop Redundancy Protocol คืออะไร?

FHRP เป็นกลุ่ม Protocol ที่ช่วยให้ Routers หรือ Layer 3 Switches หลายตัวร่วมกันนำเสนอ Virtual Default Gateway ให้ End Devices ใช้งาน

แนวคิด:

                    +---- R1
                    |
PC ---- Switch -----+
                    |
                    +---- R2

Physical R1 IP:
192.168.10.2

Physical R2 IP:
192.168.10.3

Virtual Gateway:
192.168.10.1

PC ตั้งค่าเพียง:

IP Address:
192.168.10.100

Subnet Mask:
255.255.255.0

Default Gateway:
192.168.10.1

PC ไม่จำเป็นต้องรู้ว่า ขณะนั้น R1 หรือ R2 กำลังรับหน้าที่ Forward Traffic

Virtual IP และ Virtual MAC

FHRP ใช้แนวคิด Virtual Router ซึ่งมีอย่างน้อย:

  • Virtual IP Address
  • Virtual MAC Address
  • Router ที่รับบท Forwarding หลัก
  • Router สำรอง
Hosts
  |
  | Gateway 192.168.10.1
  v
Virtual Router
192.168.10.1
  |
  +---------+
  |         |
  v         v
 R1        R2
.2         .3

เมื่อ Host ทำ ARP หา Default Gateway Protocol จะทำให้ Virtual Gateway สามารถตอบสนองผ่าน Virtual MAC ที่เกี่ยวข้อง ตามสถานะของ FHRP

ภาค 2: HSRP บน Cisco

HSRP คืออะไร?

HSRP — Hot Standby Router Protocol เป็น First Hop Redundancy Protocol ที่สัมพันธ์กับระบบ Cisco ใช้สร้าง Virtual Gateway ระหว่างอุปกรณ์หลายตัว

รูปแบบพื้นฐาน:

              VLAN 10
         192.168.10.0/24

                 |
              Switch
             /      \
            /        \
           R1        R2
      192.168.10.2  192.168.10.3
           \          /
            \        /
             \      /
        Virtual Gateway
         192.168.10.1

สำหรับ HSRP Router หนึ่งตัวทำหน้าที่ Active ขณะที่อีกตัวสามารถเป็น Standby สำหรับ HSRP Group นั้น

ตัวอย่าง:

R1 = Active
R2 = Standby

Virtual IP
192.168.10.1

HSRP States

HSRP มี State Machine สำหรับกำหนดสถานะของ Router ใน Group

State ความหมายโดยย่อ
Initial เริ่มต้น HSRP หรือ Interface ยังไม่พร้อม
Learn Router ยังเรียนรู้ข้อมูลบางส่วน เช่น Virtual IP ในบางรูปแบบ Configuration
Listen รู้ Virtual IP แต่ยังไม่ใช่ Active หรือ Standby
Speak ส่ง Hello และเข้าร่วมการเลือก Active/Standby
Standby เป็น Router สำรองที่พร้อมรับหน้าที่
Active รับผิดชอบ Virtual Gateway และ Forward Traffic

ตรวจสถานะ:

show standby brief

HSRP Configuration พื้นฐาน

สมมติ:

VLAN 10
192.168.10.0/24

R1 = 192.168.10.2
R2 = 192.168.10.3

Virtual Gateway
192.168.10.1

HSRP Group
10

R1

interface GigabitEthernet0/0
 ip address 192.168.10.2 255.255.255.0
 standby 10 ip 192.168.10.1
 no shutdown

R2

interface GigabitEthernet0/0
 ip address 192.168.10.3 255.255.255.0
 standby 10 ip 192.168.10.1
 no shutdown

ตรวจ:

R1# show standby brief
R2# show standby brief
Syntax และ Feature Support แตกต่างได้ตาม Cisco Platform และ IOS/IOS XE Release โดยเฉพาะเมื่อใช้ SVI, HSRP Version 2, IPv6 หรือ Object Tracking

HSRP Priority คืออะไร?

Priority ใช้ช่วยกำหนดว่า Router ใดควรได้รับบทบาท Active ในการ Election

โดยทั่วไป HSRP Priority มีค่า Default 100 และค่าที่สูงกว่ามีความได้เปรียบ ในการเลือก Active

ตัวอย่าง:

R1 Priority = 110
R2 Priority = 100

R1

interface GigabitEthernet0/0
 standby 10 priority 110

R2

interface GigabitEthernet0/0
 standby 10 priority 100

เป้าหมาย:

R1
Priority 110
    |
    v
Preferred Active


R2
Priority 100
    |
    v
Standby

Preempt คืออะไร?

Priority อย่างเดียว ไม่ได้หมายความว่า Router ที่มี Priority สูงกว่า จะกลับมาแย่งตำแหน่ง Active ทุกครั้งหลัง Recovery

หากต้องการให้ Router ที่มี Priority สูงกว่า สามารถกลับมารับตำแหน่ง Active เมื่อพร้อมใช้งาน มักต้องกำหนด Preempt

ตัวอย่าง R1:

interface GigabitEthernet0/0
 standby 10 priority 110
 standby 10 preempt

Flow:

Normal

R1 Active
R2 Standby

     |
     | R1 fails
     v

R2 becomes Active

     |
     | R1 returns
     v

With suitable preempt configuration

R1 can become Active again
Preempt ไม่ควรถูกเปิดโดยไม่พิจารณา Network Stability และ Boot/Convergence Time เพราะ Router อาจกลับมา Active ก่อน Routing หรือ Uplink พร้อมใช้งานอย่างสมบูรณ์

ภาค 3: Interface Tracking และ Failover

ปัญหา: Router ยังอยู่ แต่ Uplink เสีย

นี่เป็นหนึ่งใน Failure Scenario ที่สำคัญที่สุดของ FHRP

LAN
 |
 |
 R1 -------- X ISP/Core
 |
 |
HSRP Active

หาก LAN Interface ของ R1 ยังทำงานอยู่ HSRP อาจยังเห็น R1 เป็น Active แม้ Uplink ที่ใช้ส่ง Traffic ออกจาก Network จะเสีย

ขณะเดียวกัน:

LAN
 |
 |
 R2 -------- Core/Internet
 |
 |
HSRP Standby

R2 มีเส้นทางออก แต่ยังเป็น Standby

จึงต้องมีแนวคิด Tracking เพื่อให้ FHRP State สัมพันธ์กับความพร้อมใช้งาน ของเส้นทางสำคัญ

HSRP Interface Tracking

ตัวอย่างแนวคิด:

R1 Priority = 110

Track uplink Gi0/1

If Gi0/1 fails:
Priority decreases by 20

110 - 20 = 90

R2 Priority = 100

Result:
R2 can become preferred Active
when election/preemption conditions permit

ตัวอย่าง Configuration:

interface GigabitEthernet0/0
 standby 10 ip 192.168.10.1
 standby 10 priority 110
 standby 10 preempt
 standby 10 track GigabitEthernet0/1 20
Tracking Syntax แตกต่างได้ตาม Platform และ IOS/IOS XE Release ระบบใหม่อาจใช้ Object Tracking ร่วมกับ IP SLA หรือ Track Objects เพื่อสร้างเงื่อนไขที่ละเอียดกว่า การตรวจเพียง Interface Up/Down

Interface Up ไม่ได้หมายความว่า Internet ใช้งานได้

สมมติ:

R1 Gi0/1
   |
   | Ethernet Link = UP
   |
Switch / Provider
   |
   X
Remote Network Failure

Interface Tracking อาจยังเห็น Interface เป็น Up แม้ปลายทางสำคัญ จะไม่สามารถเข้าถึงได้

สำหรับ Design ที่ต้องการ ตรวจ Reachability ลึกขึ้น อาจใช้:

IP SLA
  |
  v
Track Object
  |
  v
HSRP Priority
  |
  v
Active Gateway Selection

หัวข้อนี้ควรแยกศึกษา ในบท Advanced HSRP Tracking เพราะต้องออกแบบ Probe, Threshold และ Failure Condition อย่างระมัดระวัง

HSRP Version 1 และ Version 2

Cisco มี HSRP มากกว่าหนึ่ง Version โดย HSRPv2 เพิ่มความสามารถ บางส่วน เช่น Group Number Range ที่กว้างขึ้น และใช้ Addressing/Protocol Behavior บางส่วนแตกต่างจาก Version 1

ตัวอย่างการกำหนด Version:

interface GigabitEthernet0/0
 standby version 2
 standby 10 ip 192.168.10.1
Routers ที่อยู่ HSRP Group เดียวกัน ต้องใช้ Version และ Parameters ที่เข้ากันได้ ควรตรวจ Platform Support ก่อนเปลี่ยน HSRP Version ใน Production

ภาค 4: VRRP และการเปรียบเทียบ FHRP

VRRP คืออะไร?

VRRP — Virtual Router Redundancy Protocol เป็นมาตรฐานสำหรับ First Hop Redundancy ที่ใช้แนวคิด Virtual Router เช่นเดียวกัน

Topology:

              Hosts
                |
              Switch
             /      \
            /        \
          R1          R2
            \        /
             \      /
          Virtual Router
               |
               v
        Default Gateway

VRRP ใช้แนวคิด Master/Backup ในมาตรฐานและ Version ที่เกี่ยวข้อง แทนคำว่า Active/Standby แบบ HSRP

HSRP กับ VRRP ต่างกันอย่างไร?

หัวข้อ HSRP VRRP
ประเภท First Hop Redundancy Protocol First Hop Redundancy Protocol
ความสัมพันธ์ ใช้ในระบบ Cisco มาตรฐานที่รองรับโดยหลาย Vendor
บทบาทหลัก Active / Standby Master / Backup
Virtual IP รองรับ รองรับ
Priority ใช้ในการเลือก Role ใช้ในการเลือก Role
Preemption รองรับตาม Configuration Behavior ขึ้นกับมาตรฐาน/Implementation ที่ใช้งาน
Multi-Vendor โดยทั่วไปเน้น Cisco เหมาะกับ Environment ที่ต้องการมาตรฐานข้าม Vendor
อย่าเลือก FHRP จากตาราง Feature เพียงอย่างเดียว ควรพิจารณา Platform Support, Vendor Environment, Operations Standard, Existing Architecture และ Requirement ของ Network

ภาค 5: FHRP กับ Dynamic Routing

HSRP กับ OSPF ทำงานร่วมกันอย่างไร?

HSRP และ OSPF แก้ปัญหาคนละส่วน

Technology หน้าที่หลัก
OSPF แลกเปลี่ยน Routing Information และคำนวณเส้นทางระหว่าง Routers
HSRP สร้าง Default Gateway Redundancy ให้ End Devices

ตัวอย่าง:

                  OSPF
          +-------------------+
          |                   |
          v                   v

         R1 ---------------- R2
          \                  /
           \                /
            \              /
             ---- LAN ----
                  |
             Virtual IP
            192.168.10.1
                  |
                Hosts

OSPF สามารถทำให้ R1 และ R2 รู้เส้นทางไปยัง Remote Networks

HSRP ทำให้ Hosts ไม่ต้องเปลี่ยน Default Gateway เมื่อ Gateway Router ตัวหนึ่งเสีย

จำง่าย ๆ:
OSPF = Router-to-Router Routing Redundancy
HSRP/VRRP = Host-to-Gateway Redundancy

ภาค 6: HSRP บน Layer 3 Switch และหลาย VLAN

HSRP หลาย VLAN

ใน Enterprise LAN HSRP มักถูกใช้งานบน SVI ของ Layer 3 Switch

ตัวอย่าง:

VLAN 10 USERS
192.168.10.0/24
Virtual GW 192.168.10.1

VLAN 20 SERVERS
192.168.20.0/24
Virtual GW 192.168.20.1

VLAN 30 GUEST
192.168.30.0/24
Virtual GW 192.168.30.1

Topology:

             Core / WAN
             /        \
            /          \
          SW1          SW2
           |            |
           +------------+
                |
          Access Switches
                |
       +--------+--------+
       |        |        |
     VLAN10   VLAN20   VLAN30

SW1 — VLAN 10

interface Vlan10
 ip address 192.168.10.2 255.255.255.0
 standby 10 ip 192.168.10.1
 standby 10 priority 110
 standby 10 preempt

SW2 — VLAN 10

interface Vlan10
 ip address 192.168.10.3 255.255.255.0
 standby 10 ip 192.168.10.1
 standby 10 priority 100
 standby 10 preempt

Hosts ใช้:

Default Gateway
192.168.10.1

ไม่ควรตั้ง Default Gateway ของ Clients เป็น 192.168.10.2 หรือ 192.168.10.3 หาก Design ต้องการใช้ HSRP Virtual Gateway

สามารถแบ่ง Active Gateway ระหว่าง VLAN ได้หรือไม่?

ในระบบที่มีหลาย VLAN สามารถออกแบบให้ อุปกรณ์แต่ละตัวเป็น Active ของคนละ HSRP Group เพื่อกระจายบทบาท ได้ตาม Architecture

ตัวอย่าง:

VLAN 10
SW1 = Active
SW2 = Standby

VLAN 20
SW1 = Standby
SW2 = Active

แนวคิด:

          SW1             SW2
           |               |
      Active VLAN10   Active VLAN20
      Standby VLAN20  Standby VLAN10
การกระจาย Active Gateway ควรสอดคล้องกับ Layer 2 Path, STP Root Placement, Uplinks และ Routing Design ไม่เช่นนั้น Traffic อาจเดิน อ้อมเส้นทางโดยไม่จำเป็น

ภาค 7: Cisco HSRP Lab

Lab: สร้าง Redundant Default Gateway

Topology:

            PC-A
     192.168.10.100
             |
             |
           SW-ACCESS
          /         \
         /           \
       R1             R2
192.168.10.2     192.168.10.3
Priority 110     Priority 100
     |                |
     +----------------+
              |
       Virtual Gateway
        192.168.10.1

PC-A

IP Address:
192.168.10.100

Subnet Mask:
255.255.255.0

Default Gateway:
192.168.10.1

R1 Configuration

interface GigabitEthernet0/0
 description LAN-HSRP
 ip address 192.168.10.2 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 110
 standby 10 preempt
 no shutdown

R2 Configuration

interface GigabitEthernet0/0
 description LAN-HSRP
 ip address 192.168.10.3 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 100
 standby 10 preempt
 no shutdown

ตรวจ HSRP

R1# show standby brief
R2# show standby brief

คาดหวัง:

R1
State: Active
Priority: 110

R2
State: Standby
Priority: 100

Virtual IP:
192.168.10.1

ทดสอบ HSRP Failover

ก่อนทดสอบ Failover ให้เปิด Continuous Ping จาก Client ไปยัง Remote Destination ที่เหมาะสมใน Lab

Windows:

ping 192.168.20.100 -t

จากนั้นจำลอง Failure ใน Lab เช่น Shutdown LAN Interface ของ Active Router:

R1(config)# interface GigabitEthernet0/0
R1(config-if)# shutdown

ตรวจ R2:

R2# show standby brief

คาดหวัง:

R2
Standby
   |
   | Active unavailable
   v
Active

จากนั้นเปิด R1 กลับ:

R1(config)# interface GigabitEthernet0/0
R1(config-if)# no shutdown

หาก Priority และ Preempt ถูกตั้งตาม Lab R1 สามารถกลับมาเป็น Preferred Active เมื่อเงื่อนไขครบ

การ Shutdown Interface เพื่อทดสอบ Failover ควรทำใน Lab หรือ Maintenance Window ที่ได้รับอนุญาตเท่านั้น ไม่ควรทดลองกับ Production Gateway โดยไม่มี Change Plan

ภาค 8: HSRP Troubleshooting

HSRP ไม่ทำงาน ตรวจอะไรบ้าง?

เริ่มจาก:

show ip interface brief
show standby brief
show standby
show running-config interface GigabitEthernet0/0
show arp

ปัญหา 1 — ทั้งสอง Router ไม่เห็นกัน

ตรวจ:

  • Interface Up/Down
  • VLAN
  • Subnet
  • HSRP Version
  • Group Number
  • Virtual IP
  • Layer 2 Connectivity
  • ACL/Control Plane Filtering

ปัญหา 2 — Router ที่ต้องการไม่เป็น Active

ตรวจ:

show standby brief
show standby

ดู:

  • Priority
  • Preempt
  • Tracking
  • Current State
  • Interface State

ปัญหา 3 — Failover แล้ว Traffic ยังไม่ผ่าน

อย่าตรวจเฉพาะ HSRP

HSRP state changed?
       |
       v
Virtual gateway reachable?
       |
       v
New Active has route?
       |
       v
Uplink operational?
       |
       v
ARP/MAC updated?
       |
       v
ACL / Firewall?
       |
       v
Return route?

ปัญหา 4 — HSRP Active ปกติ แต่ Uplink เสีย

นี่มักเป็นปัญหา ของ Failure Detection Scope

LAN interface = UP
HSRP = Active

but

WAN/Core path = DOWN

พิจารณา Interface Tracking หรือ Object Tracking ตาม Requirement

ปัญหา 5 — Client ใช้ Gateway ผิด

ตรวจ Client:

ipconfig /all

ควรเห็น:

Default Gateway:
192.168.10.1

ไม่ใช่:

192.168.10.2
or
192.168.10.3

หาก DHCP แจก Gateway ต้องตรวจ DHCP Option ที่เกี่ยวข้องด้วย

ภาค 9: High Availability Design

HSRP เพียงอย่างเดียวทำให้ Network High Availability หรือไม่?

ไม่

HSRP แก้ Redundancy ของ Default Gateway แต่ Network ยังมี Single Point of Failure ที่ส่วนอื่นได้

                 ISP-A
                   |
                 Core-1
                   |
                 SW-1
                   |
                 Host

แม้เพิ่ม HSRP Router แต่หากมี Access Switch, Power Supply หรือ Uplink เพียงชุดเดียว ระบบยังมี Failure Point อยู่

High Availability ต้องมองทั้ง Path:

Endpoint
   |
   v
Access Layer
   |
   v
Distribution / Gateway
   |
   v
Core
   |
   v
Firewall
   |
   v
WAN / ISP
   |
   v
Application / Service

ตัวอย่าง Redundant Architecture

             ISP-A       ISP-B
               |           |
               |           |
             Core-1 ===== Core-2
               |\           /|
               | \         / |
               |  \       /  |
               |   \     /   |
               |    \   /    |
             SW-A ======== SW-B
                \          /
                 \        /
                  \      /
                 Access
                   |
                  Host

แต่ละ Layer อาจต้องใช้ Technology แตกต่างกัน เช่น:

Layer/Requirement Technology ตัวอย่าง
Default Gateway HSRP / VRRP
Layer 2 Loop Prevention STP / RSTP / MST
Link Redundancy EtherChannel / LACP
Routing Redundancy OSPF / EIGRP / BGP ตาม Architecture
Path Monitoring Object Tracking / IP SLA ตาม Platform และ Design
Firewall Redundancy Vendor-specific HA/Cluster Technology

วิเคราะห์ Failure Scenario ก่อนใช้งานจริง

Failure HSRP อย่างเดียวช่วยได้? สิ่งที่ต้องพิจารณาเพิ่ม
Active Router ดับ โดยหลักช่วยได้ Standby และ Path ต้องพร้อม
LAN Interface ของ Active ดับ โดยหลักตรวจจับได้ตาม FHRP State ตรวจ Failover Time
Uplink ของ Active ดับ ไม่จำเป็นต้องรู้โดยอัตโนมัติทุกกรณี Tracking
Remote ISP เสีย แต่ Interface ยัง Up ไม่เพียงพอ IP SLA/Object Tracking หรือ Routing Design
Access Switch ดับ ไม่ช่วย Switch/Uplink Redundancy
Firewall ดับ ไม่ช่วยโดยตรง Firewall HA
Application Server ดับ ไม่ช่วย Server/Application HA
High Availability ที่ดี ไม่ได้ถามเพียงว่า “มีอุปกรณ์สำรองหรือไม่?” แต่ต้องถามว่า “เมื่อองค์ประกอบใดองค์ประกอบหนึ่งเสีย Traffic สามารถเปลี่ยนไปใช้ Path ที่ยังทำงานได้จริงหรือไม่?”

Cisco HSRP Command Cheat Sheet

Command หน้าที่
standby 10 ip 192.168.10.1 กำหนด HSRP Virtual IP
standby 10 priority 110 กำหนด Priority
standby 10 preempt อนุญาตให้ Router ที่เหมาะสมกลับมารับ Active Role ตาม Election Conditions
standby version 2 กำหนด HSRP Version 2 บน Interface ที่รองรับ
standby 10 track ... ผูก HSRP Priority กับ Tracking ตาม Syntax ของ Platform
show standby brief ดู HSRP Status แบบย่อ
show standby ดูรายละเอียด HSRP
show ip interface brief ตรวจ Interface และ IP
show track ตรวจ Track Objects บน Platform ที่รองรับ
show ip route ตรวจ Routing Table ของ Gateway
show arp ตรวจ ARP Information

FHRP Troubleshooting Workflow

Client has correct Virtual Gateway?
              |
              v
Gateway reachable?
              |
              v
Both routers' LAN interfaces up?
              |
              v
Same subnet/VLAN?
              |
              v
Same HSRP version/group?
              |
              v
Virtual IP consistent?
              |
              v
Active/Standby states correct?
              |
              v
Priority / Preempt correct?
              |
              v
Tracking state correct?
              |
              v
Active router has valid route?
              |
              v
Uplink actually reachable?
              |
              v
Return path correct?
              |
              v
ACL / Firewall / NAT
              |
              v
Application

คำถามที่พบบ่อย — FAQ

HSRP คืออะไร?

HSRP คือ First Hop Redundancy Protocol ที่ใช้สร้าง Virtual Default Gateway ระหว่างอุปกรณ์ Cisco เพื่อให้มี Gateway สำรอง เมื่ออุปกรณ์ที่รับหน้าที่หลัก ไม่สามารถให้บริการได้

FHRP คืออะไร?

FHRP คือกลุ่ม Protocol สำหรับสร้าง First-Hop หรือ Default Gateway Redundancy ให้กับ End Devices โดย HSRP และ VRRP เป็นตัวอย่างของ FHRP

Virtual IP คืออะไร?

เป็น IP Address ที่ Hosts ใช้เป็น Default Gateway แทนการผูกกับ Physical IP ของ Router ตัวใดตัวหนึ่งโดยตรง

Client ควรใช้ IP ของ Active Router เป็น Gateway หรือไม่?

หาก Network ถูกออกแบบด้วย FHRP Client ควรใช้ Virtual IP ที่กำหนดเป็น Default Gateway ไม่ใช่ Physical Interface IP ของ Router ตัวใดตัวหนึ่ง

HSRP Priority สูงกว่าหมายความว่าเป็น Active เสมอหรือไม่?

ไม่ควรตีความเช่นนั้นโดยไม่มีบริบท เพราะ Current State, Preemption, Tracking และ Election Conditions มีผลต่อบทบาทของ Router

Preempt มีไว้ทำอะไร?

ใช้อนุญาตให้ Router ที่มี Priority เหมาะสมกว่า สามารถกลับมารับ Active Role เมื่อกลับมาพร้อมใช้งาน ตามเงื่อนไขของ HSRP

HSRP แทน OSPF ได้หรือไม่?

ไม่ได้ HSRP ใช้สำหรับ Default Gateway Redundancy ส่วน OSPF เป็น Dynamic Routing Protocol สำหรับแลกเปลี่ยน Routing Information และคำนวณเส้นทางระหว่าง Routers

มี OSPF แล้วจำเป็นต้องมี HSRP หรือไม่?

ขึ้นอยู่กับ Architecture OSPF สามารถสร้าง Routing Redundancy ระหว่าง Routers แต่ไม่ได้ทำให้ Default Gateway ที่ Host ตั้งค่าไว้ มี Redundancy โดยอัตโนมัติ

HSRP กับ VRRP ต่างกันอย่างไร?

ทั้งสองเป็น FHRP สำหรับ Gateway Redundancy แต่ HSRP มีความสัมพันธ์กับ Cisco ขณะที่ VRRP เป็นมาตรฐาน ที่รองรับในระบบหลาย Vendor รายละเอียด State, Election และ Protocol Behavior แตกต่างกัน

ถ้า Active Router ยังทำงานแต่ Internet เสีย HSRP จะสลับหรือไม่?

ไม่จำเป็น หาก Failure ไม่ทำให้ เงื่อนไขที่ HSRP ตรวจสอบเปลี่ยน จึงอาจต้องใช้ Interface Tracking, Object Tracking, IP SLA หรือ Routing Mechanism ตาม Architecture

HSRP ทำ Load Balancing หรือไม่?

HSRP Group โดยพื้นฐาน มี Router ที่รับ Active Role สำหรับ Virtual Gateway นั้น แต่ในระบบหลาย VLAN สามารถออกแบบให้ คนละอุปกรณ์เป็น Active สำหรับคนละ Group/VLAN เพื่อกระจายบทบาทได้

HSRP ทำให้ Network ไม่มี Downtime หรือไม่?

ไม่ HSRP ลดผลกระทบจาก Gateway Failure บางประเภท แต่ Failover ยังขึ้นกับ Timer, Detection, Tracking, Layer 2, Routing และ Application จึงไม่ควรตีความว่า HSRP รับประกัน Zero Downtime

สรุป

Dynamic Routing อย่าง OSPF ช่วยให้ Routers หาเส้นทางสำรองได้ แต่ End Devices ยังต้องมี Default Gateway สำหรับออกจาก Local Subnet

หาก Default Gateway ผูกกับ Router เพียงตัวเดียว:

Hosts
  |
  v
Single Gateway
  |
  X
Failure
  |
  v
Remote Network unavailable

FHRP จึงเพิ่ม Virtual Gateway:

             Hosts
               |
               v
        Virtual Gateway
               |
        192.168.10.1
          /         \
         /           \
        v             v
       R1             R2
     Active         Standby

สำหรับ HSRP ควรเข้าใจอย่างน้อย:

Virtual IP
    |
    v
Active / Standby
    |
    v
Priority
    |
    v
Preempt
    |
    v
Tracking
    |
    v
Failover

แต่ Gateway Redundancy เป็นเพียงส่วนหนึ่งของ High Availability

High Availability

Gateway Redundancy
        +
Link Redundancy
        +
Switch Redundancy
        +
Routing Redundancy
        +
Firewall Redundancy
        +
WAN Redundancy
        +
Application Redundancy

ดังนั้นการออกแบบ Network ไม่ควรหยุดที่คำถามว่า “มี Router สองตัวหรือยัง?” แต่ควรวิเคราะห์ Failure Path ตั้งแต่ Client ไปจนถึง Service ที่ต้องการใช้งาน

บทความถัดไปควรลงลึกต่อที่ HSRP Tracking, IP SLA และ Object Tracking บน Cisco เพื่อแก้สถานการณ์ที่ Router และ LAN Interface ยัง Up แต่ Uplink, ISP หรือ Remote Path ไม่สามารถใช้งานได้จริง

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.