Techerest

HSRP vs VRRP vs GLBP: สร้าง Default Gateway Redundancy บน Cisco

HSRP, VRRP และ GLBP เป็นเทคโนโลยีกลุ่ม First Hop Redundancy Protocol หรือ FHRP ที่ใช้ลดปัญหา Default Gateway เป็น Single Point of Failure โดยสร้าง Virtual Gateway ให้ Client ใช้งานแทน IP Address ของ Router หรือ Layer 3 Switch ตัวใดตัวหนึ่งโดยตรง

บทความนี้จะเปรียบเทียบ HSRP vs VRRP vs GLBP ตั้งแต่ Virtual IP, Priority, Preempt, Failover ไปจนถึงความแตกต่างด้าน Gateway Load Balancing พร้อมตัวอย่าง Cisco Configuration และแนวทาง Troubleshooting ก่อนเข้าสู่หัวข้อ IP SLA และ Object Tracking ในบทถัดไป

ภาค 1: ทำไม Default Gateway ต้องมี Redundancy?

ปัญหา Default Gateway แบบ Single Point of Failure

สมมติว่า Client ทั้งหมด ใน VLAN 10 ใช้ Default Gateway:

192.168.10.1

Network:

PC1 ----\
PC2 -----+---- SW1 ---- R1 ---- Network / Internet
PC3 ----/              |
                    192.168.10.1

ถ้า R1 หรือ Interface ที่ทำหน้าที่ Gateway ล้มเหลว:

PC1 ----\
PC2 -----+---- SW1 ---- X R1
PC3 ----/

Default Gateway
192.168.10.1
Unavailable

แม้ Switch และ Client จะยังทำงานตามปกติ แต่ Client จะไม่สามารถ ส่ง Traffic ไปยัง Remote Network ผ่าน Gateway ดังกล่าวได้

นี่คือปัญหา First-Hop Single Point of Failure

เพิ่ม Router ตัวที่สองเพียงอย่างเดียวพอหรือไม่?

สมมติเพิ่ม R2:

             +---- R1
             |
LAN ---- SW1-+
             |
             +---- R2

แต่ Client ยังตั้ง Gateway เป็น:

192.168.10.1

หาก IP นี้อยู่บน R1 การมี R2 อยู่ใน Network ไม่ได้ทำให้ Client เปลี่ยน Gateway ไปหา R2 โดยอัตโนมัติ

จึงต้องมี Mechanism สำหรับสร้าง Logical หรือ Virtual Gateway ร่วมกัน

FHRP คืออะไร?

First Hop Redundancy Protocol (FHRP) เป็นกลุ่ม Protocol ที่ช่วยให้ Router หรือ Layer 3 Switch หลายตัว ทำงานร่วมกันเพื่อให้ Default Gateway มี Redundancy

แนวคิด:

                   R1
              192.168.10.2
                    |
                    |
PC ---- SW ---------+
                    |
                    |
              192.168.10.3
                   R2


Virtual Gateway
192.168.10.1

Client ไม่จำเป็นต้องรู้ว่า R1 หรือ R2 กำลังทำหน้าที่ Forward Traffic

Client ใช้:

Default Gateway
192.168.10.1

Virtual IP และ Virtual MAC คืออะไร?

FHRP สร้าง Logical Gateway ที่มี Virtual IP Address และโดย Protocol จะใช้ Virtual MAC Address ตามกลไกของ Protocol นั้น

ตัวอย่าง:

R1 Physical IP
192.168.10.2

R2 Physical IP
192.168.10.3

Virtual IP
192.168.10.1

Client:

IP Address:
192.168.10.100

Subnet Mask:
255.255.255.0

Default Gateway:
192.168.10.1

Client จึงผูกการใช้งาน Gateway กับ Virtual Gateway แทน Router Physical IP ตัวใดตัวหนึ่ง

ภาค 2: HSRP

HSRP คืออะไร?

HSRP — Hot Standby Router Protocol เป็น FHRP ที่ใช้กันแพร่หลาย ในระบบ Cisco เพื่อสร้าง Virtual Default Gateway ระหว่างอุปกรณ์หลายตัว

ในรูปแบบพื้นฐาน:

              HSRP Group 10

           +----------------+
           |                |
          R1               R2
       ACTIVE            STANDBY
     192.168.10.2      192.168.10.3
           \                /
            \              /
             +-----SW------+
                   |
                   |
                  PC

Virtual IP
192.168.10.1

Router ที่เป็น Active ทำหน้าที่ Forward Traffic สำหรับ Virtual Gateway

อีกตัวทำหน้าที่ Standby และสามารถรับบทบาทแทน เมื่อ Active ไม่สามารถ ทำหน้าที่ได้

HSRP States

HSRP มี State ที่เกี่ยวข้องกับกระบวนการ เข้าสู่บทบาท Active/Standby เช่น:

Initial
   |
   v
Learn
   |
   v
Listen
   |
   v
Speak
   |
   +--------+
   |        |
   v        v
Standby   Active

รายละเอียด State Transition อาจขึ้นอยู่กับสถานการณ์ และ HSRP Version แต่สำหรับการออกแบบทั่วไป สิ่งสำคัญคือเข้าใจ Active, Standby และ Virtual Gateway

HSRP Priority คืออะไร?

Priority ใช้ช่วยกำหนดว่า Router ใดควรเป็น Active

ตัวอย่าง:

R1 Priority = 110
R2 Priority = 100

หากเงื่อนไขอื่นเหมาะสม R1 ซึ่งมี Priority สูงกว่า จะถูกเลือกให้เป็น Active

ตัวอย่าง Configuration:

standby 10 priority 110
ค่า Default และ Election Tie-Breaker ควรตรวจจาก Cisco Documentation ของ HSRP Version และ Platform ที่ใช้งานจริง โดยในการออกแบบ ควรกำหนด Priority อย่างชัดเจน เพื่อให้ผลลัพธ์ตรงตาม Design

HSRP Preempt คืออะไร?

สมมติ:

R1 Priority 110
R2 Priority 100

R1 เป็น Active แล้ว R1 Down ทำให้ R2 ขึ้นมาทำหน้าที่แทน

Before Failure

R1 = ACTIVE
R2 = STANDBY


R1 fails


After Failure

R1 = DOWN
R2 = ACTIVE

เมื่อ R1 กลับมา หากต้องการให้ R1 ซึ่งมี Priority สูงกว่า กลับมารับบทบาท Active สามารถใช้:

standby 10 preempt

แนวคิด:

R1 returns
Priority 110
     |
     | Preempt
     v
R1 becomes ACTIVE

R2
Priority 100
     |
     v
STANDBY
Preempt ไม่ควรถูกเปิดโดยไม่พิจารณา Network Stability เพราะ Router ที่เพิ่ง Recovery อาจยังไม่พร้อม สำหรับ Forward Traffic ทุกเส้นทาง จึงอาจต้องพิจารณา Preempt Delay, Tracking หรือ IP SLA ร่วมด้วย

ภาค 3: VRRP

VRRP คืออะไร?

VRRP — Virtual Router Redundancy Protocol เป็นมาตรฐาน FHRP สำหรับสร้าง Virtual Router และ Default Gateway Redundancy

แนวคิดคล้าย HSRP:

              Virtual Router

           +----------------+
           |                |
          R1               R2
        MASTER           BACKUP
           \                /
            \              /
             +-----SW------+
                   |
                   |
                  PC

Virtual IP
192.168.10.1

VRRP ใช้คำว่า:

MASTER

BACKUP

แทนแนวคิด:

ACTIVE

STANDBY

ที่พบใน HSRP

ตัวอย่างแนวคิด VRRP Configuration

R1:

interface GigabitEthernet0/0
 ip address 192.168.10.2 255.255.255.0
 vrrp 10 ip 192.168.10.1
 vrrp 10 priority 110
 vrrp 10 preempt

R2:

interface GigabitEthernet0/0
 ip address 192.168.10.3 255.255.255.0
 vrrp 10 ip 192.168.10.1
 vrrp 10 priority 100
 vrrp 10 preempt
VRRP Syntax และ Feature Support แตกต่างได้ตาม Cisco Platform และ IOS/IOS XE Release จึงควรตรวจ Command Reference ก่อนนำ Configuration ไปใช้จริง

ภาค 4: GLBP

GLBP คืออะไร?

GLBP — Gateway Load Balancing Protocol เป็น First-Hop Redundancy Technology ของ Cisco ที่เพิ่มแนวคิด Gateway Load Balancing เข้ามานอกเหนือจาก Redundancy

ใน HSRP แบบพื้นฐาน Traffic ของ Group หนึ่ง มักถูก Forward ผ่าน Active Gateway เป็นหลัก:

Clients
   |
   v
Virtual Gateway
   |
   v
R1 ACTIVE
   |
   v
Upstream

R2 = STANDBY

GLBP ถูกออกแบบให้ หลาย Gateway สามารถมีบทบาท ในการ Forward Traffic ของกลุ่ม Client ได้

             Virtual Gateway
                    |
          +---------+---------+
          |                   |
          v                   v
         R1                  R2
       Forwarder           Forwarder
          |                   |
          +---------+---------+
                    |
                 Upstream

AVG และ AVF คืออะไร?

GLBP มีบทบาทสำคัญสองประเภท:

AVG — Active Virtual Gateway ทำหน้าที่จัดการ Virtual Gateway และการแจก Virtual MAC ตามกลไก GLBP

AVF — Active Virtual Forwarder เป็นอุปกรณ์ที่ทำหน้าที่ Forward Traffic สำหรับ Virtual MAC ที่ได้รับมอบหมาย

GLBP Group
    |
    +--- AVG
    |
    +--- AVF #1
    |
    +--- AVF #2

จึงทำให้ GLBP สามารถใช้ Gateway หลายตัว ในการ Forward Traffic ภายใน Group ได้

GLBP Load-Balancing Methods

GLBP สามารถรองรับ Load-Balancing Method ตาม Platform/Software เช่น:

  • Round-Robin
  • Weighted
  • Host-Dependent

แนวคิด Round-Robin:

Client A -> R1
Client B -> R2
Client C -> R1
Client D -> R2

แต่ GLBP ไม่ควรถูกตีความว่า เป็น Per-Packet Load Balancer สำหรับทุก Flow เพราะกลไกหลักเกี่ยวข้องกับ Virtual Gateway และ Virtual MAC ที่แจกให้ Client

ภาค 5: เปรียบเทียบ HSRP, VRRP และ GLBP

ตารางเปรียบเทียบ

หัวข้อ HSRP VRRP GLBP
ประเภท First-Hop Redundancy First-Hop Redundancy First-Hop Redundancy + Gateway Load Balancing
บทบาทหลัก Active / Standby Master / Backup AVG / AVF
Virtual IP มี มี มี
Gateway Redundancy มี มี มี
Gateway Load Balancing ภายใน Protocol ไม่ใช่จุดเด่นของ Group เดียว ไม่ใช่จุดเด่นหลัก มี
Vendor Scope Cisco Technology มาตรฐานเปิด Cisco Technology
Priority มี มี มี Mechanism สำหรับบทบาท Gateway/Forwarder
Preemption รองรับ รองรับตาม VRRP Behavior/Configuration มี Mechanism ตาม GLBP Role
การเลือก Protocol ต้องตรวจ Hardware, Software Release, Feature Support และ Architecture ของระบบจริง ไม่ควรเลือกจาก ชื่อ Protocol เพียงอย่างเดียว

ภาค 6: Gateway Failover

Gateway Failover ทำงานอย่างไร?

สมมติ HSRP:

Virtual IP
192.168.10.1

       |
       +----------------+
       |                |
      R1               R2
    ACTIVE           STANDBY
Priority 110       Priority 100

เมื่อ R1 Fail:

R1
 X

       |
       v

R2
STANDBY
   |
   v
ACTIVE

Client ยังคงใช้:

192.168.10.1

ไม่ต้องเปลี่ยน Default Gateway ไปเป็น Physical IP ของ R2

แต่ถ้า R1 ยัง Up แต่ Internet Path เสียล่ะ?

นี่เป็นกรณีสำคัญ:

PC
 |
SW
 |
R1 ACTIVE
 |
Gi0/1 = UP
 |
 X
Internet Path Failed

หาก FHRP ตรวจเพียง Local Interface/Peer Availability R1 อาจยังคงบทบาท Active แม้เส้นทางที่ต้องการใช้งาน จะมีปัญหาที่ไกลออกไป

นี่คือเหตุผลที่ต้องต่อยอดด้วย:

Interface Tracking
       |
       v
Object Tracking
       |
       v
IP SLA
       |
       v
Smarter Failover

ซึ่งจะเป็นหัวข้อสำคัญ ในบทความถัดไป

Redundancy กับ Load Balancing ต่างกันอย่างไร?

สองคำนี้ไม่ควรใช้แทนกัน

Redundancy

Primary
   |
   +---- Working

Backup
   |
   +---- Ready if primary fails

เป้าหมายหลักคือ Availability

Load Balancing

Traffic
   |
   +---- Path / Gateway A
   |
   +---- Path / Gateway B

เป้าหมายคือกระจายการใช้งาน ไปหลาย Resource ตามกลไกที่ออกแบบไว้

GLBP เพิ่มความสามารถ Gateway Load Balancing เข้าไปใน FHRP Design ขณะที่ HSRP/VRRP มักถูกใช้ในรูปแบบ Primary/Backup ต่อ Group

ภาค 7: FHRP กับ Multi-VLAN

หลาย VLAN ใช้ FHRP อย่างไร?

สมมติมี:

VLAN 10 USERS
192.168.10.0/24

VLAN 20 SALES
192.168.20.0/24

VLAN 30 SERVER
192.168.30.0/24

แต่ละ VLAN สามารถมี Virtual Gateway ของตัวเอง

VLAN 10
VIP = 192.168.10.1

VLAN 20
VIP = 192.168.20.1

VLAN 30
VIP = 192.168.30.1

กระจาย Active Gateway ด้วยหลาย HSRP Group

แม้ HSRP Group เดียว ไม่ได้ทำ Gateway Load Balancing แบบ GLBP แต่ในระบบหลาย VLAN สามารถออกแบบให้ Router คนละตัวเป็น Active ของแต่ละ VLAN ได้

              R1                R2
          +----------+      +----------+
VLAN 10   | ACTIVE   |      | STANDBY  |
VLAN 20   | STANDBY  |      | ACTIVE   |
VLAN 30   | ACTIVE   |      | STANDBY  |
          +----------+      +----------+

วิธีนี้ช่วยใช้ทรัพยากร ของ Gateway ทั้งสองตัว แต่เป็นการกระจาย ต่อ VLAN / ต่อ Group ไม่ใช่ Load Balancing แบบเดียวกับ GLBP

FHRP ทำงานร่วมกับ STP อย่างไร?

ใน Layer 2 Campus Network ควรพิจารณาความสัมพันธ์ระหว่าง:

STP Root Bridge
       +
FHRP Active Gateway

ตัวอย่าง Design:

VLAN 10

SW1 = STP Root
R1  = HSRP Active


VLAN 20

SW2 = STP Root
R2  = HSRP Active

การ Align บทบาท Layer 2 Forwarding กับ Layer 3 Gateway สามารถช่วยลด Traffic Path ที่ไม่จำเป็น ใน Architecture ที่เกี่ยวข้อง

ตัวอย่างที่ไม่ Align:

Client
  |
  v
SW1
  |
  | STP forwards toward SW2
  v
SW2
  |
  | Layer 2 path back/across
  v
R1 HSRP Active

Topology จริงขึ้นอยู่กับ Campus Design และ Platform จึงควรวิเคราะห์ Data Path มากกว่าจำกฎแบบตายตัว

ภาค 8: FHRP กับ Dynamic Routing

HSRP/VRRP/GLBP กับ OSPF ต่างกันอย่างไร?

FHRP และ OSPF แก้ปัญหาคนละส่วน

Technology หน้าที่
HSRP / VRRP / GLBP Default Gateway Redundancy สำหรับ End Host
OSPF แลกเปลี่ยนและเลือกเส้นทางระหว่าง Router/L3 Devices

ตัวอย่าง:

PC
 |
 | Default Gateway
 v
Virtual IP
 |
 +---- R1
 |       |
 |       +---- OSPF ---- Core
 |
 +---- R2
         |
         +---- OSPF ---- Core

FHRP ช่วย Client หา First-Hop Gateway ที่ยังใช้งานได้

OSPF ช่วย Router หาเส้นทางต่อไปยัง Remote Network

ภาค 9: Cisco HSRP Lab

Topology

                    CORE
                  /      \
                 /        \
               R1          R2
        192.168.10.2   192.168.10.3
               \          /
                \        /
                  SW1
                   |
                   |
                  PC1
            192.168.10.100

Virtual Gateway
192.168.10.1

R1 Configuration

interface GigabitEthernet0/0
 description VLAN10-LAN
 ip address 192.168.10.2 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 110
 standby 10 preempt
 no shutdown

R2 Configuration

interface GigabitEthernet0/0
 description VLAN10-LAN
 ip address 192.168.10.3 255.255.255.0
 standby version 2
 standby 10 ip 192.168.10.1
 standby 10 priority 100
 standby 10 preempt
 no shutdown

PC Configuration

IP Address:
192.168.10.100

Subnet Mask:
255.255.255.0

Default Gateway:
192.168.10.1

ตรวจ HSRP

show standby brief

ผลเชิงแนวคิด:

R1
Group 10
State Active
Priority 110
Virtual IP 192.168.10.1


R2
Group 10
State Standby
Priority 100
Virtual IP 192.168.10.1

Output จริงอาจแตกต่าง ตาม Platform และ IOS/IOS XE

ทดสอบ Failover

ก่อน Fail:

R1 = ACTIVE
R2 = STANDBY

จำลอง R1 LAN Interface Down:

R1(config)#interface GigabitEthernet0/0
R1(config-if)#shutdown

ตรวจ R2:

show standby brief

คาดหวัง:

R2
STANDBY -> ACTIVE

Client ยังคงใช้ Default Gateway เดิม:

192.168.10.1

Restore R1

R1(config)#interface GigabitEthernet0/0
R1(config-if)#no shutdown

เมื่อ R1 กลับมา Priority 110 และเปิด Preempt จึงสามารถกลับมารับ Active Role ตาม Design ได้

ภาค 10: Cisco VRRP Lab

ใช้ Topology เดียวกับ HSRP

R1
192.168.10.2

R2
192.168.10.3

Virtual IP
192.168.10.1

R1

interface GigabitEthernet0/0
 ip address 192.168.10.2 255.255.255.0
 vrrp 10 ip 192.168.10.1
 vrrp 10 priority 110
 vrrp 10 preempt
 no shutdown

R2

interface GigabitEthernet0/0
 ip address 192.168.10.3 255.255.255.0
 vrrp 10 ip 192.168.10.1
 vrrp 10 priority 100
 vrrp 10 preempt
 no shutdown

ตรวจ VRRP

show vrrp
show vrrp brief
คำสั่ง VRRP โดยเฉพาะ Syntax ของ VRRP Version ต่าง ๆ อาจแตกต่างตาม Platform และ IOS/IOS XE Release Lab จริงควรตรวจ Feature Support ของ Image ที่ใช้ก่อน

ภาค 11: GLBP Lab Concept

ตัวอย่าง GLBP

Topology:

              Virtual Gateway
              192.168.10.1
                    |
           +--------+--------+
           |                 |
          R1                R2
    192.168.10.2      192.168.10.3
           \                 /
            \               /
                  SW1
                   |
          +--------+--------+
          |                 |
         PC1               PC2

ตัวอย่าง Configuration:

interface GigabitEthernet0/0
 ip address 192.168.10.2 255.255.255.0
 glbp 10 ip 192.168.10.1
 glbp 10 priority 110
 glbp 10 preempt

R2:

interface GigabitEthernet0/0
 ip address 192.168.10.3 255.255.255.0
 glbp 10 ip 192.168.10.1
 glbp 10 priority 100
 glbp 10 preempt

ตรวจ:

show glbp
show glbp brief
GLBP ไม่ได้รองรับบน Cisco Platform หรือ Software Image ทุกชุด ดังนั้นก่อนออกแบบหรือสร้าง Lab ควรตรวจ Feature Availability ของอุปกรณ์หรือ Simulator ที่ใช้งานจริง

ภาค 12: Verification Commands

HSRP

show standby
show standby brief

VRRP

show vrrp
show vrrp brief

GLBP

show glbp
show glbp brief

ตรวจ Interface

show ip interface brief
show interfaces

ตรวจ Routing

show ip route
show ip route ospf

ตรวจ ARP

show ip arp

ตรวจ Configuration

show running-config interface GigabitEthernet0/0

ภาค 13: FHRP Troubleshooting

Troubleshooting Workflow

Physical Link
     |
     v
Interface UP?
     |
     v
IP / Subnet correct?
     |
     v
Same Layer 2 segment?
     |
     v
FHRP Group correct?
     |
     v
Virtual IP correct?
     |
     v
Protocol Version compatible?
     |
     v
Priority correct?
     |
     v
Preempt correct?
     |
     v
Active/Master role correct?
     |
     v
Upstream route correct?
     |
     v
Return path correct?
     |
     v
Tracking / IP SLA?

ปัญหา 1 — Virtual IP ผิด

R1:

standby 10 ip 192.168.10.1

R2:

standby 10 ip 192.168.10.254

Configuration ของ Group ไม่สอดคล้องกัน

ตรวจ:

show standby brief

ปัญหา 2 — Group Number ไม่ตรงกัน

R1:

standby 10 ip 192.168.10.1

R2:

standby 20 ip 192.168.10.1

อุปกรณ์ไม่ได้อยู่ใน HSRP Group เดียวกัน ตามที่ตั้งใจ

ปัญหา 3 — Priority สูงกว่าแต่ไม่กลับมาเป็น Active

ตรวจ:

show standby brief

และตรวจว่า:

standby 10 preempt

ถูก Configure ตาม Design หรือไม่

ปัญหา 4 — Active Gateway ทำงาน แต่ไม่มี Upstream Route

PC
 |
 v
R1 ACTIVE
 |
 |
 X
No route to destination

HSRP สามารถทำงานปกติ แต่ Client ยังออก Internet หรือ Remote Network ไม่ได้

ตรวจ:

show ip route
show ip route 0.0.0.0

ปัญหา 5 — Uplink เสีย แต่ Active Role ไม่เปลี่ยน

ตัวอย่าง:

LAN Interface = UP

HSRP = ACTIVE

Uplink = UP

Remote path = FAILED

FHRP พื้นฐานอาจยังไม่ทราบ ว่า End-to-End Path ใช้งานไม่ได้

จึงต้องใช้:

IP SLA
  +
Object Tracking
  +
HSRP Tracking

ปัญหา 6 — Gateway Failover สำเร็จ แต่ Application หลุด

FHRP ช่วยเรื่อง Default Gateway Availability แต่ไม่ได้หมายความว่า Application Session ทุกประเภท จะถูก Preserve

เช่น:

Gateway Failover
       |
       v
Routing path changes
       |
       v
NAT state may change
       |
       v
Firewall state may change
       |
       v
Existing session may reset

โดยเฉพาะระบบที่มี NAT, Stateful Firewall หรือ Session State อยู่บน Edge Router

ภาค 14: Enterprise High Availability Design

FHRP เป็นเพียงส่วนหนึ่งของ High Availability

Network High Availability ไม่ได้จบที่ HSRP หรือ VRRP

                 ISP / CORE
                  /       \
                 /         \
               R1           R2
                \           /
                 \         /
                SW1=======SW2
                 |\       /|
                 | \     / |
                 |  \   /  |
               Users Servers

ต้องพิจารณาร่วมกัน:

  • Dual Gateway
  • FHRP
  • Dynamic Routing
  • STP / RSTP / MST
  • EtherChannel
  • Dual Uplink
  • IP SLA / Object Tracking
  • Power Redundancy
  • WAN Redundancy
  • Monitoring

ตัวอย่าง High Availability Stack

Client
  |
  v
Access Switch
  |
  +---- Redundant Links
  |
  v
Distribution Pair
  |
  +---- STP / EtherChannel
  |
  +---- HSRP / VRRP
  |
  +---- OSPF
  |
  +---- IP SLA / Tracking
  |
  v
Core / Internet

เลือกเทคโนโลยีตามหน้าที่

Requirement Technology
Default Gateway Redundancy HSRP / VRRP / GLBP ตาม Platform และ Design
Gateway Load Distribution GLBP หรือ Multi-Group Design ตาม Architecture
Dynamic Route Failover OSPF / EIGRP / BGP ตาม Network Scope
Layer 2 Loop Prevention STP / RSTP / MST
Link Aggregation EtherChannel / LACP
Remote Path Monitoring IP SLA
Track Operational State Object Tracking
Security Policy ACL / ZBF / Firewall

Production Checklist

1. Define Virtual IP

2. Define physical gateway IPs

3. Select FHRP protocol

4. Confirm platform support

5. Define group IDs

6. Define priority

7. Decide preempt behavior

8. Consider preempt delay

9. Identify upstream failure scenarios

10. Design interface/object tracking

11. Verify routing

12. Align STP/FHRP where appropriate

13. Test gateway failure

14. Test uplink failure

15. Test recovery

16. Monitor convergence

17. Test applications

18. Document rollback

19. Update network diagram

20. Record expected roles

ภาค 15: คำถามที่พบบ่อย

HSRP, VRRP และ GLBP ใช้ทำอะไร?

ทั้งสามเกี่ยวข้องกับ First-Hop Gateway Redundancy เพื่อช่วยลดปัญหา Default Gateway เป็น Single Point of Failure โดย GLBP เพิ่มกลไก Gateway Load Balancing เข้ามาด้วย

HSRP กับ VRRP ต่างกันอย่างไร?

ทั้งคู่สร้าง Virtual Gateway และ Gateway Redundancy แต่ HSRP เป็นเทคโนโลยี ที่เกี่ยวข้องกับ Cisco ขณะที่ VRRP เป็นมาตรฐานเปิด และใช้คำเรียกบทบาท ต่างกัน เช่น Active/Standby กับ Master/Backup

GLBP ต่างจาก HSRP อย่างไร?

GLBP เพิ่มความสามารถ ให้ Gateway หลายตัว มีบทบาท Forward Traffic ภายใน Group ขณะที่ HSRP แบบพื้นฐาน ใช้ Active Gateway เป็นตัว Forward หลัก ของ Group

Client ต้องเปลี่ยน Default Gateway เมื่อ Router Fail หรือไม่?

ไม่ต้อง Client ยังคงใช้ Virtual IP Address เดิม เป็น Default Gateway

Priority สูงกว่าหมายความว่าจะเป็น Active เสมอหรือไม่?

ไม่ควรสรุปเพียง Priority อย่างเดียว เพราะ Election State, Preemption, Availability และ Protocol Behavior มีผลต่อบทบาทด้วย

Preempt จำเป็นหรือไม่?

ขึ้นอยู่กับ Design หากต้องการให้ Gateway ที่กำหนด Priority สูงกว่า กลับมารับ Preferred Role หลัง Recovery ต้องพิจารณา Preemption รวมถึง Delay และ Stability

HSRP แทน OSPF ได้หรือไม่?

ไม่ได้ HSRP ดูแล First-Hop Gateway Redundancy ส่วน OSPF เป็น Dynamic Routing Protocol สำหรับแลกเปลี่ยนและเลือก Route

HSRP แทน STP ได้หรือไม่?

ไม่ได้ HSRP ทำงานด้าน Layer 3 Gateway Redundancy ส่วน STP ป้องกัน Layer 2 Switching Loop

มี Router สองตัวแล้วจำเป็นต้องใช้ FHRP หรือไม่?

หาก End Host ต้องการ Default Gateway ที่มี Redundancy การมี Router สองตัว เพียงอย่างเดียวไม่ได้ทำให้ Client เปลี่ยน Gateway โดยอัตโนมัติ จึงต้องมี Gateway Redundancy Mechanism ที่เหมาะสม

ทำไม HSRP Active ยังอยู่แม้ Internet ใช้ไม่ได้?

เพราะ Local FHRP State อาจยังปกติ ขณะที่ Remote Path มีปัญหา กรณีนี้สามารถต่อยอด ด้วย Interface Tracking, Object Tracking และ IP SLA ตาม Design

HSRP Failover ทำให้ NAT Session อยู่ต่อหรือไม่?

ไม่จำเป็น HSRP ให้ Gateway Redundancy แต่ไม่ได้ทำหน้าที่ Synchronize NAT Translation หรือ Stateful Firewall Session ระหว่าง Router โดยอัตโนมัติ

ควรทดสอบ High Availability อย่างไร?

ไม่ควรทดสอบเฉพาะ การ Shutdown Router แต่ควรจำลองหลาย Failure Mode:

Gateway failure

LAN interface failure

Uplink failure

Remote next-hop failure

Routing failure

Recovery / failback

Application session behavior

บทสรุป

HSRP, VRRP และ GLBP ช่วยแก้ปัญหา Default Gateway เป็น Single Point of Failure โดยให้ Client ใช้ Virtual Gateway แทน Physical Gateway ตัวใดตัวหนึ่ง

                  Virtual IP
                192.168.10.1
                     |
             +-------+-------+
             |               |
            R1              R2
      192.168.10.2     192.168.10.3
             \               /
              \             /
                   LAN
                    |
                  Client

HSRP ใช้แนวคิด Active/Standby และพบได้บ่อยใน Cisco Network

VRRP เป็นมาตรฐาน First-Hop Redundancy ที่ใช้แนวคิด Master/Backup

GLBP เพิ่มความสามารถ Gateway Load Balancing โดยมีแนวคิด AVG และ AVF

HSRP
Gateway Redundancy
Active / Standby


VRRP
Gateway Redundancy
Master / Backup


GLBP
Gateway Redundancy
        +
Gateway Load Balancing

อย่างไรก็ตาม FHRP เพียงอย่างเดียว ยังไม่ครอบคลุม Failure ทุกประเภท

Gateway is alive
       |
       v
LAN Interface is UP
       |
       v
FHRP says ACTIVE
       |
       v
But remote Internet path
may already be DOWN

ดังนั้นขั้นต่อไปของ Network High Availability คือการทำให้ Gateway ตรวจสอบสถานะของ เส้นทางที่อยู่ไกลออกไปได้

บทความถัดไป: IP SLA, Object Tracking และ HSRP Tracking บน Cisco: สร้าง Gateway Failover ที่ตรวจสอบเส้นทางได้จริง

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.