HSRP, VRRP และ GLBP เป็นเทคโนโลยีกลุ่ม First Hop Redundancy Protocol หรือ FHRP ที่ใช้ลดปัญหา Default Gateway เป็น Single Point of Failure โดยสร้าง Virtual Gateway ให้ Client ใช้งานแทน IP Address ของ Router หรือ Layer 3 Switch ตัวใดตัวหนึ่งโดยตรง
บทความนี้จะเปรียบเทียบ HSRP vs VRRP vs GLBP ตั้งแต่ Virtual IP, Priority, Preempt, Failover ไปจนถึงความแตกต่างด้าน Gateway Load Balancing พร้อมตัวอย่าง Cisco Configuration และแนวทาง Troubleshooting ก่อนเข้าสู่หัวข้อ IP SLA และ Object Tracking ในบทถัดไป
สารบัญ
- ปัญหา Default Gateway แบบ Single Point of Failure
- FHRP คืออะไร?
- Virtual IP และ Virtual MAC คืออะไร?
- HSRP คืออะไร?
- HSRP Priority และ Preempt
- VRRP คืออะไร?
- GLBP คืออะไร?
- เปรียบเทียบ HSRP, VRRP และ GLBP
- Gateway Failover ทำงานอย่างไร?
- Redundancy กับ Load Balancing ต่างกันอย่างไร?
- FHRP กับ Multi-VLAN
- FHRP ทำงานร่วมกับ STP อย่างไร?
- FHRP กับ OSPF ต่างกันอย่างไร?
- Cisco HSRP Lab
- Cisco VRRP Lab
- แนวคิด GLBP Lab
- Verification Commands
- Troubleshooting
- Enterprise Design
- FAQ
- บทสรุป
ภาค 1: ทำไม Default Gateway ต้องมี Redundancy?
ปัญหา Default Gateway แบบ Single Point of Failure
สมมติว่า Client ทั้งหมด ใน VLAN 10 ใช้ Default Gateway:
192.168.10.1
Network:
PC1 ----\
PC2 -----+---- SW1 ---- R1 ---- Network / Internet
PC3 ----/ |
192.168.10.1
ถ้า R1 หรือ Interface ที่ทำหน้าที่ Gateway ล้มเหลว:
PC1 ----\
PC2 -----+---- SW1 ---- X R1
PC3 ----/
Default Gateway
192.168.10.1
Unavailable
แม้ Switch และ Client จะยังทำงานตามปกติ แต่ Client จะไม่สามารถ ส่ง Traffic ไปยัง Remote Network ผ่าน Gateway ดังกล่าวได้
นี่คือปัญหา First-Hop Single Point of Failure
เพิ่ม Router ตัวที่สองเพียงอย่างเดียวพอหรือไม่?
สมมติเพิ่ม R2:
+---- R1
|
LAN ---- SW1-+
|
+---- R2
แต่ Client ยังตั้ง Gateway เป็น:
192.168.10.1
หาก IP นี้อยู่บน R1 การมี R2 อยู่ใน Network ไม่ได้ทำให้ Client เปลี่ยน Gateway ไปหา R2 โดยอัตโนมัติ
จึงต้องมี Mechanism สำหรับสร้าง Logical หรือ Virtual Gateway ร่วมกัน
FHRP คืออะไร?
First Hop Redundancy Protocol (FHRP) เป็นกลุ่ม Protocol ที่ช่วยให้ Router หรือ Layer 3 Switch หลายตัว ทำงานร่วมกันเพื่อให้ Default Gateway มี Redundancy
แนวคิด:
R1
192.168.10.2
|
|
PC ---- SW ---------+
|
|
192.168.10.3
R2
Virtual Gateway
192.168.10.1
Client ไม่จำเป็นต้องรู้ว่า R1 หรือ R2 กำลังทำหน้าที่ Forward Traffic
Client ใช้:
Default Gateway
192.168.10.1
Virtual IP และ Virtual MAC คืออะไร?
FHRP สร้าง Logical Gateway ที่มี Virtual IP Address และโดย Protocol จะใช้ Virtual MAC Address ตามกลไกของ Protocol นั้น
ตัวอย่าง:
R1 Physical IP
192.168.10.2
R2 Physical IP
192.168.10.3
Virtual IP
192.168.10.1
Client:
IP Address:
192.168.10.100
Subnet Mask:
255.255.255.0
Default Gateway:
192.168.10.1
Client จึงผูกการใช้งาน Gateway กับ Virtual Gateway แทน Router Physical IP ตัวใดตัวหนึ่ง
ภาค 2: HSRP
HSRP คืออะไร?
HSRP — Hot Standby Router Protocol เป็น FHRP ที่ใช้กันแพร่หลาย ในระบบ Cisco เพื่อสร้าง Virtual Default Gateway ระหว่างอุปกรณ์หลายตัว
ในรูปแบบพื้นฐาน:
HSRP Group 10
+----------------+
| |
R1 R2
ACTIVE STANDBY
192.168.10.2 192.168.10.3
\ /
\ /
+-----SW------+
|
|
PC
Virtual IP
192.168.10.1
Router ที่เป็น Active ทำหน้าที่ Forward Traffic สำหรับ Virtual Gateway
อีกตัวทำหน้าที่ Standby และสามารถรับบทบาทแทน เมื่อ Active ไม่สามารถ ทำหน้าที่ได้
HSRP States
HSRP มี State ที่เกี่ยวข้องกับกระบวนการ เข้าสู่บทบาท Active/Standby เช่น:
Initial
|
v
Learn
|
v
Listen
|
v
Speak
|
+--------+
| |
v v
Standby Active
รายละเอียด State Transition อาจขึ้นอยู่กับสถานการณ์ และ HSRP Version แต่สำหรับการออกแบบทั่วไป สิ่งสำคัญคือเข้าใจ Active, Standby และ Virtual Gateway
HSRP Priority คืออะไร?
Priority ใช้ช่วยกำหนดว่า Router ใดควรเป็น Active
ตัวอย่าง:
R1 Priority = 110
R2 Priority = 100
หากเงื่อนไขอื่นเหมาะสม R1 ซึ่งมี Priority สูงกว่า จะถูกเลือกให้เป็น Active
ตัวอย่าง Configuration:
standby 10 priority 110
HSRP Preempt คืออะไร?
สมมติ:
R1 Priority 110
R2 Priority 100
R1 เป็น Active แล้ว R1 Down ทำให้ R2 ขึ้นมาทำหน้าที่แทน
Before Failure
R1 = ACTIVE
R2 = STANDBY
R1 fails
After Failure
R1 = DOWN
R2 = ACTIVE
เมื่อ R1 กลับมา หากต้องการให้ R1 ซึ่งมี Priority สูงกว่า กลับมารับบทบาท Active สามารถใช้:
standby 10 preempt
แนวคิด:
R1 returns
Priority 110
|
| Preempt
v
R1 becomes ACTIVE
R2
Priority 100
|
v
STANDBY
ภาค 3: VRRP
VRRP คืออะไร?
VRRP — Virtual Router Redundancy Protocol เป็นมาตรฐาน FHRP สำหรับสร้าง Virtual Router และ Default Gateway Redundancy
แนวคิดคล้าย HSRP:
Virtual Router
+----------------+
| |
R1 R2
MASTER BACKUP
\ /
\ /
+-----SW------+
|
|
PC
Virtual IP
192.168.10.1
VRRP ใช้คำว่า:
MASTER
BACKUP
แทนแนวคิด:
ACTIVE
STANDBY
ที่พบใน HSRP
ตัวอย่างแนวคิด VRRP Configuration
R1:
interface GigabitEthernet0/0
ip address 192.168.10.2 255.255.255.0
vrrp 10 ip 192.168.10.1
vrrp 10 priority 110
vrrp 10 preempt
R2:
interface GigabitEthernet0/0
ip address 192.168.10.3 255.255.255.0
vrrp 10 ip 192.168.10.1
vrrp 10 priority 100
vrrp 10 preempt
ภาค 4: GLBP
GLBP คืออะไร?
GLBP — Gateway Load Balancing Protocol เป็น First-Hop Redundancy Technology ของ Cisco ที่เพิ่มแนวคิด Gateway Load Balancing เข้ามานอกเหนือจาก Redundancy
ใน HSRP แบบพื้นฐาน Traffic ของ Group หนึ่ง มักถูก Forward ผ่าน Active Gateway เป็นหลัก:
Clients
|
v
Virtual Gateway
|
v
R1 ACTIVE
|
v
Upstream
R2 = STANDBY
GLBP ถูกออกแบบให้ หลาย Gateway สามารถมีบทบาท ในการ Forward Traffic ของกลุ่ม Client ได้
Virtual Gateway
|
+---------+---------+
| |
v v
R1 R2
Forwarder Forwarder
| |
+---------+---------+
|
Upstream
AVG และ AVF คืออะไร?
GLBP มีบทบาทสำคัญสองประเภท:
AVG — Active Virtual Gateway ทำหน้าที่จัดการ Virtual Gateway และการแจก Virtual MAC ตามกลไก GLBP
AVF — Active Virtual Forwarder เป็นอุปกรณ์ที่ทำหน้าที่ Forward Traffic สำหรับ Virtual MAC ที่ได้รับมอบหมาย
GLBP Group
|
+--- AVG
|
+--- AVF #1
|
+--- AVF #2
จึงทำให้ GLBP สามารถใช้ Gateway หลายตัว ในการ Forward Traffic ภายใน Group ได้
GLBP Load-Balancing Methods
GLBP สามารถรองรับ Load-Balancing Method ตาม Platform/Software เช่น:
- Round-Robin
- Weighted
- Host-Dependent
แนวคิด Round-Robin:
Client A -> R1
Client B -> R2
Client C -> R1
Client D -> R2
แต่ GLBP ไม่ควรถูกตีความว่า เป็น Per-Packet Load Balancer สำหรับทุก Flow เพราะกลไกหลักเกี่ยวข้องกับ Virtual Gateway และ Virtual MAC ที่แจกให้ Client
ภาค 5: เปรียบเทียบ HSRP, VRRP และ GLBP
ตารางเปรียบเทียบ
| หัวข้อ | HSRP | VRRP | GLBP |
|---|---|---|---|
| ประเภท | First-Hop Redundancy | First-Hop Redundancy | First-Hop Redundancy + Gateway Load Balancing |
| บทบาทหลัก | Active / Standby | Master / Backup | AVG / AVF |
| Virtual IP | มี | มี | มี |
| Gateway Redundancy | มี | มี | มี |
| Gateway Load Balancing ภายใน Protocol | ไม่ใช่จุดเด่นของ Group เดียว | ไม่ใช่จุดเด่นหลัก | มี |
| Vendor Scope | Cisco Technology | มาตรฐานเปิด | Cisco Technology |
| Priority | มี | มี | มี Mechanism สำหรับบทบาท Gateway/Forwarder |
| Preemption | รองรับ | รองรับตาม VRRP Behavior/Configuration | มี Mechanism ตาม GLBP Role |
ภาค 6: Gateway Failover
Gateway Failover ทำงานอย่างไร?
สมมติ HSRP:
Virtual IP
192.168.10.1
|
+----------------+
| |
R1 R2
ACTIVE STANDBY
Priority 110 Priority 100
เมื่อ R1 Fail:
R1
X
|
v
R2
STANDBY
|
v
ACTIVE
Client ยังคงใช้:
192.168.10.1
ไม่ต้องเปลี่ยน Default Gateway ไปเป็น Physical IP ของ R2
แต่ถ้า R1 ยัง Up แต่ Internet Path เสียล่ะ?
นี่เป็นกรณีสำคัญ:
PC
|
SW
|
R1 ACTIVE
|
Gi0/1 = UP
|
X
Internet Path Failed
หาก FHRP ตรวจเพียง Local Interface/Peer Availability R1 อาจยังคงบทบาท Active แม้เส้นทางที่ต้องการใช้งาน จะมีปัญหาที่ไกลออกไป
นี่คือเหตุผลที่ต้องต่อยอดด้วย:
Interface Tracking
|
v
Object Tracking
|
v
IP SLA
|
v
Smarter Failover
ซึ่งจะเป็นหัวข้อสำคัญ ในบทความถัดไป
Redundancy กับ Load Balancing ต่างกันอย่างไร?
สองคำนี้ไม่ควรใช้แทนกัน
Redundancy
Primary
|
+---- Working
Backup
|
+---- Ready if primary fails
เป้าหมายหลักคือ Availability
Load Balancing
Traffic
|
+---- Path / Gateway A
|
+---- Path / Gateway B
เป้าหมายคือกระจายการใช้งาน ไปหลาย Resource ตามกลไกที่ออกแบบไว้
GLBP เพิ่มความสามารถ Gateway Load Balancing เข้าไปใน FHRP Design ขณะที่ HSRP/VRRP มักถูกใช้ในรูปแบบ Primary/Backup ต่อ Group
ภาค 7: FHRP กับ Multi-VLAN
หลาย VLAN ใช้ FHRP อย่างไร?
สมมติมี:
VLAN 10 USERS
192.168.10.0/24
VLAN 20 SALES
192.168.20.0/24
VLAN 30 SERVER
192.168.30.0/24
แต่ละ VLAN สามารถมี Virtual Gateway ของตัวเอง
VLAN 10
VIP = 192.168.10.1
VLAN 20
VIP = 192.168.20.1
VLAN 30
VIP = 192.168.30.1
กระจาย Active Gateway ด้วยหลาย HSRP Group
แม้ HSRP Group เดียว ไม่ได้ทำ Gateway Load Balancing แบบ GLBP แต่ในระบบหลาย VLAN สามารถออกแบบให้ Router คนละตัวเป็น Active ของแต่ละ VLAN ได้
R1 R2
+----------+ +----------+
VLAN 10 | ACTIVE | | STANDBY |
VLAN 20 | STANDBY | | ACTIVE |
VLAN 30 | ACTIVE | | STANDBY |
+----------+ +----------+
วิธีนี้ช่วยใช้ทรัพยากร ของ Gateway ทั้งสองตัว แต่เป็นการกระจาย ต่อ VLAN / ต่อ Group ไม่ใช่ Load Balancing แบบเดียวกับ GLBP
FHRP ทำงานร่วมกับ STP อย่างไร?
ใน Layer 2 Campus Network ควรพิจารณาความสัมพันธ์ระหว่าง:
STP Root Bridge
+
FHRP Active Gateway
ตัวอย่าง Design:
VLAN 10
SW1 = STP Root
R1 = HSRP Active
VLAN 20
SW2 = STP Root
R2 = HSRP Active
การ Align บทบาท Layer 2 Forwarding กับ Layer 3 Gateway สามารถช่วยลด Traffic Path ที่ไม่จำเป็น ใน Architecture ที่เกี่ยวข้อง
ตัวอย่างที่ไม่ Align:
Client
|
v
SW1
|
| STP forwards toward SW2
v
SW2
|
| Layer 2 path back/across
v
R1 HSRP Active
Topology จริงขึ้นอยู่กับ Campus Design และ Platform จึงควรวิเคราะห์ Data Path มากกว่าจำกฎแบบตายตัว
ภาค 8: FHRP กับ Dynamic Routing
HSRP/VRRP/GLBP กับ OSPF ต่างกันอย่างไร?
FHRP และ OSPF แก้ปัญหาคนละส่วน
| Technology | หน้าที่ |
|---|---|
| HSRP / VRRP / GLBP | Default Gateway Redundancy สำหรับ End Host |
| OSPF | แลกเปลี่ยนและเลือกเส้นทางระหว่าง Router/L3 Devices |
ตัวอย่าง:
PC
|
| Default Gateway
v
Virtual IP
|
+---- R1
| |
| +---- OSPF ---- Core
|
+---- R2
|
+---- OSPF ---- Core
FHRP ช่วย Client หา First-Hop Gateway ที่ยังใช้งานได้
OSPF ช่วย Router หาเส้นทางต่อไปยัง Remote Network
ภาค 9: Cisco HSRP Lab
Topology
CORE
/ \
/ \
R1 R2
192.168.10.2 192.168.10.3
\ /
\ /
SW1
|
|
PC1
192.168.10.100
Virtual Gateway
192.168.10.1
R1 Configuration
interface GigabitEthernet0/0
description VLAN10-LAN
ip address 192.168.10.2 255.255.255.0
standby version 2
standby 10 ip 192.168.10.1
standby 10 priority 110
standby 10 preempt
no shutdown
R2 Configuration
interface GigabitEthernet0/0
description VLAN10-LAN
ip address 192.168.10.3 255.255.255.0
standby version 2
standby 10 ip 192.168.10.1
standby 10 priority 100
standby 10 preempt
no shutdown
PC Configuration
IP Address:
192.168.10.100
Subnet Mask:
255.255.255.0
Default Gateway:
192.168.10.1
ตรวจ HSRP
show standby brief
ผลเชิงแนวคิด:
R1
Group 10
State Active
Priority 110
Virtual IP 192.168.10.1
R2
Group 10
State Standby
Priority 100
Virtual IP 192.168.10.1
Output จริงอาจแตกต่าง ตาม Platform และ IOS/IOS XE
ทดสอบ Failover
ก่อน Fail:
R1 = ACTIVE
R2 = STANDBY
จำลอง R1 LAN Interface Down:
R1(config)#interface GigabitEthernet0/0
R1(config-if)#shutdown
ตรวจ R2:
show standby brief
คาดหวัง:
R2
STANDBY -> ACTIVE
Client ยังคงใช้ Default Gateway เดิม:
192.168.10.1
Restore R1
R1(config)#interface GigabitEthernet0/0
R1(config-if)#no shutdown
เมื่อ R1 กลับมา Priority 110 และเปิด Preempt จึงสามารถกลับมารับ Active Role ตาม Design ได้
ภาค 10: Cisco VRRP Lab
ใช้ Topology เดียวกับ HSRP
R1
192.168.10.2
R2
192.168.10.3
Virtual IP
192.168.10.1
R1
interface GigabitEthernet0/0
ip address 192.168.10.2 255.255.255.0
vrrp 10 ip 192.168.10.1
vrrp 10 priority 110
vrrp 10 preempt
no shutdown
R2
interface GigabitEthernet0/0
ip address 192.168.10.3 255.255.255.0
vrrp 10 ip 192.168.10.1
vrrp 10 priority 100
vrrp 10 preempt
no shutdown
ตรวจ VRRP
show vrrp
show vrrp brief
ภาค 11: GLBP Lab Concept
ตัวอย่าง GLBP
Topology:
Virtual Gateway
192.168.10.1
|
+--------+--------+
| |
R1 R2
192.168.10.2 192.168.10.3
\ /
\ /
SW1
|
+--------+--------+
| |
PC1 PC2
ตัวอย่าง Configuration:
interface GigabitEthernet0/0
ip address 192.168.10.2 255.255.255.0
glbp 10 ip 192.168.10.1
glbp 10 priority 110
glbp 10 preempt
R2:
interface GigabitEthernet0/0
ip address 192.168.10.3 255.255.255.0
glbp 10 ip 192.168.10.1
glbp 10 priority 100
glbp 10 preempt
ตรวจ:
show glbp
show glbp brief
ภาค 12: Verification Commands
HSRP
show standby
show standby brief
VRRP
show vrrp
show vrrp brief
GLBP
show glbp
show glbp brief
ตรวจ Interface
show ip interface brief
show interfaces
ตรวจ Routing
show ip route
show ip route ospf
ตรวจ ARP
show ip arp
ตรวจ Configuration
show running-config interface GigabitEthernet0/0
ภาค 13: FHRP Troubleshooting
Troubleshooting Workflow
Physical Link
|
v
Interface UP?
|
v
IP / Subnet correct?
|
v
Same Layer 2 segment?
|
v
FHRP Group correct?
|
v
Virtual IP correct?
|
v
Protocol Version compatible?
|
v
Priority correct?
|
v
Preempt correct?
|
v
Active/Master role correct?
|
v
Upstream route correct?
|
v
Return path correct?
|
v
Tracking / IP SLA?
ปัญหา 1 — Virtual IP ผิด
R1:
standby 10 ip 192.168.10.1
R2:
standby 10 ip 192.168.10.254
Configuration ของ Group ไม่สอดคล้องกัน
ตรวจ:
show standby brief
ปัญหา 2 — Group Number ไม่ตรงกัน
R1:
standby 10 ip 192.168.10.1
R2:
standby 20 ip 192.168.10.1
อุปกรณ์ไม่ได้อยู่ใน HSRP Group เดียวกัน ตามที่ตั้งใจ
ปัญหา 3 — Priority สูงกว่าแต่ไม่กลับมาเป็น Active
ตรวจ:
show standby brief
และตรวจว่า:
standby 10 preempt
ถูก Configure ตาม Design หรือไม่
ปัญหา 4 — Active Gateway ทำงาน แต่ไม่มี Upstream Route
PC
|
v
R1 ACTIVE
|
|
X
No route to destination
HSRP สามารถทำงานปกติ แต่ Client ยังออก Internet หรือ Remote Network ไม่ได้
ตรวจ:
show ip route
show ip route 0.0.0.0
ปัญหา 5 — Uplink เสีย แต่ Active Role ไม่เปลี่ยน
ตัวอย่าง:
LAN Interface = UP
HSRP = ACTIVE
Uplink = UP
Remote path = FAILED
FHRP พื้นฐานอาจยังไม่ทราบ ว่า End-to-End Path ใช้งานไม่ได้
จึงต้องใช้:
IP SLA
+
Object Tracking
+
HSRP Tracking
ปัญหา 6 — Gateway Failover สำเร็จ แต่ Application หลุด
FHRP ช่วยเรื่อง Default Gateway Availability แต่ไม่ได้หมายความว่า Application Session ทุกประเภท จะถูก Preserve
เช่น:
Gateway Failover
|
v
Routing path changes
|
v
NAT state may change
|
v
Firewall state may change
|
v
Existing session may reset
โดยเฉพาะระบบที่มี NAT, Stateful Firewall หรือ Session State อยู่บน Edge Router
ภาค 14: Enterprise High Availability Design
FHRP เป็นเพียงส่วนหนึ่งของ High Availability
Network High Availability ไม่ได้จบที่ HSRP หรือ VRRP
ISP / CORE
/ \
/ \
R1 R2
\ /
\ /
SW1=======SW2
|\ /|
| \ / |
| \ / |
Users Servers
ต้องพิจารณาร่วมกัน:
- Dual Gateway
- FHRP
- Dynamic Routing
- STP / RSTP / MST
- EtherChannel
- Dual Uplink
- IP SLA / Object Tracking
- Power Redundancy
- WAN Redundancy
- Monitoring
ตัวอย่าง High Availability Stack
Client
|
v
Access Switch
|
+---- Redundant Links
|
v
Distribution Pair
|
+---- STP / EtherChannel
|
+---- HSRP / VRRP
|
+---- OSPF
|
+---- IP SLA / Tracking
|
v
Core / Internet
เลือกเทคโนโลยีตามหน้าที่
| Requirement | Technology |
|---|---|
| Default Gateway Redundancy | HSRP / VRRP / GLBP ตาม Platform และ Design |
| Gateway Load Distribution | GLBP หรือ Multi-Group Design ตาม Architecture |
| Dynamic Route Failover | OSPF / EIGRP / BGP ตาม Network Scope |
| Layer 2 Loop Prevention | STP / RSTP / MST |
| Link Aggregation | EtherChannel / LACP |
| Remote Path Monitoring | IP SLA |
| Track Operational State | Object Tracking |
| Security Policy | ACL / ZBF / Firewall |
Production Checklist
1. Define Virtual IP
2. Define physical gateway IPs
3. Select FHRP protocol
4. Confirm platform support
5. Define group IDs
6. Define priority
7. Decide preempt behavior
8. Consider preempt delay
9. Identify upstream failure scenarios
10. Design interface/object tracking
11. Verify routing
12. Align STP/FHRP where appropriate
13. Test gateway failure
14. Test uplink failure
15. Test recovery
16. Monitor convergence
17. Test applications
18. Document rollback
19. Update network diagram
20. Record expected roles
ภาค 15: คำถามที่พบบ่อย
HSRP, VRRP และ GLBP ใช้ทำอะไร?
ทั้งสามเกี่ยวข้องกับ First-Hop Gateway Redundancy เพื่อช่วยลดปัญหา Default Gateway เป็น Single Point of Failure โดย GLBP เพิ่มกลไก Gateway Load Balancing เข้ามาด้วย
HSRP กับ VRRP ต่างกันอย่างไร?
ทั้งคู่สร้าง Virtual Gateway และ Gateway Redundancy แต่ HSRP เป็นเทคโนโลยี ที่เกี่ยวข้องกับ Cisco ขณะที่ VRRP เป็นมาตรฐานเปิด และใช้คำเรียกบทบาท ต่างกัน เช่น Active/Standby กับ Master/Backup
GLBP ต่างจาก HSRP อย่างไร?
GLBP เพิ่มความสามารถ ให้ Gateway หลายตัว มีบทบาท Forward Traffic ภายใน Group ขณะที่ HSRP แบบพื้นฐาน ใช้ Active Gateway เป็นตัว Forward หลัก ของ Group
Client ต้องเปลี่ยน Default Gateway เมื่อ Router Fail หรือไม่?
ไม่ต้อง Client ยังคงใช้ Virtual IP Address เดิม เป็น Default Gateway
Priority สูงกว่าหมายความว่าจะเป็น Active เสมอหรือไม่?
ไม่ควรสรุปเพียง Priority อย่างเดียว เพราะ Election State, Preemption, Availability และ Protocol Behavior มีผลต่อบทบาทด้วย
Preempt จำเป็นหรือไม่?
ขึ้นอยู่กับ Design หากต้องการให้ Gateway ที่กำหนด Priority สูงกว่า กลับมารับ Preferred Role หลัง Recovery ต้องพิจารณา Preemption รวมถึง Delay และ Stability
HSRP แทน OSPF ได้หรือไม่?
ไม่ได้ HSRP ดูแล First-Hop Gateway Redundancy ส่วน OSPF เป็น Dynamic Routing Protocol สำหรับแลกเปลี่ยนและเลือก Route
HSRP แทน STP ได้หรือไม่?
ไม่ได้ HSRP ทำงานด้าน Layer 3 Gateway Redundancy ส่วน STP ป้องกัน Layer 2 Switching Loop
มี Router สองตัวแล้วจำเป็นต้องใช้ FHRP หรือไม่?
หาก End Host ต้องการ Default Gateway ที่มี Redundancy การมี Router สองตัว เพียงอย่างเดียวไม่ได้ทำให้ Client เปลี่ยน Gateway โดยอัตโนมัติ จึงต้องมี Gateway Redundancy Mechanism ที่เหมาะสม
ทำไม HSRP Active ยังอยู่แม้ Internet ใช้ไม่ได้?
เพราะ Local FHRP State อาจยังปกติ ขณะที่ Remote Path มีปัญหา กรณีนี้สามารถต่อยอด ด้วย Interface Tracking, Object Tracking และ IP SLA ตาม Design
HSRP Failover ทำให้ NAT Session อยู่ต่อหรือไม่?
ไม่จำเป็น HSRP ให้ Gateway Redundancy แต่ไม่ได้ทำหน้าที่ Synchronize NAT Translation หรือ Stateful Firewall Session ระหว่าง Router โดยอัตโนมัติ
ควรทดสอบ High Availability อย่างไร?
ไม่ควรทดสอบเฉพาะ การ Shutdown Router แต่ควรจำลองหลาย Failure Mode:
Gateway failure
LAN interface failure
Uplink failure
Remote next-hop failure
Routing failure
Recovery / failback
Application session behavior
บทสรุป
HSRP, VRRP และ GLBP ช่วยแก้ปัญหา Default Gateway เป็น Single Point of Failure โดยให้ Client ใช้ Virtual Gateway แทน Physical Gateway ตัวใดตัวหนึ่ง
Virtual IP
192.168.10.1
|
+-------+-------+
| |
R1 R2
192.168.10.2 192.168.10.3
\ /
\ /
LAN
|
Client
HSRP ใช้แนวคิด Active/Standby และพบได้บ่อยใน Cisco Network
VRRP เป็นมาตรฐาน First-Hop Redundancy ที่ใช้แนวคิด Master/Backup
GLBP เพิ่มความสามารถ Gateway Load Balancing โดยมีแนวคิด AVG และ AVF
HSRP
Gateway Redundancy
Active / Standby
VRRP
Gateway Redundancy
Master / Backup
GLBP
Gateway Redundancy
+
Gateway Load Balancing
อย่างไรก็ตาม FHRP เพียงอย่างเดียว ยังไม่ครอบคลุม Failure ทุกประเภท
Gateway is alive
|
v
LAN Interface is UP
|
v
FHRP says ACTIVE
|
v
But remote Internet path
may already be DOWN
ดังนั้นขั้นต่อไปของ Network High Availability คือการทำให้ Gateway ตรวจสอบสถานะของ เส้นทางที่อยู่ไกลออกไปได้
บทความถัดไป: IP SLA, Object Tracking และ HSRP Tracking บน Cisco: สร้าง Gateway Failover ที่ตรวจสอบเส้นทางได้จริง
Share your thoughts here
Join the conversation and share your perspective on this article.