← Network+: networking and production diagnosis
06 / 7 · 25 MIN

Diagnosis using counters, DNS, and captures

Form hypotheses proportionate to collected signals.

Concept and mechanism

Start with impact, scope, and timeline: who fails, since when, on which path, and after which change. Compare healthy and affected situations. Growing CRC errors suggest frame corruption but do not alone identify the faulty cable, transceiver, or component. Observe endpoint counters and the recently changed path. Preserve values and measurement intervals to distinguish historical counters from new errors. A hypothesis should produce a test that supports or weakens it. Changing several components simultaneously may restore service but reduces causal understanding; record that limitation if an emergency requires it.

Guided application

For name resolution, retain the question, resolver, and response. NXDOMAIN observed at one resolver should not be generalized without context to every network location. In an IP-based test, preserve hostname and SNI when required to avoid introducing another difference. For TCP, repeated SYNs without a reply in a client capture demonstrate only no reply observed there. Blocking may be on the forward path, return path, host, or policy; collect evidence at other authorized points. If ARP alternates between two distinct devices’ MACs for an ordinary static IP, check address conflict and IPAM before attributing malicious intent. Document facts separately from hypotheses to support international shift handover.

IN PRACTICE

Client capture: SYN, SYN, SYN. Useful communication: no reply was observed here; we will correlate with the destination and return path.

Common pitfalls

CRC as exclusive cable proof; NXDOMAIN as high CPU; unanswered SYN as definite server failure; conflict as proven attack.

Related topics: MTU, capacity, and service validation · Layers, subnets, and addressing plans

Take this idea with you

Every observation has a scope: collect the next signal that distinguishes plausible causes.

Create account

Reference: TCP specification · N10-009 V9