Concept and mechanism
Start with impact, scope, and timeline: who fails, since when, on which path, and after which change. Compare healthy and affected situations. Growing CRC errors suggest frame corruption but do not alone identify the faulty cable, transceiver, or component. Observe endpoint counters and the recently changed path. Preserve values and measurement intervals to distinguish historical counters from new errors. A hypothesis should produce a test that supports or weakens it. Changing several components simultaneously may restore service but reduces causal understanding; record that limitation if an emergency requires it.
Guided application
For name resolution, retain the question, resolver, and response. NXDOMAIN observed at one resolver should not be generalized without context to every network location. In an IP-based test, preserve hostname and SNI when required to avoid introducing another difference. For TCP, repeated SYNs without a reply in a client capture demonstrate only no reply observed there. Blocking may be on the forward path, return path, host, or policy; collect evidence at other authorized points. If ARP alternates between two distinct devices’ MACs for an ordinary static IP, check address conflict and IPAM before attributing malicious intent. Document facts separately from hypotheses to support international shift handover.
Client capture: SYN, SYN, SYN. Useful communication: no reply was observed here; we will correlate with the destination and return path.
Common pitfalls
CRC as exclusive cable proof; NXDOMAIN as high CPU; unanswered SYN as definite server failure; conflict as proven attack.
Related topics: MTU, capacity, and service validation · Layers, subnets, and addressing plans
Every observation has a scope: collect the next signal that distinguishes plausible causes.
Reference: TCP specification · N10-009 V9