Chapter 16: Troubleshooting Network Performance, Tools, and Protocols Study Guide
Introduction to Network Performance Troubleshooting
The primary focus of network performance troubleshooting is identifying and resolving performance bottlenecks.
Key objectives include:
Enhancing network reliability.
Minimizing system downtime.
Optimizing overall user experiences.
Core topics for diagnosing and remediation include:
Bandwidth, latency, and congestion issues.
Enhancing network efficiency.
Reducing operational bottlenecks.
These notes align with CompTIA Exam Objectives:
5.4: Given a scenario, troubleshoot common performance issues.
5.5: Given a scenario, use the appropriate tool or protocol to solve networking issues.
Fundamental Network Performance Metrics
Bandwidth: This represents the maximum data transfer capacity of a network. It is the theoretical maximum amount of data that can be sent over a specific connection in a given amount of time.
Throughput: This is the actual amount of data successfully transmitted over the network. It is typically lower than bandwidth due to factors such as latency, overhead, and congestion.
Goodput: A specific subset of throughput that focuses exclusively on successfully delivered application-level data. It excludes protocol overhead and retransmitted packets.
Troubleshooting Performance Issues and Hardware Constraints
Bandwidth Capacity:
Networking teams utilize tools like NetFlow and SNMP (Simple Network Management Protocol) to track bandwidth usage.
Aim to identify overutilized links and optimize traffic patterns to prevent saturation.
Congestion Causes:
High traffic volumes.
Inefficient routing protocols or paths.
Inadequate hardware capacity.
Congestion Solutions:
Prioritizing critical traffic using Quality of Service (QoS).
Upgrading hardware components as necessary.
Hardware Constraints and Bottlenecks:
Analysis of CPU, memory, and interface utilization is required to identify hardware-level bottlenecks.
Solutions include hardware upgrades or balancing workloads across different devices.
Older protocols, such as IPv4, may not fully utilize the capabilities of modern hardware.
Legacy devices often struggle with modern requirements like high-speed traffic processing or intensive encryption tasks.
Latency, Jitter, and Packet Loss
Latency:
Common causes: Long transmission distances, queuing delays in routers/switches, and general network congestion.
Identification tools:
ping: Measures the round-trip time () to assess connectivity and basic latency.
traceroute: Identifies the specific path packets take and reveals delays across individual network hops.
Jitter:
Defined as the variation in packet arrival times, which disrupts the consistency of data flow.
Monitoring: VoIP monitoring tools are essential for tracking jitter and latency metrics in real-time environments.
Addressing Jitter:
Implementation of jitter buffers to smooth out packet delivery for the receiver.
Prioritization of real-time traffic (e.g., VoIP, video conferencing) via QoS.
Network Contention:
Occurs when multiple devices compete for shared, limited resources.
Mitigation involves deploying QoS and increasing available bandwidth.
Packet Loss:
Common causes: Congestion, hardware faults, and signal degradation.
Remediation: Optimizing bandwidth usage and replacing faulty hardware components.
Troubleshooting Wireless Network Performance
Wireless Interference:
Common sources: Microwaves, cordless phones, and overlapping Wi-Fi channels.
Mitigation: Use spectrum analyzers to identify and eliminate interference sources.
Signal Degradation:
Symptoms: Weak signals, dropped connections, and slow speeds.
Remediation: Reposition access points () and adjust transmit power levels for optimal coverage.
Coverage Gaps:
Identified through regular wireless surveys to find literal weak spots.
Solutions: Deploying additional access points or mesh network extensions.
Common Misconfigurations:
Duplicate or Conflicting SSIDs: Causes connectivity confusion for client devices.
Improper Channel Selection: Leads to co-channel or adjacent-channel interference.
Roaming Issues:
Common causes: Weak signal handoffs between cells, mismatched AP configurations, or outdated firmware.
Remediation: Implement seamless handoff protocols and ensure uniform settings across all access points.
Command-Line Utilities for Connectivity and Latency
ping Utility:
Checks connectivity and measures latency to a target IP.
Display output typically includes: Message size (bytes), round-trip time () in , and Time to Live ().
Example success: Ping to .
Windows/Linux ping Options:
/ : Forces the use of IPv4 or IPv6 respectively.
(Windows): Sends continuous pings until stopped by . (Note: Continuous ping is the default behavior in Linux/macOS).
(Windows): Specifies the exact number of echo requests to send.
(Linux/macOS): Specifies the exact number of echo requests to send.
traceroute / tracert Utility:
Displays the route and delays of packets; Windows uses
tracert, while Linux/macOS usestraceroute.Common Options:
/ : Forces IPv4 or IPv6 usage.
(Windows): Prevents DNS resolution of IP addresses for faster output.
(Linux/macOS): Prevents DNS resolution.
(Windows): Sets the maximum number of hops (e.g., ).
(Linux/macOS): Sets the maximum number of hops.
: Sets timeout for each hop in milliseconds. (Windows Default: ; Linux/macOS Default: ).
(Linux/macOS): Forces the use of ICMP echo requests instead of the default UDP packets.
DNS Troubleshooting Utilities: nslookup and dig
nslookup:
Used to resolve domain names to IP addresses, query DNS records, check response times, and test DNS configurations.
Supports an interactive mode.
Example: Querying
comptia.orgMX records using Cloudflare's public resolver ().Options:
-type=<record_type>or-query=<record_type>.Record types include:
A(IPv4),AAAA(IPv6),MX(Mail Exchanger),NS(Name Server),TXT(Text),CNAME(Canonical Name).
dig (Domain Information Groper):
Performs DNS lookups with higher detail than
nslookup.It distinguishes between authoritative and non-authoritative answers by the presence or absence of the
aa(authoritative answer) flag in the flags section.Common Options:
@<server>: Specifies the DNS server to query (overrides system default).<domain> <record_type>: Specifies target and record type.+short: Enables a truncated/minimal output.-x <ip_address>: Performs a reverse DNS lookup.+trace: Displays the full resolution path for debugging.+answer: Displays only the answer section of the response.
Packet Analysis with tcpdump
tcpdump is a CLI-based tool for packet capture and analysis.
Common Options:
-i <interface>: Specifies the network interface (e.g.,tcpdump -i ens33).-v, -vv, -vvv: Incremental levels of verbosity.-w <file>: Writes capture to a file (usually.pcap) for later analysis.-r <file>: Reads packets from a saved file for analysis.
Filter Expressions:
Protocol:
arp,tcp,udp,icmp,ip,http, etc.Host:
host 192.168.1.1orhost example.com.Port:
port 80orportrange 8000-8080.Direction:
src(source) ordst(destination).Logical Operators:
and(matches all),or(matches any),not(excludes specific traffic).Compound Example:
tcpdump -i ens33 src host 192.168.1.1 and (dst port 80 or dst port 443).
Network State and Statistics with netstat
netstat displays network connections, listening ports, routing tables, and interface statistics.
Connection States (Commonly seen in Windows PowerShell):
TIME_WAIT: Device is waiting to close the connection.SYN_SENT: Device is attempting to establish a connection.FIN_WAIT_1: Device is closing the connection.
Command Options:
-a: Displays all active connections and listening ports.-b(Windows): Displays the executable/process name for each connection.-c(Linux/macOS): Continuous display.-e: Displays Ethernet statistics (bytes sent/received).-f(Windows): Displays FQDNs for remote addresses.-i(Linux/macOS): Lists network interfaces and status.-n: Displays addresses and ports numerically (skips DNS resolution).-o(Windows): Shows active TCP connections and their Process IDs ().-p <protocol>: Filters by protocol.-r: Displays the routing table.-s: Displays statistics by protocol.-t, -u(Linux/macOS): Shows only TCP or UDP respectively.-4, -6: Forces IPv4 or IPv6.
Interface Management: ip, ifconfig, and ipconfig
ip (Linux): The modern, versatile tool for managing interfaces, addressing, and routing.
ip addr: Displays all interfaces, IP/MAC addresses, and state.ip addr add <ip_address/mask> dev <interface>: Adds an address.ip route show: Displays the system routing table.ip link set <interface> up | down: Enables or disables an interface.ip -s link: Displays interface statistics.
ipconfig (Windows): Standard utility for TCP/IP settings.
ipconfig /all: Shows DHCP status, MAC, and DNS server details.ipconfig /release//renew: Releases or renews DHCP leases for IPv4.ipconfig /release6//renew6: For IPv6 leases.ipconfig /displaydns//flushdns: Views or clears the local DNS resolver cache.ipconfig /registerdns: Forces re-registration with dynamic DNS.
ifconfig: Legacy Linux tool, currently used in macOS/FreeBSD.
arp Utility:
Interacts with the ARP table (resolving IP to MAC).
-a: Displays the ARP cache.-s <ip> <mac>: Adds a static entry. (Note: Windows uses hyphensOA-1B...; Linux uses colons0a:1b...).-d <ip>: Deletes an entry. (Windows uses*to delete all entries).
Specialized Network Discovery and Hardware Tools
Nmap (Network Mapper):
Open-source tool for device discovery and security assessment.
nmap -sn: Performs a ping scan over a subnet (e.g.,192.168.91.0/24).GUI version is called Zenmap.
Discovery Protocols:
LLDP (Link Layer Discovery Protocol): Standardized protocol.
CDP (Cisco Discovery Protocol): Proprietary Cisco tool.
Hardware Diagnostic Tools:
Toner: Traces cables and identifies endpoints.
Cable Tester: Verifies physical integrity of copper/fiber wiring.
Network Tap (Test Access Point): Copies and monitors traffic between two devices.
Wi-Fi Analyzer: Detects signal strength, channel usage, and interference.
Visual Fault Locator (VFL): Identifies breaks/faults in fiber optic cables using light.
iPerf: Used for throughput testing and bandwidth analysis.
Network Device Analysis: The 'show' Commands
Common commands used on switches and routers for performance analysis:
show mac-address-table: Displays the learned MAC addresses and associated ports/VLANs.show route: Displays the active routing table.show interface: Provides status and statistics (speed, duplex, errors, packet counters).show config: Lists the general configuration (IPs, VLANs, ACLs).show running-config: Displays the active, in-memory configuration.show startup-config: Displays the configuration saved to memory for the next reboot.show arp: Displays the device-level ARP table.show vlan: Lists configured VLANs on a switch.show power: Displays power status, power supply details, and PoE (Power over Ethernet) data.