Chapter 16: Troubleshooting Network Performance, Tools, and Protocols Study Guide

Introduction to Network Performance Troubleshooting

  • The primary focus of network performance troubleshooting is identifying and resolving performance bottlenecks.

  • Key objectives include:

    • Enhancing network reliability.

    • Minimizing system downtime.

    • Optimizing overall user experiences.

  • Core topics for diagnosing and remediation include:

    • Bandwidth, latency, and congestion issues.

    • Enhancing network efficiency.

    • Reducing operational bottlenecks.

  • These notes align with CompTIA Exam Objectives:

    • 5.4: Given a scenario, troubleshoot common performance issues.

    • 5.5: Given a scenario, use the appropriate tool or protocol to solve networking issues.

Fundamental Network Performance Metrics

  • Bandwidth: This represents the maximum data transfer capacity of a network. It is the theoretical maximum amount of data that can be sent over a specific connection in a given amount of time.

  • Throughput: This is the actual amount of data successfully transmitted over the network. It is typically lower than bandwidth due to factors such as latency, overhead, and congestion.

  • Goodput: A specific subset of throughput that focuses exclusively on successfully delivered application-level data. It excludes protocol overhead and retransmitted packets.

Troubleshooting Performance Issues and Hardware Constraints

  • Bandwidth Capacity:

    • Networking teams utilize tools like NetFlow and SNMP (Simple Network Management Protocol) to track bandwidth usage.

    • Aim to identify overutilized links and optimize traffic patterns to prevent saturation.

  • Congestion Causes:

    • High traffic volumes.

    • Inefficient routing protocols or paths.

    • Inadequate hardware capacity.

  • Congestion Solutions:

    • Prioritizing critical traffic using Quality of Service (QoS).

    • Upgrading hardware components as necessary.

  • Hardware Constraints and Bottlenecks:

    • Analysis of CPU, memory, and interface utilization is required to identify hardware-level bottlenecks.

    • Solutions include hardware upgrades or balancing workloads across different devices.

    • Older protocols, such as IPv4, may not fully utilize the capabilities of modern hardware.

    • Legacy devices often struggle with modern requirements like high-speed traffic processing or intensive encryption tasks.

Latency, Jitter, and Packet Loss

  • Latency:

    • Common causes: Long transmission distances, queuing delays in routers/switches, and general network congestion.

    • Identification tools:

      • ping: Measures the round-trip time (RTTRTT) to assess connectivity and basic latency.

      • traceroute: Identifies the specific path packets take and reveals delays across individual network hops.

  • Jitter:

    • Defined as the variation in packet arrival times, which disrupts the consistency of data flow.

    • Monitoring: VoIP monitoring tools are essential for tracking jitter and latency metrics in real-time environments.

    • Addressing Jitter:

      • Implementation of jitter buffers to smooth out packet delivery for the receiver.

      • Prioritization of real-time traffic (e.g., VoIP, video conferencing) via QoS.

  • Network Contention:

    • Occurs when multiple devices compete for shared, limited resources.

    • Mitigation involves deploying QoS and increasing available bandwidth.

  • Packet Loss:

    • Common causes: Congestion, hardware faults, and signal degradation.

    • Remediation: Optimizing bandwidth usage and replacing faulty hardware components.

Troubleshooting Wireless Network Performance

  • Wireless Interference:

    • Common sources: Microwaves, cordless phones, and overlapping Wi-Fi channels.

    • Mitigation: Use spectrum analyzers to identify and eliminate interference sources.

  • Signal Degradation:

    • Symptoms: Weak signals, dropped connections, and slow speeds.

    • Remediation: Reposition access points (APsAPs) and adjust transmit power levels for optimal coverage.

  • Coverage Gaps:

    • Identified through regular wireless surveys to find literal weak spots.

    • Solutions: Deploying additional access points or mesh network extensions.

  • Common Misconfigurations:

    • Duplicate or Conflicting SSIDs: Causes connectivity confusion for client devices.

    • Improper Channel Selection: Leads to co-channel or adjacent-channel interference.

  • Roaming Issues:

    • Common causes: Weak signal handoffs between cells, mismatched AP configurations, or outdated firmware.

    • Remediation: Implement seamless handoff protocols and ensure uniform settings across all access points.

Command-Line Utilities for Connectivity and Latency

  • ping Utility:

    • Checks connectivity and measures latency to a target IP.

    • Display output typically includes: Message size (bytes), round-trip time (RTTRTT) in msms, and Time to Live (TTLTTL).

    • Example success: Ping to 93.184.215.1493.184.215.14.

    • Windows/Linux ping Options:

      • −4-4 / −6-6: Forces the use of IPv4 or IPv6 respectively.

      • −t-t (Windows): Sends continuous pings until stopped by CTRL+CCTRL+C. (Note: Continuous ping is the default behavior in Linux/macOS).

      • −n-n (Windows): Specifies the exact number of echo requests to send.

      • −c-c (Linux/macOS): Specifies the exact number of echo requests to send.

  • traceroute / tracert Utility:

    • Displays the route and delays of packets; Windows uses tracert, while Linux/macOS uses traceroute.

    • Common Options:

      • −4-4 / −6-6: Forces IPv4 or IPv6 usage.

      • −d-d (Windows): Prevents DNS resolution of IP addresses for faster output.

      • −n-n (Linux/macOS): Prevents DNS resolution.

      • −h-h (Windows): Sets the maximum number of hops (e.g., 3030).

      • −m-m (Linux/macOS): Sets the maximum number of hops.

      • −w-w: Sets timeout for each hop in milliseconds. (Windows Default: 4,000 ms4,000\,ms; Linux/macOS Default: 5,000 ms5,000\,ms).

      • −I-I (Linux/macOS): Forces the use of ICMP echo requests instead of the default UDP packets.

DNS Troubleshooting Utilities: nslookup and dig

  • nslookup:

    • Used to resolve domain names to IP addresses, query DNS records, check response times, and test DNS configurations.

    • Supports an interactive mode.

    • Example: Querying comptia.org MX records using Cloudflare's public resolver (1.1.1.11.1.1.1).

    • Options:

      • -type=<record_type> or -query=<record_type>.

      • Record types include: A (IPv4), AAAA (IPv6), MX (Mail Exchanger), NS (Name Server), TXT (Text), CNAME (Canonical Name).

  • dig (Domain Information Groper):

    • Performs DNS lookups with higher detail than nslookup.

    • It distinguishes between authoritative and non-authoritative answers by the presence or absence of the aa (authoritative answer) flag in the flags section.

    • Common Options:

      • @<server>: Specifies the DNS server to query (overrides system default).

      • <domain> <record_type>: Specifies target and record type.

      • +short: Enables a truncated/minimal output.

      • -x <ip_address>: Performs a reverse DNS lookup.

      • +trace: Displays the full resolution path for debugging.

      • +answer: Displays only the answer section of the response.

Packet Analysis with tcpdump

  • tcpdump is a CLI-based tool for packet capture and analysis.

  • Common Options:

    • -i <interface>: Specifies the network interface (e.g., tcpdump -i ens33).

    • -v, -vv, -vvv: Incremental levels of verbosity.

    • -w <file>: Writes capture to a file (usually .pcap) for later analysis.

    • -r <file>: Reads packets from a saved file for analysis.

  • Filter Expressions:

    • Protocol: arp, tcp, udp, icmp, ip, http, etc.

    • Host: host 192.168.1.1 or host example.com.

    • Port: port 80 or portrange 8000-8080.

    • Direction: src (source) or dst (destination).

    • Logical Operators: and (matches all), or (matches any), not (excludes specific traffic).

    • Compound Example: tcpdump -i ens33 src host 192.168.1.1 and (dst port 80 or dst port 443).

Network State and Statistics with netstat

  • netstat displays network connections, listening ports, routing tables, and interface statistics.

  • Connection States (Commonly seen in Windows PowerShell):

    • TIME_WAIT: Device is waiting to close the connection.

    • SYN_SENT: Device is attempting to establish a connection.

    • FIN_WAIT_1: Device is closing the connection.

  • Command Options:

    • -a: Displays all active connections and listening ports.

    • -b (Windows): Displays the executable/process name for each connection.

    • -c (Linux/macOS): Continuous display.

    • -e: Displays Ethernet statistics (bytes sent/received).

    • -f (Windows): Displays FQDNs for remote addresses.

    • -i (Linux/macOS): Lists network interfaces and status.

    • -n: Displays addresses and ports numerically (skips DNS resolution).

    • -o (Windows): Shows active TCP connections and their Process IDs (PIDsPIDs).

    • -p <protocol>: Filters by protocol.

    • -r: Displays the routing table.

    • -s: Displays statistics by protocol.

    • -t, -u (Linux/macOS): Shows only TCP or UDP respectively.

    • -4, -6: Forces IPv4 or IPv6.

Interface Management: ip, ifconfig, and ipconfig

  • ip (Linux): The modern, versatile tool for managing interfaces, addressing, and routing.

    • ip addr: Displays all interfaces, IP/MAC addresses, and state.

    • ip addr add <ip_address/mask> dev <interface>: Adds an address.

    • ip route show: Displays the system routing table.

    • ip link set <interface> up | down: Enables or disables an interface.

    • ip -s link: Displays interface statistics.

  • ipconfig (Windows): Standard utility for TCP/IP settings.

    • ipconfig /all: Shows DHCP status, MAC, and DNS server details.

    • ipconfig /release / /renew: Releases or renews DHCP leases for IPv4.

    • ipconfig /release6 / /renew6: For IPv6 leases.

    • ipconfig /displaydns / /flushdns: Views or clears the local DNS resolver cache.

    • ipconfig /registerdns: Forces re-registration with dynamic DNS.

  • ifconfig: Legacy Linux tool, currently used in macOS/FreeBSD.

  • arp Utility:

    • Interacts with the ARP table (resolving IP to MAC).

    • -a: Displays the ARP cache.

    • -s <ip> <mac>: Adds a static entry. (Note: Windows uses hyphens OA-1B...; Linux uses colons 0a:1b...).

    • -d <ip>: Deletes an entry. (Windows uses * to delete all entries).

Specialized Network Discovery and Hardware Tools

  • Nmap (Network Mapper):

    • Open-source tool for device discovery and security assessment.

    • nmap -sn: Performs a ping scan over a subnet (e.g., 192.168.91.0/24).

    • GUI version is called Zenmap.

  • Discovery Protocols:

    • LLDP (Link Layer Discovery Protocol): Standardized protocol.

    • CDP (Cisco Discovery Protocol): Proprietary Cisco tool.

  • Hardware Diagnostic Tools:

    • Toner: Traces cables and identifies endpoints.

    • Cable Tester: Verifies physical integrity of copper/fiber wiring.

    • Network Tap (Test Access Point): Copies and monitors traffic between two devices.

    • Wi-Fi Analyzer: Detects signal strength, channel usage, and interference.

    • Visual Fault Locator (VFL): Identifies breaks/faults in fiber optic cables using light.

    • iPerf: Used for throughput testing and bandwidth analysis.

Network Device Analysis: The 'show' Commands

Common commands used on switches and routers for performance analysis:

  • show mac-address-table: Displays the learned MAC addresses and associated ports/VLANs.

  • show route: Displays the active routing table.

  • show interface: Provides status and statistics (speed, duplex, errors, packet counters).

  • show config: Lists the general configuration (IPs, VLANs, ACLs).

  • show running-config: Displays the active, in-memory configuration.

  • show startup-config: Displays the configuration saved to memory for the next reboot.

  • show arp: Displays the device-level ARP table.

  • show vlan: Lists configured VLANs on a switch.

  • show power: Displays power status, power supply details, and PoE (Power over Ethernet) data.