Home/CCIE/Troubleshooting process
The NDA troubleshooting process

Analyze. Gather. Isolate. Solve.

The way you want to analyze, gather, troubleshoot and solve a network situation — as a CCNP engineer on a real network, and as a CCIE candidate with the lab clock running.

Five rules that never change

Elimination beats intuition.

Every fault is found the same way: remove everything that is not the problem, with evidence, until one explanation is left.

RULE 01

Evidence before action

No configuration change without output that supports it. "I think" is not evidence.

RULE 02

Split the problem in half

Every question you ask should rule out roughly half of the possible causes.

RULE 03

Find the first divergence

Follow the packet from the source. The first point where reality differs from expectation is where you work.

RULE 04

One change at a time

Change one variable, verify, then decide. Otherwise you never know what fixed it.

RULE 05

Prove it from the source

Done means tested from where the user is, in both directions — not a green line on one router.

The troubleshooting matrix

Eight phases. Two levels of expectation.

Select a phase. For each one you see the goal, the questions to ask, the evidence to collect, how a CCNP engineer and a CCIE candidate are expected to work, the exit criteria and the trap to avoid.

The loop

From report to proof — and back when the evidence disagrees.

DEFINEwhat · where · when SCOPEwho · which way SWEEPL1 → L3 fast check SPLIT PLANEScontrol · data · policy DIVERGENCEfirst wrong hop HYPOTHESISexplains ALLthe evidence ONE CHANGEwith rollback VERIFYfrom the source NO SIDE EFFECTSre-test the rest DOCUMENTcause · fix · proof verify fails →back to scope
Elimination matrix

Rule out the foundation in minutes, not hours.

Sweep bottom-up quickly. A layer only counts as ruled out when the evidence in the "healthy when" column is on your screen.

Layer / planeWhat you checkEvidence (Cisco examples)Healthy whenTypical faults
PhysicalLink state, errors, optics, speed/duplexshow interfaces · show interfaces counters errors · show interfaces transceiverup/up, no incrementing CRC/input errors, light levels in rangeBad cable/optic, duplex mismatch, err-disabled port
Data linkVLANs, trunks, STP, EtherChannel, MAC learningshow vlan brief · show interfaces trunk · show spanning-tree vlan X · show etherchannel summary · show mac address-tableVLAN allowed, active and forwarding; expected root; bundle (P); MAC learned on the right portPruned VLAN, native mismatch, wrong root, suspended member, loops
Network: addressingIP/mask, gateway, ARP/ND, first hopshow ip interface brief · show ip arp · show ipv6 neighbors · show standby briefCorrect subnet on both ends, ARP complete, one active gatewayWrong mask, duplicate IP, FHRP split-brain, missing helper
Control planeNeighbors, routes, best path, redistributionshow ip ospf neighbor · show ip eigrp neighbors · show bgp ipv4 unicast summary · show ip route XAdjacencies FULL/Established, route present with expected source, AD and next hopParameter mismatch, filtering, next hop unreachable, loops by redistribution
Data planeWhat the hardware actually doesshow ip cef X detail · show ip cef exact-route S D · show mpls forwarding-table · tracerouteCEF matches the RIB, labels present, traceroute follows the designRecursive failure, missing label, ECMP to a dead path
Policy & securityACLs, NAT, zones, QoS, uRPF, AAAshow access-lists (hit counters) · show ip nat translations · show policy-map interfaceCounters match expected traffic, translations present, no unexpected dropsImplicit deny, wrong direction, NAT of VPN traffic, CoPP drops
Overlay & servicesTunnels, VPNs, VXLAN, SD-WAN, DHCP, DNS, NTPshow crypto ipsec sa · show dmvpn · show nve peers · show sdwan bfd sessions · show ntp statusSAs encrypt and decrypt, peers up, time synchronisedMTU/overhead, NHRP, RT mismatch, clock skew
Management & automationReachability of the device, APIs, telemetryshow netconf-yang status · API status codes · show telemetry ietf subscription allSession up, 2xx responses, subscriptions valid401/404, lock-denied, invalid XPath, expired tokens
Start from the symptom

What you see decides where you look first.

Pick the symptom. You get the first question to ask, the elimination steps in order and the domains where the cause usually lives.

Level of expectation

Same process. Different depth, speed and scope.

DimensionCCNP engineerCCIE candidate
ScopeOne domain at a time, a handful of devicesMultiple interacting domains; faults hide behind other faults
SpeedAccuracy first; minutes per check are acceptableA full layer sweep in minutes; every command has a purpose
EvidenceReads show output and recognises obvious mismatchesPredicts the output before running it and notices what is missing
Protocol depthKnows states, timers and common parametersKnows selection algorithms, loop prevention and side-effects between protocols
HypothesesOne hypothesis tested at a timeRanks several hypotheses by probability and cost to test
ChangeCorrect fix for the symptomMinimal fix that meets every requirement and constraint in the task
VerificationTests the reported pathTests the reported path, the reverse path and everything the change could affect
TimeEscalates when stuckTimeboxes, moves on and returns with fresh eyes
Lab-day time model

Manage the clock like a resource.

A guideline for a troubleshooting task under exam pressure. Reset the clock for every task; when a box runs out, decide consciously.

Read & scope — 20%Underline requirements and constraints. Decide what "fixed" means before you type.
Sweep & isolate — 50%Fast bottom-up sweep, then split planes and hunt the first divergence.
Fix & verify — 30%One minimal change with rollback, then prove it from the source in both directions.

Stuck past the timebox? Note what you ruled out, move on, and come back. The notes make the second attempt fast.

Practise the process

Learn it here. Drill it online. Perform it in Lelystad.

Every NDA scenario and every campus simulation is coached along this process — our instructors ask the questions, you collect the evidence.