Analyze. Gather. Isolate. Solve.
The way you want to analyze, gather, troubleshoot and solve a network situation — as a CCNP engineer on a real network, and as a CCIE candidate with the lab clock running.
Elimination beats intuition.
Every fault is found the same way: remove everything that is not the problem, with evidence, until one explanation is left.
Evidence before action
No configuration change without output that supports it. "I think" is not evidence.
Split the problem in half
Every question you ask should rule out roughly half of the possible causes.
Find the first divergence
Follow the packet from the source. The first point where reality differs from expectation is where you work.
One change at a time
Change one variable, verify, then decide. Otherwise you never know what fixed it.
Prove it from the source
Done means tested from where the user is, in both directions — not a green line on one router.
Eight phases. Two levels of expectation.
Select a phase. For each one you see the goal, the questions to ask, the evidence to collect, how a CCNP engineer and a CCIE candidate are expected to work, the exit criteria and the trap to avoid.
From report to proof — and back when the evidence disagrees.
Rule out the foundation in minutes, not hours.
Sweep bottom-up quickly. A layer only counts as ruled out when the evidence in the "healthy when" column is on your screen.
| Layer / plane | What you check | Evidence (Cisco examples) | Healthy when | Typical faults |
|---|---|---|---|---|
| Physical | Link state, errors, optics, speed/duplex | show interfaces · show interfaces counters errors · show interfaces transceiver | up/up, no incrementing CRC/input errors, light levels in range | Bad cable/optic, duplex mismatch, err-disabled port |
| Data link | VLANs, trunks, STP, EtherChannel, MAC learning | show vlan brief · show interfaces trunk · show spanning-tree vlan X · show etherchannel summary · show mac address-table | VLAN allowed, active and forwarding; expected root; bundle (P); MAC learned on the right port | Pruned VLAN, native mismatch, wrong root, suspended member, loops |
| Network: addressing | IP/mask, gateway, ARP/ND, first hop | show ip interface brief · show ip arp · show ipv6 neighbors · show standby brief | Correct subnet on both ends, ARP complete, one active gateway | Wrong mask, duplicate IP, FHRP split-brain, missing helper |
| Control plane | Neighbors, routes, best path, redistribution | show ip ospf neighbor · show ip eigrp neighbors · show bgp ipv4 unicast summary · show ip route X | Adjacencies FULL/Established, route present with expected source, AD and next hop | Parameter mismatch, filtering, next hop unreachable, loops by redistribution |
| Data plane | What the hardware actually does | show ip cef X detail · show ip cef exact-route S D · show mpls forwarding-table · traceroute | CEF matches the RIB, labels present, traceroute follows the design | Recursive failure, missing label, ECMP to a dead path |
| Policy & security | ACLs, NAT, zones, QoS, uRPF, AAA | show access-lists (hit counters) · show ip nat translations · show policy-map interface | Counters match expected traffic, translations present, no unexpected drops | Implicit deny, wrong direction, NAT of VPN traffic, CoPP drops |
| Overlay & services | Tunnels, VPNs, VXLAN, SD-WAN, DHCP, DNS, NTP | show crypto ipsec sa · show dmvpn · show nve peers · show sdwan bfd sessions · show ntp status | SAs encrypt and decrypt, peers up, time synchronised | MTU/overhead, NHRP, RT mismatch, clock skew |
| Management & automation | Reachability of the device, APIs, telemetry | show netconf-yang status · API status codes · show telemetry ietf subscription all | Session up, 2xx responses, subscriptions valid | 401/404, lock-denied, invalid XPath, expired tokens |
What you see decides where you look first.
Pick the symptom. You get the first question to ask, the elimination steps in order and the domains where the cause usually lives.
Same process. Different depth, speed and scope.
| Dimension | CCNP engineer | CCIE candidate |
|---|---|---|
| Scope | One domain at a time, a handful of devices | Multiple interacting domains; faults hide behind other faults |
| Speed | Accuracy first; minutes per check are acceptable | A full layer sweep in minutes; every command has a purpose |
| Evidence | Reads show output and recognises obvious mismatches | Predicts the output before running it and notices what is missing |
| Protocol depth | Knows states, timers and common parameters | Knows selection algorithms, loop prevention and side-effects between protocols |
| Hypotheses | One hypothesis tested at a time | Ranks several hypotheses by probability and cost to test |
| Change | Correct fix for the symptom | Minimal fix that meets every requirement and constraint in the task |
| Verification | Tests the reported path | Tests the reported path, the reverse path and everything the change could affect |
| Time | Escalates when stuck | Timeboxes, moves on and returns with fresh eyes |
Manage the clock like a resource.
A guideline for a troubleshooting task under exam pressure. Reset the clock for every task; when a box runs out, decide consciously.
Stuck past the timebox? Note what you ruled out, move on, and come back. The notes make the second attempt fast.
Learn it here. Drill it online. Perform it in Lelystad.
Every NDA scenario and every campus simulation is coached along this process — our instructors ask the questions, you collect the evidence.