Local DNS Failure Can Look Like a Dead Server
Test the known address before rebooting a host just because its name stopped resolving.
TOPIC
Lessons, explainers, experiments, and implementation notes.
Test the known address before rebooting a host just because its name stopped resolving.
A switch learns from source MAC addresses, not destination addresses. Watching the table populate makes unknown unicast, flooding and forwarding much easier to reason about.
Subnetting became much easier once I treated it as address boundaries and binary arithmetic instead of a collection of shortcut tables.
A topology view should consume routing state rather than infer a gateway from labels or layout.
A two-PC switch lab is simple enough to expose the actual sequence behind a successful ping: addressing, ARP, MAC learning and frame forwarding.
Both features route packets through another tailnet device, but they solve different problems.
STP made more sense after I created the failure it is designed to prevent: a Layer 2 loop with no TTL to save the network.
A peer can be reachable over the tailnet while an SSH login is correctly denied by another policy layer.
Topology is most useful when it explains packet movement across gateways, hosts, overlays and ingress first.
Resolve the symptom into DNS, routing, transport, policy, ingress or application before changing configuration.
Using DNS SRV records showed me how SIP clients can discover service hosts and ports without baking one server address into every configuration.
PAT stopped feeling like a magic Internet-sharing feature once I watched inside local addresses, public translations and transport ports change in the NAT table.
Capturing a simple ping showed that the interesting packet often arrives before ICMP: ARP has to resolve the Layer 2 destination first.
OSPF became useful when I compared it directly with the static routes I had been maintaining by hand and watched neighbors and learned routes change with the topology.
A VLAN is first a Layer 2 boundary. IP subnets often map to VLANs, but keeping those two concepts separate makes switching and routing much easier to reason about.
Connectivity tests become useful only when each test is tied to a layer: local addressing, routing, DNS resolution, TCP reachability and the application itself.
"SSH is not working" can mean several different things: the address is wrong, there is no route, nothing is listening on the port, or authentication failed. Restarting the server is not the universal answer.
A peer marked online is only the start. I also care whether the path is direct, relayed and stable enough for the workload.
I troubleshoot from the network boundary inward so I do not restart a healthy server because one naming or authorization layer failed.
My first memorable ACL mistake was technically correct: it blocked exactly what I told it to block, including the management traffic I still needed.
The tailnet can reach printers, embedded devices and LAN-only services without installing a Tailscale client on every endpoint.
A trunk can be up while one VLAN is still broken. That lab pushed me to verify allowed VLANs and operational state instead of assuming the link was simply good or bad.
A three-router topology is enough to show the most important routing lesson: reachability is directional, and the return path matters just as much as the forward path.
One router interface, an 802.1Q trunk and a few subinterfaces were enough to connect separate VLANs without hiding what was happening at Layer 2 and Layer 3.
DHCP is easier to troubleshoot when treated as a timed client-server exchange that delivers an address plus the parameters a host needs to participate in the network.
Wider channels suggest higher speed, but nearby networks still occupy the same radio environment. Increasing your own peak capacity and getting stable performance in that environment are not the same design decision.
Resolving a domain to an address is an important first step, but DNS cannot tell you whether the service is reachable, the certificate matches, or the application itself is working. Successful name resolution is not system health.
A trunk does not merge VLANs. It preserves multiple Layer 2 domains across one physical link by carrying VLAN identity with the frame.