Network Interface Health
Use this skill when a network symptom might be caused by a physical link, switch
port, cable, transceiver, duplex setting, or congested interface.
When to Use
- A host or VLAN has packet loss, latency spikes, or intermittent reachability.
- A switch or router interface shows CRCs, runts, giants, drops, resets, or flaps.
- You need to compare both ends of a link before replacing hardware.
- A change window needs before/after interface counter evidence.
- Monitoring reports rising
ifInErrors, ifOutErrors, or ifOutDiscards.
How It Works
Interface counters are evidence, but the trend matters more than the absolute
number. Capture a baseline, wait a measurement interval, capture again, then
compare increments.
show interfaces <interface>
show interfaces <interface> status
show logging | include <interface>|changed state|line protocol
On Linux hosts:
ip -s link show <interface>
ethtool <interface>
ethtool -S <interface>
Counter Reference
| Counter |
Meaning |
Common cause |
| CRC |
Received frame checksum failed |
Bad cable, dirty fiber, bad optic, duplex mismatch |
| input errors |
Aggregate receive-side errors |
Check sub-counters before concluding |
| runts |
Frames below minimum Ethernet size |
Duplex mismatch, collision domain, faulty NIC |
| giants |
Frames larger than expected MTU |
MTU mismatch or jumbo-frame boundary |
| input drops |
Device could not accept inbound packets |
Burst, oversubscription, CPU path, queue pressure |
| output drops |
Egress queue discarded packets |
Congestion, QoS policy, undersized uplink |
| resets |
Interface hardware reset |
Flapping, keepalive, driver, optic, power |
| collisions |
Ethernet collision counter |
Half duplex or negotiation mismatch |
Diagnosis Flow
CRCs Or Input Errors
- Confirm counters are incrementing, not just historical.
- Check both ends of the link. Receive-side errors usually point to the signal
arriving on that side, not necessarily the port reporting the error.
- Replace patch cable or clean/replace fiber and optics.
- Confirm speed/duplex settings match on both sides.
- Check logs for flap events around the same timestamp.
Drops
- Separate input drops from output drops.
- Compare interface rate against capacity.
- Check QoS policy, queue counters, and whether the link is an oversubscribed
uplink.
- Treat queue tuning as secondary. First prove whether the link is congested.
Duplex And Speed
Prefer auto-negotiation on modern Ethernet links when both sides support it. If
one side must be fixed, configure both sides explicitly and document why. Never
mix fixed speed/duplex on one side with auto on the other.
show interfaces <interface> | include duplex|speed
Safe Parser Example
Slice each interface block from one header to the next. Do not use an arbitrary
character window; large interface blocks can cause counters to be missed or
assigned to the wrong port.
import re
from typing import Any
HEADER_RE = re.compile(
r"^(?P<name>\S+) is (?P<status>(?:administratively )?down|up), "
r"line protocol is (?P<protocol>up|down)",
re.I | re.M,
)
ERROR_RE = re.compile(r"(?P<input>\d+) input errors, (?P<crc>\d+) CRC", re.I)
DROP_RE = re.compile(r"(?P<output>\d+) output errors", re.I)
DUPLEX_RE = re.compile(r"(?P<duplex>Full|Half|Auto)-duplex,\s+(?P<speed>[^,]+)", re.I)
def parse_show_interfaces(raw: str) -> list[dict[str, Any]]:
headers = list(HEADER_RE.finditer(raw))
interfaces = []
for index, header in enumerate(headers):
end = headers[index + 1].start() if index + 1 < len(headers) else len(raw)
block = raw[header.start():end]
errors = ERROR_RE.search(block)
drops = DROP_RE.search(block)
duplex = DUPLEX_RE.search(block)
interfaces.append({
"name": header.group("name"),
"status": header.group("status"),
"protocol": header.group("protocol"),
"duplex": duplex.group("duplex") if duplex else "unknown",
"speed": duplex.group("speed").strip() if duplex else "unknown",
"input_errors": int(errors.group("input")) if errors else 0,
"crc_errors": int(errors.group("crc")) if errors else 0,
"output_errors": int(drops.group("output")) if drops else 0,
})
return interfaces
Examples
CRCs On One Switch Port
- Capture counters on the local port.
- Capture counters on the connected remote port.
- Replace the cable or optic before changing routing or firewall rules.
- Clear counters only after recording the baseline.
- Recheck after a fixed interval.
Internet Slow But LAN Is Fine
- Check WAN interface drops/errors.
- Check LAN uplink utilization and output drops.
- Check gateway CPU if the WAN link is clean but throughput is still low.
- Compare wired and wireless tests before blaming upstream service.
Anti-Patterns
- Clearing counters before saving a baseline.
- Looking at only one side of a link.
- Assuming all historical CRCs are active problems without a time window.
- Mixing auto-negotiation on one side with fixed speed/duplex on the other.
- Treating output drops as a cable problem before checking congestion.
See Also
- Agent:
network-troubleshooter
- Skill:
network-config-validation
- Skill:
homelab-network-setup
1---2name: network-interface-health3description: Diagnose interface errors, drops, CRCs, duplex mismatches, flapping, speed negotiation issues, and counter trends on routers, switches, and Linux hosts.4---5
6# Network Interface Health
7
8Use this skill when a network symptom might be caused by a physical link, switch
9port, cable, transceiver, duplex setting, or congested interface.
10
11## When to Use
12
13- A host or VLAN has packet loss, latency spikes, or intermittent reachability.
14- A switch or router interface shows CRCs, runts, giants, drops, resets, or flaps.
15- You need to compare both ends of a link before replacing hardware.
16- A change window needs before/after interface counter evidence.
17- Monitoring reports rising `ifInErrors`, `ifOutErrors`, or `ifOutDiscards`.
18
19## How It Works
20
21Interface counters are evidence, but the trend matters more than the absolute
22number. Capture a baseline, wait a measurement interval, capture again, then
23compare increments.
24
25```text
26show interfaces <interface>
27show interfaces <interface> status
28show logging | include <interface>|changed state|line protocol
29```
30
31On Linux hosts:
32
33```text
34ip -s link show <interface>
35ethtool <interface>
36ethtool -S <interface>
37```
38
39## Counter Reference
40
41| Counter | Meaning | Common cause |
42| --- | --- | --- |
43| CRC | Received frame checksum failed | Bad cable, dirty fiber, bad optic, duplex mismatch |
44| input errors | Aggregate receive-side errors | Check sub-counters before concluding |
45| runts | Frames below minimum Ethernet size | Duplex mismatch, collision domain, faulty NIC |
46| giants | Frames larger than expected MTU | MTU mismatch or jumbo-frame boundary |
47| input drops | Device could not accept inbound packets | Burst, oversubscription, CPU path, queue pressure |
48| output drops | Egress queue discarded packets | Congestion, QoS policy, undersized uplink |
49| resets | Interface hardware reset | Flapping, keepalive, driver, optic, power |
50| collisions | Ethernet collision counter | Half duplex or negotiation mismatch |
51
52## Diagnosis Flow
53
54### CRCs Or Input Errors
55
561. Confirm counters are incrementing, not just historical.
572. Check both ends of the link. Receive-side errors usually point to the signal
58 arriving on that side, not necessarily the port reporting the error.
593. Replace patch cable or clean/replace fiber and optics.
604. Confirm speed/duplex settings match on both sides.
615. Check logs for flap events around the same timestamp.
62
63### Drops
64
651. Separate input drops from output drops.
662. Compare interface rate against capacity.
673. Check QoS policy, queue counters, and whether the link is an oversubscribed
68 uplink.
694. Treat queue tuning as secondary. First prove whether the link is congested.
70
71### Duplex And Speed
72
73Prefer auto-negotiation on modern Ethernet links when both sides support it. If
74one side must be fixed, configure both sides explicitly and document why. Never
75mix fixed speed/duplex on one side with auto on the other.
76
77```text
78show interfaces <interface> | include duplex|speed
79```
80
81## Safe Parser Example
82
83Slice each interface block from one header to the next. Do not use an arbitrary
84character window; large interface blocks can cause counters to be missed or
85assigned to the wrong port.
86
87```python
88import re
89from typing import Any
90
91HEADER_RE = re.compile(
92 r"^(?P<name>\S+) is (?P<status>(?:administratively )?down|up), "
93 r"line protocol is (?P<protocol>up|down)",
94 re.I | re.M,
95)
96ERROR_RE = re.compile(r"(?P<input>\d+) input errors, (?P<crc>\d+) CRC", re.I)
97DROP_RE = re.compile(r"(?P<output>\d+) output errors", re.I)
98DUPLEX_RE = re.compile(r"(?P<duplex>Full|Half|Auto)-duplex,\s+(?P<speed>[^,]+)", re.I)
99
100def parse_show_interfaces(raw: str) -> list[dict[str, Any]]:
101 headers = list(HEADER_RE.finditer(raw))
102 interfaces = []
103 for index, header in enumerate(headers):
104 end = headers[index + 1].start() if index + 1 < len(headers) else len(raw)
105 block = raw[header.start():end]
106 errors = ERROR_RE.search(block)
107 drops = DROP_RE.search(block)
108 duplex = DUPLEX_RE.search(block)
109 interfaces.append({
110 "name": header.group("name"),
111 "status": header.group("status"),
112 "protocol": header.group("protocol"),
113 "duplex": duplex.group("duplex") if duplex else "unknown",
114 "speed": duplex.group("speed").strip() if duplex else "unknown",
115 "input_errors": int(errors.group("input")) if errors else 0,
116 "crc_errors": int(errors.group("crc")) if errors else 0,
117 "output_errors": int(drops.group("output")) if drops else 0,
118 })
119 return interfaces
120```
121
122## Examples
123
124### CRCs On One Switch Port
125
1261. Capture counters on the local port.
1272. Capture counters on the connected remote port.
1283. Replace the cable or optic before changing routing or firewall rules.
1294. Clear counters only after recording the baseline.
1305. Recheck after a fixed interval.
131
132### Internet Slow But LAN Is Fine
133
1341. Check WAN interface drops/errors.
1352. Check LAN uplink utilization and output drops.
1363. Check gateway CPU if the WAN link is clean but throughput is still low.
1374. Compare wired and wireless tests before blaming upstream service.
138
139## Anti-Patterns
140
141- Clearing counters before saving a baseline.
142- Looking at only one side of a link.
143- Assuming all historical CRCs are active problems without a time window.
144- Mixing auto-negotiation on one side with fixed speed/duplex on the other.
145- Treating output drops as a cable problem before checking congestion.
146
147## See Also
148
149- Agent: `network-troubleshooter`
150- Skill: `network-config-validation`
151- Skill: `homelab-network-setup`