Most early network work is not about clever protocols. It is about disciplined observation: what changed, what is still green, and what the ticket language is hiding.
Use this as a personal checklist — not a rigid runbook. Adjust for your ISP, campus, or enterprise edge.
1. Confirm the complaint
Rewrite the symptom in one sentence: who is affected, where, since when, and what still works. "Internet down" is not a diagnosis — "branch VLAN 40 cannot reach DNS after 09:12" is.
2. Physical and link layer
Check link lights, negotiated speed/duplex, errors/CRC counters, and whether the fault follows a cable, port, or CPE. Layer 1 lies quietly until you look.
3. Address and gateway truth
Verify the host got the expected IP, mask, gateway, and DNS. A "routing" ticket is often a wrong gateway or a stale DHCP lease.
4. Path and policy
Trace one hop at a time toward the destination. Note where packets stop. Then ask: ACL, NAT, VRF, firewall policy, or upstream?
5. Document before you escalate
Capture timestamps, interfaces, commands run, and what you ruled out. Clean escalation is a skill — it is also how analysts get trusted with harder work.
Closing
This page will expand with Packet Tracer lab references and anonymized ISP-edge patterns from Tikona-style triage.