
Network Troubleshooting & Diagnostic Framework
Diagnose network issues systematically using OSI layer methodology and remediation workflows
What You Can Do
You can rapidly transform vague customer reports ("the network is slow") into actionable diagnostics with ranked root causes, confidence levels, and specific verification steps. The skill applies OSI layer methodology to isolate problems across physical, data link, network, transport, and application layers, then generates targeted remediation workflows with step-by-step instructions, expected outcomes, and escalation criteria for complex multi-vendor environments.
Features
Systematically analyze symptoms across all seven OSI layers to pinpoint which layer contains the root cause
Convert customer reports into structured diagnostic data with probability-ranked causes
Create step-by-step resolution procedures with verification checkpoints and success criteria
Analyze ping, tracert, netstat, tcpdump, and other diagnostic tool outputs to extract actionable insights
Prioritize investigation sequence when multiple simultaneous issues exist across different network segments
Generate knowledge base articles and escalation summaries for complex or recurring issues
Rank potential root causes by probability and provide evidence requirements for each diagnosis
Example Output
Example 1: Intermittent Connectivity Issue
Customer Report: "Users in Building C lose connectivity for 30 seconds every 2 hours"
Diagnosis Output:
- Layer 2 (Data Link) — 65% probability: Switch port flapping or spanning tree reconvergence
- Layer 3 (Network) — 25% probability: DHCP lease renewal timeout or gateway failover delay
- Layer 1 (Physical) — 10% probability: Intermittent cable fault
Recommended Next Steps:
- Check switch logs for port state changes (show interfaces status)
- Verify DHCP snooping and lease timing
- Test with static IP to isolate DHCP involvement
Example 2: Selective Application Failure
Customer Report: "Email works fine but file sharing is down; web browsing is slow"
Diagnosis Output:
- Layer 4 (Transport) — 70% probability: Port 445 (SMB) blocked; port 443 (HTTPS) congested
- Layer 3 (Network) — 20% probability: QoS policy affecting traffic classification
- Layer 7 (Application) — 10% probability: Application-specific issues
Verification Steps: Run netstat -ano to identify listening ports and establish connections to specific services
What's Included
- SKILL.md instruction file with complete diagnostic methodology and framework:
- OSI Layer Diagnostic Checklist: Physical through Application layer investigation matrix
- Symptom-to-Cause Mapping Template: Quick reference for translating customer reports to diagnostic categories
- Remediation Workflow Generator: Step-by-step procedures for common issues (DNS failures, DHCP problems, routing loops, switch misconfigurations)
- Telemetry Interpretation Guide: How to extract meaning from ping, tracert, netstat, and tcpdump output
- Escalation Documentation Template: Format for knowledge base articles and support ticket summaries
Who It's For
- Technical Support Engineers — Diagnose and resolve customer network connectivity issues faster with structured methodology
- Network Administrators — Triage multi-site or multi-vendor network problems using systematic layer-by-layer analysis
- Helpdesk Managers — Document troubleshooting procedures and escalation criteria for team knowledge sharing
- Solutions Architects — Validate network designs by systematically testing connectivity across all OSI layers
- IT Service Desk Leads — Create repeatable diagnostic workflows and SOP documentation for tier-1 and tier-2 support teams
Best For
- Customer connectivity outages and intermittent disconnection issues
- Network performance degradation (latency, packet loss, throughput reduction)
- Selective application failures (email works, file sharing doesn't)
- Multi-site or multi-vendor environment troubleshooting with complex routing
- Knowledge base article creation and escalation documentation
- Diagnostic tool output interpretation (ping, tracert, netstat, tcpdump, iperf results)







