Troubleshooting labadvanced10 steps~30 min7 devices
Fix the branch that fails four ways
A branch depot has lost head office, and two of its hosts have faults of their own. Find all four, one layer at a time.
What you'll be able to do: Every host in the depot reaches the head-office file server and head office reaches every host back — after you found a shut port, a route to nowhere, a wrong gateway and a wrong VLAN, and fixed each with the smallest possible change.
Topics: Troubleshooting · Static routing · VLANs · Default gateway · Interfaces
The network you're handed
- Depot-GW — a router, the depot's router and every host's gateway
- HQ-Edge — a router, the head-office router at the far end of the WAN
- SW-Depot — a switch, the depot's access switch
- PC-Dispatch — a pc, the dispatch desk
- PC-Stock — a pc, the stock-control desk
- Depot-Printer — a printer, the depot's label printer, configured correctly
- HQ-Files — a server, the head-office file server everyone needs
Step by step
1. Map the symptoms before you touch anything
Head office's file server is unreachable from the depot. Test from three hosts and write down what each can and cannot reach: the printer (known to be configured correctly), the dispatch desk, and the stock desk.
On Depot-Printer — The known-good host: test head office, then the gateway
ping 172.16.1.10 ping 192.168.60.1On PC-Dispatch — Test head office from the dispatch desk
ping 172.16.1.10On PC-Stock — Test the gateway from the stock desk
ping 192.168.60.1Check: run
ipconfigon Depot-Printer and look forDefault Gateway . . . . . . . . : 192.168.60.1.Why: Two patterns means at least two faults. Everyone loses head office, including a printer whose settings are right and which reaches its gateway — so one fault is at or beyond Depot-GW, on the path everybody shares. PC-Stock cannot reach even the gateway, a local fault of its own. Take the shared fault first: it affects every user, and while it is there it hides any other host-level problem behind the same failure.
2. Fault 1 — find it: the WAN port
The shared path leaves the depot through Depot-GW. Start at the bottom of the stack on that router: are its interfaces up? Then try to reach the far end of the WAN link from the router itself.
On Depot-GW — Check every port's state, then test the far end of the WAN
enable show ip interface brief ping 10.0.0.2Check: run
show ip interface briefon Depot-GW and look forSe0/0/0 10.0.0.1 YES manual administratively down down.Why: `administratively down` means the port was never enabled — a configuration fault, not a broken cable. With the WAN port down the router has no connected route to 10.0.0.0/30, so nothing it holds can reach head office, whatever the routing table says.
3. Fault 1 — fix it: enable the WAN port
Bring Se0/0/0 up and retest the far end of the link from the router.
On Depot-GW — Enable the WAN port, then retest
enable configure terminal interface Se0/0/0 no shutdown end ping 10.0.0.2Check: run
show ip interface briefon Depot-GW and look forSe0/0/0 10.0.0.1 YES manual up up.Why: Up/up on the serial line means layers 1 and 2 of the WAN are healthy, and the router now holds a connected route for 10.0.0.0/30 — which is why 10.0.0.2 answers.
4. Fault 2 — find it: a route to nowhere
The link is up and the printer still cannot reach head office. Read Depot-GW's routing table: there is no default route in it. Then read the configuration — the route was typed, it just never made it into the table.
On Depot-Printer — Retest from the known-good host
ping 172.16.1.10On Depot-GW — Compare the routing table with the configured routes
enable show ip route show running-config | include ip routeCheck: run
show running-config | include ip routeon Depot-GW and look forip route 0.0.0.0 0.0.0.0 10.0.0.5.Why: The configuration holds a default route, but the table does not — so the router is refusing to install it. A next hop must sit on a subnet the router is connected to. Depot-GW's WAN is 10.0.0.0/30 (10.0.0.1 and 10.0.0.2 only); 10.0.0.5 belongs to a different /30, most likely another branch's link copied from a template.
5. Fault 2 — fix it: point the default route at the real neighbour
Remove the wrong route first, then add the default route via 10.0.0.2 — the address at the other end of this depot's own WAN link. Retest from the printer.
On Depot-GW — Replace the unreachable next hop with the WAN neighbour
enable configure terminal no ip route 0.0.0.0 0.0.0.0 10.0.0.5 ip route 0.0.0.0 0.0.0.0 10.0.0.2 endOn Depot-Printer — Retest head office
ping 172.16.1.10Check: run
show ip routeon Depot-GW and look forS* 0.0.0.0/0 via 10.0.0.2, Se0/0/0.Why: 10.0.0.2 is on the connected /30, so the route resolves and installs as the gateway of last resort: everything the depot does not know is now handed across the WAN. Head office already had its route back to 192.168.60.0/24, so the path works in both directions.
6. Fault 3 — find it: the dispatch desk still fails
With the shared path fixed, retest the other hosts. PC-Dispatch still cannot reach head office, yet it reaches 192.168.60.1 — the same gateway the printer uses successfully. Read its settings.
On PC-Dispatch — Test head office, then the gateway, then read the host's settings
ping 172.16.1.10 ping 192.168.60.1 ipconfigCheck: run
ipconfigon PC-Dispatch and look forDefault Gateway . . . . . . . . : 192.168.60.254.Why: This fault was there all along, masked: while the WAN was down, every host failed the same way. Now that the printer gets through, a host that reaches the gateway's address but nothing beyond it can only be sending off-subnet traffic somewhere else — and 192.168.60.254 belongs to nobody.
7. Fault 3 — fix it: the right gateway on the dispatch desk
Re-enter the desk's address with 192.168.60.1 as its gateway, and retest.
On PC-Dispatch — Same address and mask, the router's address as the gateway
ipconfig Eth0 192.168.60.21 255.255.255.0 192.168.60.1 ping 172.16.1.10Check: run
ipconfigon PC-Dispatch and look forDefault Gateway . . . . . . . . : 192.168.60.1.Why: A host's gateway must be an address a router on its own subnet actually owns. There is one on this LAN, 192.168.60.1, and every host should point at it.
8. Fault 4 — find it: the stock desk is cut off locally
PC-Stock cannot reach the gateway or the printer beside it, so the fault is on the LAN, between the desk and the switch. Its own settings look right — so read the switch's VLAN table and find Fa0/2.
On PC-Stock — Test the gateway and the printer, then read the host's settings
ping 192.168.60.1 ping 192.168.60.30 ipconfigOn SW-Depot — See which VLAN each port is in
enable show vlan briefCheck: run
show vlan briefon SW-Depot and look for20 GUEST active Fa0/2.Why: The desk's address, mask and gateway are all correct, and it still cannot reach hosts on its own subnet — so no router is involved and the fault is layer 2. Fa0/2 sits in GUEST while the uplink and every other depot port sit in STAFF: the desk is in a different broadcast domain, and its ARP requests never reach the gateway.
9. Fault 4 — fix it: move the port into STAFF
Put Fa0/2 into VLAN 10 and retest from the stock desk — the printer first, then head office.
On SW-Depot — Reassign the stock desk's access port
enable configure terminal interface Fa0/2 switchport access vlan 10 endOn PC-Stock — Retest locally, then across the WAN
ping 192.168.60.30 ping 172.16.1.10Check: run
show vlan briefon SW-Depot and look for10 STAFF active Fa0/1, Fa0/2, Fa0/3, Gi0/1.Why: An access port belongs to exactly one VLAN. With Fa0/2 in STAFF the desk shares a broadcast domain with its gateway again, and every path the earlier fixes repaired opens up for it at once.
10. Prove the whole branch from head office
Close the ticket from the far end: the file server pings every depot host, and HQ-Edge's table shows the route that carries the replies home.
On HQ-Files — Reach every host in the depot
ping 192.168.60.21 ping 192.168.60.22 ping 192.168.60.30On HQ-Edge — The route back to the depot
enable show ip routeCheck: run
show ip routeon HQ-Edge and look forS 192.168.60.0/24 via 10.0.0.1, Se0/0/0.Why: Four faults on four layers — a port left shut, a next hop on nobody's subnet, a gateway nobody owns and a port in the wrong VLAN — each found with the one command that looks at that layer. Testing every host from the far end is what proves none of them is still hiding behind another.
The theory behind it
More in Troubleshooting
- Fix the broken office — Nobody in a two-desk office can reach the intranet server. Find the two faults and fix them, one layer at a time.
- Fix the VLAN that stops at the trunk — Engineering's server is unreachable and the south desk is cut off completely. Find the wrong VLAN and the trunk that drops it.
- Fix the desks DHCP forgot — The clinic's desks come up with no address. Find why the DHCP server never hears them — then why their leases still go nowhere.
- Fix the NAT that translates nothing — The shop's desks and tills cannot reach the internet, yet the router itself can. Find why nothing leaves translated.
- Fix the OSPF adjacencies — Three routers run OSPF and nothing converges. Find the area mismatch and the network statement that matches nothing.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab