All guided builds

Troubleshooting labadvanced10 steps~30 min7 devices

Fix the branch that fails four ways

A branch depot has lost head office, and two of its hosts have faults of their own. Find all four, one layer at a time.

What you'll be able to do: Every host in the depot reaches the head-office file server and head office reaches every host back — after you found a shut port, a route to nowhere, a wrong gateway and a wrong VLAN, and fixed each with the smallest possible change.

Open the broken network in the lab 7 devices — needs any paid plan (the free canvas fits 5).

Topics: Troubleshooting · Static routing · VLANs · Default gateway · Interfaces

The network you're handed

Step by step

  1. 1. Map the symptoms before you touch anything

    Head office's file server is unreachable from the depot. Test from three hosts and write down what each can and cannot reach: the printer (known to be configured correctly), the dispatch desk, and the stock desk.

    On Depot-Printer — The known-good host: test head office, then the gateway

    ping 172.16.1.10
    ping 192.168.60.1

    On PC-Dispatch — Test head office from the dispatch desk

    ping 172.16.1.10

    On PC-Stock — Test the gateway from the stock desk

    ping 192.168.60.1

    Check: run ipconfig on Depot-Printer and look for Default Gateway . . . . . . . . : 192.168.60.1.

    Why: Two patterns means at least two faults. Everyone loses head office, including a printer whose settings are right and which reaches its gateway — so one fault is at or beyond Depot-GW, on the path everybody shares. PC-Stock cannot reach even the gateway, a local fault of its own. Take the shared fault first: it affects every user, and while it is there it hides any other host-level problem behind the same failure.

  2. 2. Fault 1 — find it: the WAN port

    The shared path leaves the depot through Depot-GW. Start at the bottom of the stack on that router: are its interfaces up? Then try to reach the far end of the WAN link from the router itself.

    On Depot-GW — Check every port's state, then test the far end of the WAN

    enable
    show ip interface brief
    ping 10.0.0.2

    Check: run show ip interface brief on Depot-GW and look for Se0/0/0 10.0.0.1 YES manual administratively down down.

    Why: `administratively down` means the port was never enabled — a configuration fault, not a broken cable. With the WAN port down the router has no connected route to 10.0.0.0/30, so nothing it holds can reach head office, whatever the routing table says.

  3. 3. Fault 1 — fix it: enable the WAN port

    Bring Se0/0/0 up and retest the far end of the link from the router.

    On Depot-GW — Enable the WAN port, then retest

    enable
    configure terminal
    interface Se0/0/0
    no shutdown
    end
    ping 10.0.0.2

    Check: run show ip interface brief on Depot-GW and look for Se0/0/0 10.0.0.1 YES manual up up.

    Why: Up/up on the serial line means layers 1 and 2 of the WAN are healthy, and the router now holds a connected route for 10.0.0.0/30 — which is why 10.0.0.2 answers.

  4. 4. Fault 2 — find it: a route to nowhere

    The link is up and the printer still cannot reach head office. Read Depot-GW's routing table: there is no default route in it. Then read the configuration — the route was typed, it just never made it into the table.

    On Depot-Printer — Retest from the known-good host

    ping 172.16.1.10

    On Depot-GW — Compare the routing table with the configured routes

    enable
    show ip route
    show running-config | include ip route

    Check: run show running-config | include ip route on Depot-GW and look for ip route 0.0.0.0 0.0.0.0 10.0.0.5.

    Why: The configuration holds a default route, but the table does not — so the router is refusing to install it. A next hop must sit on a subnet the router is connected to. Depot-GW's WAN is 10.0.0.0/30 (10.0.0.1 and 10.0.0.2 only); 10.0.0.5 belongs to a different /30, most likely another branch's link copied from a template.

  5. 5. Fault 2 — fix it: point the default route at the real neighbour

    Remove the wrong route first, then add the default route via 10.0.0.2 — the address at the other end of this depot's own WAN link. Retest from the printer.

    On Depot-GW — Replace the unreachable next hop with the WAN neighbour

    enable
    configure terminal
    no ip route 0.0.0.0 0.0.0.0 10.0.0.5
    ip route 0.0.0.0 0.0.0.0 10.0.0.2
    end

    On Depot-Printer — Retest head office

    ping 172.16.1.10

    Check: run show ip route on Depot-GW and look for S* 0.0.0.0/0 via 10.0.0.2, Se0/0/0.

    Why: 10.0.0.2 is on the connected /30, so the route resolves and installs as the gateway of last resort: everything the depot does not know is now handed across the WAN. Head office already had its route back to 192.168.60.0/24, so the path works in both directions.

  6. 6. Fault 3 — find it: the dispatch desk still fails

    With the shared path fixed, retest the other hosts. PC-Dispatch still cannot reach head office, yet it reaches 192.168.60.1 — the same gateway the printer uses successfully. Read its settings.

    On PC-Dispatch — Test head office, then the gateway, then read the host's settings

    ping 172.16.1.10
    ping 192.168.60.1
    ipconfig

    Check: run ipconfig on PC-Dispatch and look for Default Gateway . . . . . . . . : 192.168.60.254.

    Why: This fault was there all along, masked: while the WAN was down, every host failed the same way. Now that the printer gets through, a host that reaches the gateway's address but nothing beyond it can only be sending off-subnet traffic somewhere else — and 192.168.60.254 belongs to nobody.

  7. 7. Fault 3 — fix it: the right gateway on the dispatch desk

    Re-enter the desk's address with 192.168.60.1 as its gateway, and retest.

    On PC-Dispatch — Same address and mask, the router's address as the gateway

    ipconfig Eth0 192.168.60.21 255.255.255.0 192.168.60.1
    ping 172.16.1.10

    Check: run ipconfig on PC-Dispatch and look for Default Gateway . . . . . . . . : 192.168.60.1.

    Why: A host's gateway must be an address a router on its own subnet actually owns. There is one on this LAN, 192.168.60.1, and every host should point at it.

  8. 8. Fault 4 — find it: the stock desk is cut off locally

    PC-Stock cannot reach the gateway or the printer beside it, so the fault is on the LAN, between the desk and the switch. Its own settings look right — so read the switch's VLAN table and find Fa0/2.

    On PC-Stock — Test the gateway and the printer, then read the host's settings

    ping 192.168.60.1
    ping 192.168.60.30
    ipconfig

    On SW-Depot — See which VLAN each port is in

    enable
    show vlan brief

    Check: run show vlan brief on SW-Depot and look for 20 GUEST active Fa0/2.

    Why: The desk's address, mask and gateway are all correct, and it still cannot reach hosts on its own subnet — so no router is involved and the fault is layer 2. Fa0/2 sits in GUEST while the uplink and every other depot port sit in STAFF: the desk is in a different broadcast domain, and its ARP requests never reach the gateway.

  9. 9. Fault 4 — fix it: move the port into STAFF

    Put Fa0/2 into VLAN 10 and retest from the stock desk — the printer first, then head office.

    On SW-Depot — Reassign the stock desk's access port

    enable
    configure terminal
    interface Fa0/2
    switchport access vlan 10
    end

    On PC-Stock — Retest locally, then across the WAN

    ping 192.168.60.30
    ping 172.16.1.10

    Check: run show vlan brief on SW-Depot and look for 10 STAFF active Fa0/1, Fa0/2, Fa0/3, Gi0/1.

    Why: An access port belongs to exactly one VLAN. With Fa0/2 in STAFF the desk shares a broadcast domain with its gateway again, and every path the earlier fixes repaired opens up for it at once.

  10. 10. Prove the whole branch from head office

    Close the ticket from the far end: the file server pings every depot host, and HQ-Edge's table shows the route that carries the replies home.

    On HQ-Files — Reach every host in the depot

    ping 192.168.60.21
    ping 192.168.60.22
    ping 192.168.60.30

    On HQ-Edge — The route back to the depot

    enable
    show ip route

    Check: run show ip route on HQ-Edge and look for S 192.168.60.0/24 via 10.0.0.1, Se0/0/0.

    Why: Four faults on four layers — a port left shut, a next hop on nobody's subnet, a gateway nobody owns and a port in the wrong VLAN — each found with the one command that looks at that layer. Testing every host from the far end is what proves none of them is still hiding behind another.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Fix the branch that fails four ways — step-by-step network lab · NetForge-AI