Why does ping fail? A layer-by-layer checklist
Short answer
When ping fails, check from the bottom up: is the interface up, does each host have the right IP address and mask, does it have the right default gateway, are both ends in the right VLAN, does every router on the path have a route there AND back, and is an access list dropping the traffic. The first check that fails is your fault.
Most "the network is down" problems in a lab come down to a handful of causes. This lesson gives a bottom-up checklist — link, addressing, gateway, VLAN, routing, filtering — with the command that checks each one, so you can find the fault instead of guessing.
Open this labWork bottom-up, one layer at a time
Guessing wastes time because many faults look identical from the PC: the ping just times out. Each row below checks one thing, using a command that shows the answer directly. Stop at the first row that is wrong, fix it, and ping again.
| Check | Command | What wrong looks like |
|---|---|---|
| Link and interface up | show ip interface brief | Status down or administratively down — router ports start shut until no shutdown |
| IP address and mask | ipconfig (PC), show ip interface brief (router) | A typo, or the two ends in different subnets |
| Default gateway | ipconfig (PC) | Missing, or not the router's address on that subnet |
| VLAN membership | show vlan brief | The port in the wrong VLAN, or a trunk not carrying the VLAN |
| Routing, both directions | show ip route | No route to the destination — or none back to the source |
| Filtering | show access-lists | A deny line matching the traffic, often from a wrong wildcard |
| Layer 2 resolution | show arp, arp -a | An incomplete entry: nobody answered the ARP request |
Timed out versus unreachable
"Request timed out" means the echo left but no reply came back within the timeout — the packet or the reply was lost somewhere: a missing return route and an access list are the classic causes. "Destination host unreachable" means a device on the path could not forward the packet at all, often because the sender or a router had no route or could not resolve the next hop.
The return path is half the problem
A ping is two packets: the request and the reply. A route that gets the request there is useless without a route that brings the reply back. When a remote ping fails but every interface is up, check the routing table on the far router for a route to the source network.
Use traceroute to find where it stops
traceroute (tracert on a PC) lists each router hop that answers. The last hop that replies is the last device that had a working path; the fault is on the next hop or the link to it.
Common questions
- Why can I ping my gateway but not another network?
- The local link works, so the fault is further along: the router is missing a route to the destination, the far side has no route back, or an access list is dropping the traffic.
- What does 'request timed out' mean?
- The echo request was sent but no reply arrived in time — the request or the reply was dropped somewhere on the path.
- Why does the first ping fail and the rest succeed?
- The first packet waits for ARP to resolve the next-hop MAC address; once it is cached, the following pings go straight through.
- Why is my router interface down after I configured an IP address?
- Router interfaces start administratively down. Enter no shutdown in interface configuration mode to bring the interface up.
Practice this in the lab
Reading helps. Wiring it up yourself and breaking it makes it stick.
Open the lab