Routelearn.net
Course menu

Unit 14: Network TroubleshootingLesson 14.3 (3 of 10 in this unit)75 of 84 in the Network Fundamentals course

Checking a computer's settings

ipconfig, ip addr, arp and nslookup: confirm what a host thinks its network looks like.

Beginner · 7 min read

Host configuration checks are commands such as ipconfig, ip addr, ip route, arp -a, ip neigh and nslookup that show a computer's IP address, subnet mask, default gateway, DNS servers and ARP cache, so you can confirm the host itself is set up correctly before looking at the network.

In simple terms: Before checking routers and switches, look at the computer itself: does it have a sensible IP address, the right default gateway and working DNS? A few commands tell you in seconds.

A real-life situation

A user says, “My PC can't get online.” Before you look at any switch or router, check what the PC itself believes. Very often it has no address from DHCP, the wrong default gateway, or an old DNS server typed in by hand. Four settings decide almost everything a host does on the network.

What to check

SettingWhy it mattersWindowsLinuxmacOS
IP address and subnet maskDecides which addresses are “local”ipconfig /allip addrifconfig
Default gatewayWhere traffic for other networks goesipconfig, route printip routenetstat -rn
DNS serversWhich server translates names into IP addressesipconfig /allresolvectl statusscutil --dns
ARP cacheThe MAC address of each local IP addressarp -aip neigharp -a
PC192.168.10.25/24SwitchGateway192.168.10.1DHCP / DNS192.168.10.5Other networks
  1. 1. Address: the PC asks the DHCP server for its IP address, subnet mask, default gateway and DNS server.
  2. 2. Gateway MAC: to send traffic to another network, the PC uses ARP to learn the gateway's MAC address.
  3. 3. Names: every name lookup goes to the DNS server the PC was given.
  4. 4. Off-network traffic: goes to the default gateway, which routes it onwards.

Reading ipconfig and ip addr

Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
C:\> ipconfig /all
Ethernet adapter Ethernet:

   Physical Address. . . . . . . . . : 02-00-5E-10-00-25
   DHCP Enabled. . . . . . . . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 169.254.37.12(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.0.0
   Default Gateway . . . . . . . . . :
   DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
What to look for: DHCP Enabled: Yes but an IPv4 Address starting with 169.254. This is an APIPA (Automatic Private IP Addressing) address, which Windows assigns to itself when no DHCP server answers. The Default Gateway is empty, and the DNS server fec0:0:0:ffff::1%1 is only a placeholder that Windows shows when no real DNS server was received. So the real question is: why can't the PC reach the DHCP server? Check the cable, the switch port, the VLAN and the DHCP server itself.
Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
$ ip addr show eth0
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000
    link/ether 02:00:5e:10:00:25 brd ff:ff:ff:ff:ff:ff
    inet 192.168.10.25/24 brd 192.168.10.255 scope global dynamic eth0
       valid_lft 85934sec preferred_lft 85934sec
What to look for: UP,LOWER_UP means the interface is enabled and has a physical link. inet 192.168.10.25/24 is the IP address, and /24 is the subnet mask (255.255.255.0). dynamic means the address came from DHCP, and valid_lft shows how many seconds are left on the lease.
Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
$ ip route
default via 192.168.10.1 dev eth0 proto dhcp metric 100
192.168.10.0/24 dev eth0 proto kernel scope link src 192.168.10.25
What to look for: the default via 192.168.10.1 line is the default gateway, learned from DHCP (proto dhcp). The second line is the local subnet, which the PC reaches directly. If there is no default line, the PC can only reach its own subnet.

The ARP cache and nslookup

The ARP cache is the PC's list of local IP addresses and the MAC address that belongs to each one. Entries are added when the PC talks to a device and expire after a while. If the gateway still has no entry right after you ping it, the PC can't reach the gateway at Layer 2.

Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
C:\> arp -a
Interface: 192.168.10.25 --- 0x7
  Internet Address      Physical Address      Type
  192.168.10.1          00-1b-54-aa-10-01     dynamic
  192.168.10.255        ff-ff-ff-ff-ff-ff     static
What to look for: the gateway 192.168.10.1 has a dynamic entry, so ARP worked and the PC knows the gateway's MAC address. The static ff-ff-ff-ff-ff-ff entry is the subnet's broadcast address and is always there. On Linux, ip neigh shows the same information; FAILED or INCOMPLETE means no ARP reply came back.
Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
C:\> nslookup intranet.example.com
Server:  dns1.example.com
Address:  192.168.10.5

Name:    intranet.example.com
Address:  192.168.20.80
What to look for: the first two lines show which DNS server the PC asked (192.168.10.5). The last two lines are the answer: the IP address of the name. If the server is not the one you expect, the PC has the wrong DNS settings.

Learn more: DNS Problems

Why these fixes work

ipconfig /release && ipconfig /renew

Windows: release the DHCP address and ask for a new one. Linux: sudo dhclient -r && sudo dhclient, or reconnect in NetworkManager.

ipconfig /flushdns

Windows: clear cached DNS answers. Linux with systemd-resolved: resolvectl flush-caches.

arp -d *

Windows (as administrator): clear the ARP cache. Linux: sudo ip neigh flush all.

These commands clear out old or wrong information so that the host learns it again. They don't fix the network itself. If the same problem comes back, the cause is somewhere else.

Check yourself

Predict · scenario 1

A user's Windows PC can't reach anything. ipconfig shows 169.254.37.12 and no default gateway. What is the most likely problem?

Predict · scenario 2

A Linux server can reach its own subnet but nothing else. Which command shows whether it has a default gateway?