A real-life situation
A user says, “My PC can't get online.” Before you look at any switch or router, check what the PC itself believes. Very often it has no address from DHCP, the wrong default gateway, or an old DNS server typed in by hand. Four settings decide almost everything a host does on the network.
What to check
| Setting | Why it matters | Windows | Linux | macOS |
|---|---|---|---|---|
| IP address and subnet mask | Decides which addresses are “local” | ipconfig /all | ip addr | ifconfig |
| Default gateway | Where traffic for other networks goes | ipconfig, route print | ip route | netstat -rn |
| DNS servers | Which server translates names into IP addresses | ipconfig /all | resolvectl status | scutil --dns |
| ARP cache | The MAC address of each local IP address | arp -a | ip neigh | arp -a |
- 1. Address: the PC asks the DHCP server for its IP address, subnet mask, default gateway and DNS server.
- 2. Gateway MAC: to send traffic to another network, the PC uses ARP to learn the gateway's MAC address.
- 3. Names: every name lookup goes to the DNS server the PC was given.
- 4. Off-network traffic: goes to the default gateway, which routes it onwards.
Reading ipconfig and ip addr
C:\> ipconfig /all Ethernet adapter Ethernet: Physical Address. . . . . . . . . : 02-00-5E-10-00-25 DHCP Enabled. . . . . . . . . . . : Yes IPv4 Address. . . . . . . . . . . : 169.254.37.12(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.0.0 Default Gateway . . . . . . . . . : DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
169.254. This is an APIPA (Automatic Private IP Addressing) address, which Windows assigns to itself when no DHCP server answers. The Default Gateway is empty, and the DNS server fec0:0:0:ffff::1%1 is only a placeholder that Windows shows when no real DNS server was received. So the real question is: why can't the PC reach the DHCP server? Check the cable, the switch port, the VLAN and the DHCP server itself.$ ip addr show eth0 2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP group default qlen 1000 link/ether 02:00:5e:10:00:25 brd ff:ff:ff:ff:ff:ff inet 192.168.10.25/24 brd 192.168.10.255 scope global dynamic eth0 valid_lft 85934sec preferred_lft 85934sec
UP,LOWER_UP means the interface is enabled and has a physical link. inet 192.168.10.25/24 is the IP address, and /24 is the subnet mask (255.255.255.0). dynamic means the address came from DHCP, and valid_lft shows how many seconds are left on the lease.$ ip route default via 192.168.10.1 dev eth0 proto dhcp metric 100 192.168.10.0/24 dev eth0 proto kernel scope link src 192.168.10.25
default via 192.168.10.1 line is the default gateway, learned from DHCP (proto dhcp). The second line is the local subnet, which the PC reaches directly. If there is no default line, the PC can only reach its own subnet.The ARP cache and nslookup
The ARP cache is the PC's list of local IP addresses and the MAC address that belongs to each one. Entries are added when the PC talks to a device and expire after a while. If the gateway still has no entry right after you ping it, the PC can't reach the gateway at Layer 2.
C:\> arp -a Interface: 192.168.10.25 --- 0x7 Internet Address Physical Address Type 192.168.10.1 00-1b-54-aa-10-01 dynamic 192.168.10.255 ff-ff-ff-ff-ff-ff static
192.168.10.1 has a dynamic entry, so ARP worked and the PC knows the gateway's MAC address. The static ff-ff-ff-ff-ff-ff entry is the subnet's broadcast address and is always there. On Linux, ip neigh shows the same information; FAILED or INCOMPLETE means no ARP reply came back.C:\> nslookup intranet.example.com Server: dns1.example.com Address: 192.168.10.5 Name: intranet.example.com Address: 192.168.20.80
192.168.10.5). The last two lines are the answer: the IP address of the name. If the server is not the one you expect, the PC has the wrong DNS settings.Learn more: DNS Problems
Why these fixes work
ipconfig /release && ipconfig /renewWindows: release the DHCP address and ask for a new one. Linux: sudo dhclient -r && sudo dhclient, or reconnect in NetworkManager.
ipconfig /flushdnsWindows: clear cached DNS answers. Linux with systemd-resolved: resolvectl flush-caches.
arp -d *Windows (as administrator): clear the ARP cache. Linux: sudo ip neigh flush all.
These commands clear out old or wrong information so that the host learns it again. They don't fix the network itself. If the same problem comes back, the cause is somewhere else.
Check yourself
A user's Windows PC can't reach anything. ipconfig shows 169.254.37.12 and no default gateway. What is the most likely problem?
A Linux server can reach its own subnet but nothing else. Which command shows whether it has a default gateway?