Routelearn.net
Course menu

Unit 14: Network TroubleshootingLesson 14.9 (9 of 10 in this unit)81 of 84 in the Network Fundamentals course

Lab: fix a broken office network

Five faults hidden in one small network. Find and fix each one with the method.

Intermediate · 25 min read

Network troubleshooting is the systematic process of finding and fixing the cause of a network fault: defining the symptom, gathering facts with commands, testing one likely cause at a time, applying a fix and verifying it from the user's side.

In simple terms: It is detective work for networks: collect clues, check the most likely suspect, fix it, then prove the problem is really gone.

The situation

You are the new IT person at a small office. Over the weekend, someone “tidied up” the network. On Monday, the help desk has a pile of tickets. There are five faults hidden in this network. For each ticket, use the troubleshooting method: define the problem, decide which command to run, predict what you will see, and only then open the answer.

Gi0/0trunkVLAN 20trunkGi1/0/1Gi1/0/2Gi1/0/3Gi1/0/4ISP198.51.100.1R1DHCP for VLAN 10SW1SRV1192.168.20.5SW2AnaBenCarastatic IPPrinter192.168.10.50
  1. 1. Your job: get every user working again. Traffic from VLAN 10 must reach SRV1 and the internet.
  2. 2. Servers: SRV1 is the file server and the office DNS server, in VLAN 20.

How it should be set up

DeviceInterfaceCorrect setting
R1Gi0/0198.51.100.2/30; ISP at 198.51.100.1; PAT for internet traffic
R1Gi0/1.10 / Gi0/1.20192.168.10.1/24 (VLAN 10, staff) / 192.168.20.1/24 (VLAN 20, servers)
R1 DHCP poolVLAN 10Gateway 192.168.10.1, DNS 192.168.20.5
SW2Gi1/0/1–4Access ports in VLAN 10
Cara's laptopStatic192.168.10.60/24, gateway 192.168.10.1, DNS 192.168.20.5
PrinterStatic192.168.10.50/24, gateway 192.168.10.1

The tickets

  1. Ana: "My PC says the network cable is unplugged. I didn't touch it."
  2. Ben: "My PC has a 169.254 address."
  3. Cara: "I can print, but I can't open the file server or any website."
  4. Everyone: "No websites work at all, not even by IP address."
  5. Ana and Ben, after ticket 4 is fixed: "Websites still fail by name, and so does fileserver.office.example."

💡 Work bottom-up for tickets 1 and 2, and use divide and conquer with ping for the rest. All Cisco output in this lab is based on Cisco documentation, not run on a lab device.

Fault 1: Ana has no link

Which command on SW2 shows the state of every port in one view?

Show answer
Example output · based on Cisco documentation; exact format varies by platform and software version
SW2#show interfaces status
Port      Name         Status       Vlan       Duplex  Speed Type
Gi1/0/1   Ana          disabled     10           auto   auto 10/100/1000BaseTX
Gi1/0/2   Ben          connected    99         a-full a-1000 10/100/1000BaseTX
Gi1/0/3   Cara         connected    10         a-full a-1000 10/100/1000BaseTX
Gi1/0/4   Printer      connected    10         a-full  a-100 10/100/1000BaseTX
Gi1/0/24  Uplink-SW1   connected    trunk      a-full a-1000 10/100/1000BaseTX
What to look for: Gi1/0/1 shows disabled, which means the port was shut down by hand (administratively down). The cable was never the problem.
Example output · based on Cisco documentation; exact format varies by platform and software version
SW2(config)#interface gigabitEthernet1/0/1
SW2(config-if)#no shutdown
SW2(config-if)#end
%LINK-3-UPDOWN: Interface GigabitEthernet1/0/1, changed state to up
%LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/0/1, changed state to up
The two log messages confirm that the interface and its line protocol have come up.

Verify: the port shows connected, and Ana gets a 192.168.10.x address.

Fault 2: Ben gets 169.254

Ben's link is up. Look at the same output again. What is different about his port?

Show answer

Gi1/0/2 is in VLAN 99. R1 only provides DHCP in VLAN 10, so Ben's request never reaches it, and Windows falls back to an APIPA address.

Example output · based on Cisco documentation; exact format varies by platform and software version
SW2(config)#interface gigabitEthernet1/0/2
SW2(config-if)#switchport access vlan 10
SW2(config-if)#end

Verify: show vlan brief lists Gi1/0/2 under VLAN 10, and ipconfig /renew on Ben's PC gives him a real address.

Fault 3: Cara can print but nothing else

Printing is local traffic. Everything else leaves the subnet. Which setting does that point to?

Show answer
Example output · typical of Windows, written for this lab, not captured from a real computer
C:\> ipconfig
   IPv4 Address. . . . . . . . . . . : 192.168.10.60
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.10.254
What to look for: the address and mask are correct, but the Default Gateway is 192.168.10.254, which doesn't exist. Set it to 192.168.10.1. Verify with ping 192.168.10.1 and then ping 192.168.20.5.

Fault 4: no one reaches the internet

Hint: tracert -d 203.0.113.80 from any PC stops at 192.168.10.1, which reports: Destination net unreachable. What does that tell you, and what should you check on R1?

Show answer
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip route static
R1 itself reports that it has no route, so look at its routing table. The output is empty: there are no static routes at all, and show ip route says Gateway of last resort is not set. Next, look at the configuration:
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show running-config | include ip route
ip route 0.0.0.0 0.0.0.0 198.51.100.5
The default route is configured, but its next hop is mistyped. 198.51.100.5 is not inside R1's connected network 198.51.100.0/30, so IOS can't reach the next hop and leaves the route out of the routing table.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1(config)#no ip route 0.0.0.0 0.0.0.0 198.51.100.5
R1(config)#ip route 0.0.0.0 0.0.0.0 198.51.100.1
R1(config)#end
R1#show ip route static
      ...
S*    0.0.0.0/0 [1/0] via 198.51.100.1
The S* line shows the static default route is now in the routing table, with the ISP router as the next hop.

Verify: ping 203.0.113.80 from a PC now gets replies.

Fault 5: names still fail

Ping by IP address now works for everyone. What do Ben's DNS settings say, and where did they come from?

Show answer
Example output · typical of Windows, written for this lab, not captured from a real computer
C:\> ipconfig /all
   IPv4 Address. . . . . . . . . . . : 192.168.10.101(Preferred)
   Default Gateway . . . . . . . . . : 192.168.10.1
   DHCP Server . . . . . . . . . . . : 192.168.10.1
   DNS Servers . . . . . . . . . . . : 192.168.20.50
What to look for: DNS Servers shows 192.168.20.50, but it should be 192.168.20.5. The DHCP Server line shows the setting came from R1, so every DHCP user has the same problem. (Cara has the right DNS server typed in by hand, which is a good clue.)
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show running-config | section dhcp
ip dhcp excluded-address 192.168.10.1 192.168.10.99
ip dhcp pool STAFF
 network 192.168.10.0 255.255.255.0
 default-router 192.168.10.1
 dns-server 192.168.20.50
The dns-server line in the STAFF pool has the mistyped address.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1(config)#ip dhcp pool STAFF
R1(dhcp-config)#no dns-server 192.168.20.50
R1(dhcp-config)#dns-server 192.168.20.5
R1(dhcp-config)#end
Clients keep the old DNS setting until they renew their DHCP lease. Run ipconfig /renew (or reconnect), then verify with nslookup fileserver.office.example.

Final check

Close each ticket only after testing from the user's side: Ana and Ben get addresses, everyone can reach 192.168.20.5 and 203.0.113.80, and names resolve. Then write down all five causes and fixes, and save the configurations with copy running-config startup-config on R1 and SW2.