A real-life situation
Two colleagues get the same ticket: "I can't open the intranet site." One walks to the user's desk and checks the cable. The other opens a browser and tries the site from their own PC. Both are following a real method. They just start at opposite ends of the OSI model, the seven-layer model of network communication, from the cable (Layer 1) up to the application (Layer 7).
What the three approaches are
| Approach | Start at | Good when | Downside |
|---|---|---|---|
| Bottom-up | Layer 1: cable, port lights, interface status | You suspect hardware, or nothing at all works | Slow if the fault is high up (for example, a mistyped URL) |
| Top-down | Layer 7: the application the user is using | Only one application or site fails; others work | You may check several upper layers before you find a lower-layer fault |
| Divide and conquer | Layer 3: usually a ping | You have no strong clue yet; often the fastest | Takes experience to read the result correctly |
Watch each approach
- 1. Bottom-up: check the cable, the port light and the switch port first, then the IP settings, then the application.
- 2. Top-down: try the website itself first. If it fails, try another site, then a ping, then the link.
- 3. Divide and conquer: start with a ping to the server. If it succeeds, Layers 1–3 work, so look higher. If it fails, look lower.
Why divide and conquer is so popular
A ping sends a small test message and waits for a reply. If a ping from the PC to the web server's IP address works, then the cable, the switch, the IP addresses and the routing are all fine in both directions. One test has cleared three layers. You only need to look at what sits above them: the service itself, the firewall rules for that port, or DNS.
If the ping fails, the problem is most likely at Layer 3 or below, so you work downwards from there. (Remember that some servers and firewalls block ping, so check that ping normally works to that target.) Either way, one quick test has cut the search in half.
💡 Another simple technique is to follow the path: test hop by hop along the route the traffic takes (PC, switch, router, server) and stop where it fails. Traceroute does this for you automatically.
Learn more: Traceroute: Finding the Path
How to choose
- “Nothing works”, port lights are off, or the cabling is new: bottom-up.
- “Only this one app fails; everything else is fine”: top-down. The lower layers are clearly working.
- No clue yet: divide and conquer with a ping.
How to verify: one ping, two answers
- 1. Ping succeeds: Layers 1–3 work end to end. Check the web service, the firewall rules for port 443 and DNS next.
- 2. Ping fails: work downwards. Can the PC ping its gateway, R1? If not, the problem is local: the IP address, the VLAN or the cable.
Check yourself
A user can open every website except the company HR portal. Which approach fits best?
You ping the server's IP address and get replies. Which layers have you just shown to be working?