Routelearn.net
Course menu

Unit 14: Network TroubleshootingLesson 14.2 (2 of 10 in this unit)74 of 84 in the Network Fundamentals course

Bottom-up, top-down, divide and conquer

Three ways to walk the OSI layers, and how to choose between them.

Beginner · 6 min read

Layered troubleshooting approaches are ways of checking the OSI layers in a set order. Bottom-up starts at the physical layer, top-down starts at the application, and divide and conquer starts in the middle, usually with a ping at Layer 3, then moves up or down depending on the result.

In simple terms: Instead of checking things at random, you pick a starting point (the cable, the app or the middle) and work through the layers until you find the broken one.

A real-life situation

Two colleagues get the same ticket: "I can't open the intranet site." One walks to the user's desk and checks the cable. The other opens a browser and tries the site from their own PC. Both are following a real method. They just start at opposite ends of the OSI model, the seven-layer model of network communication, from the cable (Layer 1) up to the application (Layer 7).

What the three approaches are

ApproachStart atGood whenDownside
Bottom-upLayer 1: cable, port lights, interface statusYou suspect hardware, or nothing at all worksSlow if the fault is high up (for example, a mistyped URL)
Top-downLayer 7: the application the user is usingOnly one application or site fails; others workYou may check several upper layers before you find a lower-layer fault
Divide and conquerLayer 3: usually a pingYou have no strong clue yet; often the fastestTakes experience to read the result correctly

Watch each approach

PC192.168.10.25SW1R1192.168.10.1Web server203.0.113.80
  1. 1. Bottom-up: check the cable, the port light and the switch port first, then the IP settings, then the application.
  2. 2. Top-down: try the website itself first. If it fails, try another site, then a ping, then the link.
  3. 3. Divide and conquer: start with a ping to the server. If it succeeds, Layers 1–3 work, so look higher. If it fails, look lower.

Why divide and conquer is so popular

A ping sends a small test message and waits for a reply. If a ping from the PC to the web server's IP address works, then the cable, the switch, the IP addresses and the routing are all fine in both directions. One test has cleared three layers. You only need to look at what sits above them: the service itself, the firewall rules for that port, or DNS.

If the ping fails, the problem is most likely at Layer 3 or below, so you work downwards from there. (Remember that some servers and firewalls block ping, so check that ping normally works to that target.) Either way, one quick test has cut the search in half.

💡 Another simple technique is to follow the path: test hop by hop along the route the traffic takes (PC, switch, router, server) and stop where it fails. Traceroute does this for you automatically.

Learn more: Traceroute: Finding the Path

How to choose

  • “Nothing works”, port lights are off, or the cabling is new: bottom-up.
  • “Only this one app fails; everything else is fine”: top-down. The lower layers are clearly working.
  • No clue yet: divide and conquer with a ping.

How to verify: one ping, two answers

PC192.168.10.25SW1R1192.168.10.1Web server203.0.113.80
  1. 1. Ping succeeds: Layers 1–3 work end to end. Check the web service, the firewall rules for port 443 and DNS next.
  2. 2. Ping fails: work downwards. Can the PC ping its gateway, R1? If not, the problem is local: the IP address, the VLAN or the cable.

Check yourself

Predict · scenario 1

A user can open every website except the company HR portal. Which approach fits best?

Predict · scenario 2

You ping the server's IP address and get replies. Which layers have you just shown to be working?