A real-life situation
A new laptop can't reach anything. Before you open a single menu, you run a few quick pings. Within seconds you know that the laptop's own network software is fine and that it can reach the office router, but nothing beyond it. That is the power of ping: a tiny test that shows you how far traffic gets.
What ping is
Ping sends an ICMP echo request to an address and waits for an echo reply. ICMP (Internet Control Message Protocol) is a helper protocol that carries test and error messages for IP. If a reply comes back, the path works in both directions.
Ping tests the whole path in both directions. A reply proves that your request reached the target and that the target had a working route back to you.
Learn more: ICMP
How ping works, step by step
You type ping 192.168.10.1 on a laptop at 192.168.10.25 that has just been switched on, so its ARP cache is empty. Here's what happens:
- Local or remote? The laptop compares the target with its own IP address and subnet mask.
192.168.10.1is in the same subnet, so the laptop can send to it directly. (For a remote target, it would send the packet to its default gateway instead.) - ARP, if needed. To build an Ethernet frame, the laptop needs the target's MAC address. The cache is empty, so it broadcasts an ARP request: “Who has 192.168.10.1?” The router answers with its MAC address.
- Echo request. The laptop sends an ICMP echo request (type 8) with sequence number 1 and notes the exact time it was sent.
- Echo reply. The router answers with an echo reply (type 0) that carries the same identifier, sequence number and data.
- Measure. The laptop subtracts the send time from the receive time. The result is the round-trip time. It prints the result, waits about a second and sends sequence number 2.
- Summarise. After the last request (the fourth on Windows, or when you press Ctrl+C on Linux), it prints how many requests were sent, received and lost, plus the minimum, average and maximum times.
Why the first reply can be slow, or time out
The ARP step only happens when the MAC address isn't already cached. What the sender does while it waits depends on the device:
- PCs (Windows, Linux, macOS) usually hold the packet and send it once ARP finishes. The first reply is a little slower than the rest.
- Cisco routers drop the packet that triggered ARP. The first ping times out and you see
.!!!!. - The same thing can happen further away. When you ping a remote host, the last router on the path may need to use ARP to find the target's MAC address. If that router drops the first packet, the first ping to a remote host times out too.
Run the ping a second time. If all the replies come back now, the first loss was just ARP, not a fault.
Reading the result
| Result | Windows | Cisco IOS | What it means |
|---|---|---|---|
| Reply | Reply from … time=2ms | ! | The path works both ways. |
| Timeout | Request timed out. | . | No answer at all. The request or the reply was lost, or a firewall dropped it. |
| Unreachable | Destination host unreachable. | U | A device answered to say it can't deliver the packet. Check who sent the message. |
Look closely at an unreachable message on Windows. If it says Reply from 192.168.10.25 (your own address), your PC could not even find the next device with ARP, so the problem is local. If it comes from a router's address, that router could not deliver the packet, most often because it has no route to the destination network. Depending on the router, Windows shows this as Destination net unreachable or Destination host unreachable.
C:\> ping 192.168.10.1 Pinging 192.168.10.1 with 32 bytes of data: Reply from 192.168.10.1: bytes=32 time=1ms TTL=255 Reply from 192.168.10.1: bytes=32 time=1ms TTL=255 Reply from 192.168.10.1: bytes=32 time=2ms TTL=255 Reply from 192.168.10.1: bytes=32 time=1ms TTL=255 Ping statistics for 192.168.10.1: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 1ms, Maximum = 2ms, Average = 1ms
time is the round-trip time in milliseconds, and TTL is the hop counter left in the reply.$ ping -c 4 203.0.113.80 PING 203.0.113.80 (203.0.113.80) 56(84) bytes of data. --- 203.0.113.80 ping statistics --- 4 packets transmitted, 0 received, 100% packet loss, time 3062ms
-c 4 to send four requests. Here, 0 received, 100% packet loss means every request went unanswered, and there are no reply lines at all.The Cisco version below is based on Cisco documentation, not run on a lab device.
R1#ping 192.168.20.10 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 192.168.20.10, timeout is 2 seconds: .!!!! Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms
! is a reply and each . is a timeout. The first dot is normal on a router: the first packet is dropped while the router learns the target's MAC address with ARP. The success rate of 80 percent (4/5) comes from that one dot.Round-trip time (latency)
Latency is the time data takes to travel across the network. Ping measures the round-trip time (RTT): the time out and back, in milliseconds (ms). It includes the time on every link, the time each router takes to forward the packet, and the time the target takes to answer.
| Path | Typical round-trip time |
|---|---|
| Wired, same LAN | Under 1 ms (Windows shows time<1ms) |
| Wi-Fi to the home router | 1–10 ms, more on a busy network |
| A server in the same country | About 10–40 ms |
| Across an ocean | About 70–150 ms or more |
| Satellite in high orbit | About 600 ms |
Distance matters because signals in fibre travel at roughly 200,000 km per second. That adds about 1 ms of round-trip time for every 100 km of cable. Look at three things in the summary:
- Average: the normal latency of this path.
- Maximum: big spikes point to congestion or a busy Wi-Fi channel.
- The spread between the minimum and maximum. Delay that varies a lot (called jitter) hurts voice and video calls, even when the average looks fine.
TTL in the reply: what it hints at
Each reply line shows a TTL value. This is the time to live (TTL) left in the reply packet when it reached you. The target set a starting value, and every router on the way back lowered it by 1. Systems start from well-known values:
| Starting TTL | Usually | Seen as | Hops away |
|---|---|---|---|
| 64 | Linux, macOS, Android, iOS, many servers | TTL=54 | 64 − 54 = 10 routers |
| 128 | Windows | TTL=127 | 1 router (for example, a PC in another VLAN) |
| 255 | Routers and network equipment | TTL=255 | 0: directly connected |
Treat this as a hint, not proof. Administrators can change the starting TTL, and the return path can be different from the outward path. However, a sudden TTL change on a path that was stable usually means the route has changed.
Packet loss
Packet loss is the percentage of requests that got no reply. Windows shows it as Lost = 1 (25% loss), and Linux as 25% packet loss.
- 0%: healthy.
- 100%: nothing gets through (or ICMP is filtered). Find where it stops with the ping order below, or with traceroute.
- Small, regular loss (for example, 2–10%): the hardest kind to track down. Common causes are a damaged cable, a duplex mismatch, a weak Wi-Fi signal or a congested link.
Four pings are too few to measure light loss. Send 100 instead: ping -n 100 on Windows or ping -c 100 on Linux.
$ ping -c 4 routelearn.net PING routelearn.net (203.0.113.10) 56(84) bytes of data. 64 bytes from 203.0.113.10: icmp_seq=1 ttl=54 time=23.8 ms 64 bytes from 203.0.113.10: icmp_seq=2 ttl=54 time=22.9 ms 64 bytes from 203.0.113.10: icmp_seq=4 ttl=54 time=41.6 ms --- routelearn.net ping statistics --- 4 packets transmitted, 3 received, 25% packet loss, time 3005ms rtt min/avg/max/mdev = 22.871/29.433/41.627/8.611 ms
203.0.113.10 first, so DNS works. icmp_seq=3 is missing: that request was lost, which gives 25% loss. ttl=54 hints at a Linux-style server about 10 hops away. Sequence 4 took 41.6 ms, compared with about 23 ms for the others, and mdev (the spread) is high. Both are signs of a congested or unstable path.C:\> ping 192.168.10.1 Pinging 192.168.10.1 with 32 bytes of data: Request timed out. Reply from 192.168.10.1: bytes=32 time=1ms TTL=255 Reply from 192.168.10.1: bytes=32 time=1ms TTL=255 Reply from 192.168.10.1: bytes=32 time<1ms TTL=255 Ping statistics for 192.168.10.1: Packets: Sent = 4, Received = 3, Lost = 1 (25% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 1ms, Average = 0ms
Useful options
| Goal | Windows | Linux / macOS |
|---|---|---|
| Send a set number of pings | ping -n 100 host | ping -c 100 host |
| Ping until stopped | ping -t host (press Ctrl+C to stop) | The default (press Ctrl+C to stop) |
| Bigger packets | ping -l 1400 host | ping -s 1400 host |
| Force IPv4 / IPv6 | ping -4 / ping -6 | ping -4 / ping -6 |
| Show the name of an IP address | ping -a 203.0.113.10 | Shown by default when a reverse DNS name exists |
Why the order matters
Ping in steps, from near to far. The first step that fails shows you where to look.
- 1. 1. Loopback: ping 127.0.0.1 tests your own TCP/IP software. The traffic never leaves the PC.
- 2. 2. Your own address: confirms that the address you expect is configured on the PC. This traffic doesn't leave the PC either.
- 3. 3. Default gateway: tests the cable, the switch, the VLAN and your IP address and subnet mask on the local network.
- 4. 4. A remote IP: tests routing beyond your network, in both directions.
- 5. 5. A remote name: ping routelearn.net adds a DNS lookup. If step 4 works but this fails, suspect DNS.
ping 127.0.0.1Step 1: loopback test (Windows, Linux and macOS).
ping -t 192.168.10.1Windows: keep pinging until you press Ctrl+C. Useful while you move a cable or restart a device.
💡 A timeout does not always mean the path is broken. Many firewalls and servers block ICMP on purpose. If a web page loads but ping fails, ICMP is most likely being filtered.
| Step | Command (example) | If this is the first step that fails, suspect |
|---|---|---|
| 1. Loopback | ping 127.0.0.1 | The computer's own TCP/IP software (very rare) |
| 2. Own IP address | ping 192.168.10.25 | The network adapter or its IP settings |
| 3. Default gateway | ping 192.168.10.1 | Cable, Wi-Fi, switch port, VLAN, or a wrong IP address or mask |
| 4. Remote IP address | ping 203.0.113.80 | Routing, NAT or a firewall beyond your network (or ICMP filtering at the target) |
| 5. Remote name | ping routelearn.net | DNS (see DNS problems) |
Common mistakes
- Treating a timeout as proof that a device is down. Many servers ignore echo requests, and Windows Firewall blocks incoming pings by default. Test the real service as well.
- Worrying about one lost first ping. It is usually caused by ARP. Ping again before you look for a fault.
- Judging packet loss from four pings. Four samples are too few. Use 100 or more to see light, intermittent loss.
- Ignoring who sent an unreachable message. “Reply from 192.168.10.25: Destination host unreachable” comes from your own PC, not from the target or a router.
- Pinging a name first. If it fails, you don't know whether DNS or the network is broken. Ping the IP address first.
- Ping sends ICMP echo requests (type 8) and waits for echo replies (type 0). A reply proves the path works both ways.
- The first ping may need ARP, so it can be slower or, on routers, time out.
timeis the round-trip time. Watch the average and the spread.- The TTL in the reply hints at how many hops away the target is (common start values: 64, 128, 255).
- Ping from near to far: loopback, own IP address, gateway, remote IP address, then a name.
- A timeout can mean ICMP is filtered, not that the path has failed.
Check yourself
A ping to the gateway works. A ping to 203.0.113.80 fails with 'Reply from 192.168.10.1: Destination host unreachable.' Where is the problem?
On a Cisco router you see '.!!!!'. What does the first dot most likely mean?
ping 203.0.113.80 works, but ping www.example.com fails. What do you check next?
Every reply from a web server shows TTL=56. What is the best guess?
Related lessons
Ping is built on ICMP and, for the first packet, on ARP. When ping tells you that a path is broken but not where, move on to traceroute. To use ping as part of a complete process, follow a structured method.
Learn more: A Troubleshooting Method