Routelearn.net
Course menu

Unit 9: ICMP and Network TestingLesson 9.2 (2 of 3 in this unit)59 of 84 in the Network Fundamentals course

Ping: Testing Reachability

Ping is the first tool most network engineers reach for. Learn what happens when you ping (including the ARP step on the first ping), how to read the round-trip time, TTL and packet loss in Windows and Linux output, and the order to ping in to find where a problem is.

Beginner · 15 min read · Before this: ICMP, ARP fundamentals

Ping is a diagnostic tool that sends ICMP (Internet Control Message Protocol) Echo Request messages to a destination and waits for Echo Reply messages. For each request, it reports whether a reply arrived, the round-trip time and the TTL of the reply.

In simple terms: Ping asks another device “are you there?” and times how long the answer takes. No answer means that the device did not reply, or that something on the way blocked or lost the message.

A real-life situation

A new laptop can't reach anything. Before you open a single menu, you run a few quick pings. Within seconds you know that the laptop's own network software is fine and that it can reach the office router, but nothing beyond it. That is the power of ping: a tiny test that shows you how far traffic gets.

What ping is

Ping sends an ICMP echo request to an address and waits for an echo reply. ICMP (Internet Control Message Protocol) is a helper protocol that carries test and error messages for IP. If a reply comes back, the path works in both directions.

Step 1 of 4 · Echo request
Office LAN and WAN
Laptop
192.168.10.25
Gateway R1
192.168.10.1
Server
203.0.113.80

Ping tests the whole path in both directions. A reply proves that your request reached the target and that the target had a working route back to you.

Learn more: ICMP

How ping works, step by step

You type ping 192.168.10.1 on a laptop at 192.168.10.25 that has just been switched on, so its ARP cache is empty. Here's what happens:

  1. Local or remote? The laptop compares the target with its own IP address and subnet mask. 192.168.10.1 is in the same subnet, so the laptop can send to it directly. (For a remote target, it would send the packet to its default gateway instead.)
  2. ARP, if needed. To build an Ethernet frame, the laptop needs the target's MAC address. The cache is empty, so it broadcasts an ARP request: “Who has 192.168.10.1?” The router answers with its MAC address.
  3. Echo request. The laptop sends an ICMP echo request (type 8) with sequence number 1 and notes the exact time it was sent.
  4. Echo reply. The router answers with an echo reply (type 0) that carries the same identifier, sequence number and data.
  5. Measure. The laptop subtracts the send time from the receive time. The result is the round-trip time. It prints the result, waits about a second and sends sequence number 2.
  6. Summarise. After the last request (the fourth on Windows, or when you press Ctrl+C on Linux), it prints how many requests were sent, received and lost, plus the minimum, average and maximum times.
Step 1 of 4 · ARP request
Laptop
192.168.10.25
Same subnet
192.168.10.0/24
Gateway R1
192.168.10.1
The first ping to a neighbour: an ARP exchange, then the ICMP echo request and reply. Later pings skip the ARP step while the entry stays in the cache.

Why the first reply can be slow, or time out

The ARP step only happens when the MAC address isn't already cached. What the sender does while it waits depends on the device:

  • PCs (Windows, Linux, macOS) usually hold the packet and send it once ARP finishes. The first reply is a little slower than the rest.
  • Cisco routers drop the packet that triggered ARP. The first ping times out and you see .!!!!.
  • The same thing can happen further away. When you ping a remote host, the last router on the path may need to use ARP to find the target's MAC address. If that router drops the first packet, the first ping to a remote host times out too.

Run the ping a second time. If all the replies come back now, the first loss was just ARP, not a fault.

Reading the result

ResultWindowsCisco IOSWhat it means
ReplyReply from … time=2ms!The path works both ways.
TimeoutRequest timed out..No answer at all. The request or the reply was lost, or a firewall dropped it.
UnreachableDestination host unreachable.UA device answered to say it can't deliver the packet. Check who sent the message.

Look closely at an unreachable message on Windows. If it says Reply from 192.168.10.25 (your own address), your PC could not even find the next device with ARP, so the problem is local. If it comes from a router's address, that router could not deliver the packet, most often because it has no route to the destination network. Depending on the router, Windows shows this as Destination net unreachable or Destination host unreachable.

Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
C:\> ping 192.168.10.1
Pinging 192.168.10.1 with 32 bytes of data:
Reply from 192.168.10.1: bytes=32 time=1ms TTL=255
Reply from 192.168.10.1: bytes=32 time=1ms TTL=255
Reply from 192.168.10.1: bytes=32 time=2ms TTL=255
Reply from 192.168.10.1: bytes=32 time=1ms TTL=255

Ping statistics for 192.168.10.1:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 1ms, Maximum = 2ms, Average = 1ms
What to look for: four Reply from 192.168.10.1 lines and Lost = 0 (0% loss) mean the gateway answered every request. Windows sends 4 pings and stops. time is the round-trip time in milliseconds, and TTL is the hop counter left in the reply.
Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
$ ping -c 4 203.0.113.80
PING 203.0.113.80 (203.0.113.80) 56(84) bytes of data.

--- 203.0.113.80 ping statistics ---
4 packets transmitted, 0 received, 100% packet loss, time 3062ms
Linux and macOS keep pinging until you press Ctrl+C, so use -c 4 to send four requests. Here, 0 received, 100% packet loss means every request went unanswered, and there are no reply lines at all.

The Cisco version below is based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#ping 192.168.20.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.20.10, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 1/1/2 ms
Each ! is a reply and each . is a timeout. The first dot is normal on a router: the first packet is dropped while the router learns the target's MAC address with ARP. The success rate of 80 percent (4/5) comes from that one dot.

Round-trip time (latency)

Latency is the time data takes to travel across the network. Ping measures the round-trip time (RTT): the time out and back, in milliseconds (ms). It includes the time on every link, the time each router takes to forward the packet, and the time the target takes to answer.

PathTypical round-trip time
Wired, same LANUnder 1 ms (Windows shows time<1ms)
Wi-Fi to the home router1–10 ms, more on a busy network
A server in the same countryAbout 10–40 ms
Across an oceanAbout 70–150 ms or more
Satellite in high orbitAbout 600 ms

Distance matters because signals in fibre travel at roughly 200,000 km per second. That adds about 1 ms of round-trip time for every 100 km of cable. Look at three things in the summary:

  • Average: the normal latency of this path.
  • Maximum: big spikes point to congestion or a busy Wi-Fi channel.
  • The spread between the minimum and maximum. Delay that varies a lot (called jitter) hurts voice and video calls, even when the average looks fine.

TTL in the reply: what it hints at

Each reply line shows a TTL value. This is the time to live (TTL) left in the reply packet when it reached you. The target set a starting value, and every router on the way back lowered it by 1. Systems start from well-known values:

Starting TTLUsuallySeen asHops away
64Linux, macOS, Android, iOS, many serversTTL=5464 − 54 = 10 routers
128WindowsTTL=1271 router (for example, a PC in another VLAN)
255Routers and network equipmentTTL=2550: directly connected

Treat this as a hint, not proof. Administrators can change the starting TTL, and the return path can be different from the outward path. However, a sudden TTL change on a path that was stable usually means the route has changed.

Packet loss

Packet loss is the percentage of requests that got no reply. Windows shows it as Lost = 1 (25% loss), and Linux as 25% packet loss.

  • 0%: healthy.
  • 100%: nothing gets through (or ICMP is filtered). Find where it stops with the ping order below, or with traceroute.
  • Small, regular loss (for example, 2–10%): the hardest kind to track down. Common causes are a damaged cable, a duplex mismatch, a weak Wi-Fi signal or a congested link.

Four pings are too few to measure light loss. Send 100 instead: ping -n 100 on Windows or ping -c 100 on Linux.

Example output from a Linux computer, written for this lesson
$ ping -c 4 routelearn.net
PING routelearn.net (203.0.113.10) 56(84) bytes of data.
64 bytes from 203.0.113.10: icmp_seq=1 ttl=54 time=23.8 ms
64 bytes from 203.0.113.10: icmp_seq=2 ttl=54 time=22.9 ms
64 bytes from 203.0.113.10: icmp_seq=4 ttl=54 time=41.6 ms

--- routelearn.net ping statistics ---
4 packets transmitted, 3 received, 25% packet loss, time 3005ms
rtt min/avg/max/mdev = 22.871/29.433/41.627/8.611 ms
Reading it line by line: the name was resolved to 203.0.113.10 first, so DNS works. icmp_seq=3 is missing: that request was lost, which gives 25% loss. ttl=54 hints at a Linux-style server about 10 hops away. Sequence 4 took 41.6 ms, compared with about 23 ms for the others, and mdev (the spread) is high. Both are signs of a congested or unstable path.
Example output from a Windows PC, written for this lesson
C:\> ping 192.168.10.1
Pinging 192.168.10.1 with 32 bytes of data:
Request timed out.
Reply from 192.168.10.1: bytes=32 time=1ms TTL=255
Reply from 192.168.10.1: bytes=32 time=1ms TTL=255
Reply from 192.168.10.1: bytes=32 time<1ms TTL=255

Ping statistics for 192.168.10.1:
    Packets: Sent = 4, Received = 3, Lost = 1 (25% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 1ms, Average = 0ms
What to look for: one Request timed out. followed by steady replies, the first time you ping a device, is most likely the ARP step, not a fault. Ping again to be sure. (Windows sends 32 bytes of data by default; Linux sends 56.)

Useful options

GoalWindowsLinux / macOS
Send a set number of pingsping -n 100 hostping -c 100 host
Ping until stoppedping -t host (press Ctrl+C to stop)The default (press Ctrl+C to stop)
Bigger packetsping -l 1400 hostping -s 1400 host
Force IPv4 / IPv6ping -4 / ping -6ping -4 / ping -6
Show the name of an IP addressping -a 203.0.113.10Shown by default when a reverse DNS name exists

Why the order matters

Ping in steps, from near to far. The first step that fails shows you where to look.

Your PC192.168.10.25Gateway192.168.10.1InternetRemote host203.0.113.80
  1. 1. 1. Loopback: ping 127.0.0.1 tests your own TCP/IP software. The traffic never leaves the PC.
  2. 2. 2. Your own address: confirms that the address you expect is configured on the PC. This traffic doesn't leave the PC either.
  3. 3. 3. Default gateway: tests the cable, the switch, the VLAN and your IP address and subnet mask on the local network.
  4. 4. 4. A remote IP: tests routing beyond your network, in both directions.
  5. 5. 5. A remote name: ping routelearn.net adds a DNS lookup. If step 4 works but this fails, suspect DNS.
ping 127.0.0.1

Step 1: loopback test (Windows, Linux and macOS).

ping -t 192.168.10.1

Windows: keep pinging until you press Ctrl+C. Useful while you move a cable or restart a device.

💡 A timeout does not always mean the path is broken. Many firewalls and servers block ICMP on purpose. If a web page loads but ping fails, ICMP is most likely being filtered.

StepCommand (example)If this is the first step that fails, suspect
1. Loopbackping 127.0.0.1The computer's own TCP/IP software (very rare)
2. Own IP addressping 192.168.10.25The network adapter or its IP settings
3. Default gatewayping 192.168.10.1Cable, Wi-Fi, switch port, VLAN, or a wrong IP address or mask
4. Remote IP addressping 203.0.113.80Routing, NAT or a firewall beyond your network (or ICMP filtering at the target)
5. Remote nameping routelearn.netDNS (see DNS problems)

Common mistakes

  • Treating a timeout as proof that a device is down. Many servers ignore echo requests, and Windows Firewall blocks incoming pings by default. Test the real service as well.
  • Worrying about one lost first ping. It is usually caused by ARP. Ping again before you look for a fault.
  • Judging packet loss from four pings. Four samples are too few. Use 100 or more to see light, intermittent loss.
  • Ignoring who sent an unreachable message. “Reply from 192.168.10.25: Destination host unreachable” comes from your own PC, not from the target or a router.
  • Pinging a name first. If it fails, you don't know whether DNS or the network is broken. Ping the IP address first.
✅ Key takeaways
  • Ping sends ICMP echo requests (type 8) and waits for echo replies (type 0). A reply proves the path works both ways.
  • The first ping may need ARP, so it can be slower or, on routers, time out.
  • time is the round-trip time. Watch the average and the spread.
  • The TTL in the reply hints at how many hops away the target is (common start values: 64, 128, 255).
  • Ping from near to far: loopback, own IP address, gateway, remote IP address, then a name.
  • A timeout can mean ICMP is filtered, not that the path has failed.

Check yourself

Predict · scenario 1

A ping to the gateway works. A ping to 203.0.113.80 fails with 'Reply from 192.168.10.1: Destination host unreachable.' Where is the problem?

Predict · scenario 2

On a Cisco router you see '.!!!!'. What does the first dot most likely mean?

Predict · scenario 3

ping 203.0.113.80 works, but ping www.example.com fails. What do you check next?

Predict · scenario 4

Every reply from a web server shows TTL=56. What is the best guess?

Related lessons

Ping is built on ICMP and, for the first packet, on ARP. When ping tells you that a path is broken but not where, move on to traceroute. To use ping as part of a complete process, follow a structured method.

Learn more: A Troubleshooting Method

FAQ

Why does the first ping sometimes time out?
Before the first packet can be sent, the sender (or the last router on the path) may need to learn the next device's MAC address with ARP. Cisco routers drop the packet that triggered ARP, so the first ping shows a dot. PCs usually hold the packet and send it once ARP finishes, so you see a slower first reply instead.
What is a good ping time?
It depends on distance. Expect under 1 ms on a wired LAN, a few milliseconds on Wi-Fi, roughly 10 to 40 ms to servers in the same country, and 70 to 150 ms or more across an ocean. What matters most is whether the time is normal for that path, and whether it stays stable.
What does TTL mean in a ping reply?
It is the TTL (time to live) value left in the reply packet when it reached you. Each router on the way back lowered it by 1. Because systems start from well-known values (often 64, 128 or 255), it gives a rough hint of how many hops away the target is and what kind of system it might be.
Can I ping a port?
No. Ping uses ICMP, which has no port numbers. To test whether a TCP port such as 443 is open, use a port-testing tool, such as the RouteLearn Port Checker or Test-NetConnection on Windows.