When a Windows PC has a network problem, you don't need special software to investigate. A handful of built-in commands show what the PC believes about the network and test whether packets can get where they need to go. This lesson goes through each one, the way you would use it when following a troubleshooting method.
Before you start: opening a command prompt
A command prompt is a text window where you type commands and read the results. Windows has two: the classic Command Prompt (cmd) and the newer PowerShell. Every command here works in both.
- Press Windows + R, type
cmdand press Enter. Or search for "Command Prompt" or "Terminal" in the Start menu. - For commands that change settings (for example
arp -dornetstat -b), right-click and choose Run as administrator. - Type
command /?(for exampleipconfig /?) to see every option for a command.
💡 Copy text out of the window: select the output with the mouse and press Enter (Command Prompt) or Ctrl+C. Pasting the real output into a ticket is much better than describing it.
The commands at a glance
| Command | Question it answers | Troubleshooting step |
|---|---|---|
ipconfig | What are my IP address, mask and gateway? | IP settings |
ipconfig /all | Plus MAC address, DHCP server, lease and DNS servers | IP settings, services |
ipconfig /release, /renew | Give back my DHCP address and ask for a new one | Services (DHCP) |
ipconfig /flushdns | Forget all cached DNS answers | Services (DNS) |
ping | Can I reach this address, and how fast? | Reachability |
tracert | Which routers does my traffic pass, and where does it stop? | Reachability |
arp -a | Which MAC address belongs to each local IP? | Ethernet / IP |
nslookup | What IP address does this name turn into, and who told me? | Services (DNS) |
netstat -ano | What connections and listening ports does this PC have? | Application |
route print | Where does this PC send traffic for each network? | IP settings |
All the examples use one office PC: address 192.168.10.25/24, default gateway 192.168.10.1, and a server at 192.168.10.5 that does both DHCP and DNS. The remote web server is web.example.com at 203.0.113.10.
- 1. ipconfig /all, /renew: show and refresh the settings the PC got from the DHCP server.
- 2. arp -a and route print: the gateway's MAC address, and the rule that sends off-network traffic to it.
- 3. nslookup: asks the DNS server to turn web.example.com into 203.0.113.10.
- 4. ping and tracert: test the path to the server and list each router on the way.
- 5. netstat -ano: lists this PC's open connections, like the browser's HTTPS session.
ipconfig: what are my settings?
ipconfig (IP configuration) shows the network settings of every network adapter (each network card or Wi-Fi card) in the PC. It is almost always the first command to run, because a PC with wrong settings can't work no matter how healthy the network is.
Syntaxipconfig [/all | /release | /renew | /flushdns | /displaydns]
C:\> ipconfig Windows IP Configuration Ethernet adapter Ethernet: Connection-specific DNS Suffix . : office.example Link-local IPv6 Address . . . . . : fe80::1c2a:5b3f:9e4d:7a10%7 IPv4 Address. . . . . . . . . . . : 192.168.10.25 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.10.1 Wireless LAN adapter Wi-Fi: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . :
fe80:: line is an automatic IPv6 address every adapter has; you can ignore it for now. "Media disconnected" on the Wi-Fi adapter just means Wi-Fi isn't in use.ipconfig /all: the full picture
C:\> ipconfig /all Windows IP Configuration Host Name . . . . . . . . . . . . : PC-SALES-07 Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : office.example Ethernet adapter Ethernet: Connection-specific DNS Suffix . : office.example Description . . . . . . . . . . . : Intel(R) Ethernet Connection I219-LM Physical Address. . . . . . . . . : 02-00-00-00-00-25 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::1c2a:5b3f:9e4d:7a10%7(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.10.25(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : Monday, 5 October 2026 08:02:14 Lease Expires . . . . . . . . . . : Tuesday, 6 October 2026 08:02:14 Default Gateway . . . . . . . . . : 192.168.10.1 DHCP Server . . . . . . . . . . . : 192.168.10.5 DNS Servers . . . . . . . . . . . : 192.168.10.5 NetBIOS over Tcpip. . . . . . . . : Enabled
| Line | What it tells you | Warning signs |
|---|---|---|
| Physical Address | The adapter's MAC address (Windows writes it with dashes) | Needed when a switch or DHCP reservation is tied to a MAC |
| DHCP Enabled | Yes = settings came from DHCP. No = typed in by hand (static) | "No" on a normal user PC often means someone set it manually |
| IPv4 Address | The PC's address. "(Preferred)" means it is in use | 169.254.x.x = DHCP failed. "(Duplicate)" = address conflict |
| Lease Obtained / Expires | When DHCP lent the address and when the loan ends | Very old "Obtained" with fresh problems: try a renew |
| Default Gateway | The router for every other network (default gateway) | Blank, or not in the PC's own subnet |
| DHCP Server | Which server gave the address | An unknown address here may be a rogue DHCP server (for example a home router plugged into the office) |
| DNS Servers | Where the PC sends name lookups | A typo, or a server that no longer exists |
C:\> ipconfig /all Ethernet adapter Ethernet: Physical Address. . . . . . . . . : 02-00-00-00-00-25 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Autoconfiguration IPv4 Address. . : 169.254.37.12(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.0.0 Default Gateway . . . . . . . . . : DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1 fec0:0:0:ffff::2%1 fec0:0:0:ffff::3%1
169.254 is an APIPA address (Automatic Private IP Addressing): Windows invented it because no DHCP server answered. There is no gateway, and the fec0:: DNS entries are placeholders. The real question is why DHCP didn't answer: cable, switch port, VLAN or the DHCP server itself.ipconfig /release and /renew: get a fresh DHCP address
/release tells the DHCP server "I'm giving this address back" and removes it from the adapter. /renew runs the DHCP exchange again to get a new lease. Use them after fixing a cable or VLAN problem, or when a PC still holds settings from the wrong network.
- IPv4:
- 192.168.10.25
- Gateway:
- 192.168.10.1
- DNS:
- 192.168.10.5
C:\> ipconfig /renew Windows IP Configuration An error occurred while renewing interface Ethernet : unable to contact your DHCP server. Request has timed out.
ipconfig.⚠️ Careful when working remotely. ipconfig /release cuts the PC off the network until the renew finishes. If you are connected to that PC by remote desktop, you will lose the session. Run ipconfig /release && ipconfig /renew as one line so the renew still happens.
ipconfig /flushdns: forget cached names
Windows remembers recent DNS answers in a DNS cache so it doesn't ask again every time. If a website moved to a new IP address, the PC may keep using the old one until the cached answer expires. /flushdns empties the cache; /displaydns shows what is in it.
C:\> ipconfig /flushdns Windows IP Configuration Successfully flushed the DNS Resolver Cache.
ping: can I reach it?
ping sends small ICMP echo request messages to an address and waits for echo reply messages. Windows sends four by default. It tells you whether the target answers, how long the round trip takes, and whether any messages were lost. The full story is in Ping.
Syntaxping [-n count] [-t] [-l size] [-4] target
| Option | Meaning |
|---|---|
-n 10 | Send 10 echo requests instead of 4 |
-t | Keep pinging until you press Ctrl+C. Good for watching a link while you move a cable |
-l 1400 | Send 1400 bytes of data instead of 32 |
-4 | Force IPv4 when a name has both IPv4 and IPv6 addresses |
C:\> ping 192.168.10.1 Pinging 192.168.10.1 with 32 bytes of data: Reply from 192.168.10.1: bytes=32 time=1ms TTL=255 Reply from 192.168.10.1: bytes=32 time<1ms TTL=255 Reply from 192.168.10.1: bytes=32 time<1ms TTL=255 Reply from 192.168.10.1: bytes=32 time<1ms TTL=255 Ping statistics for 192.168.10.1: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 1ms, Average = 0ms
time is the round trip; on a LAN it is usually under 1 ms, across the internet 10 to 100 ms. TTL is the time-to-live left in the reply: it hints at the type of device and how many routers the reply crossed, but it is not a speed.| You see | It means | Next step |
|---|---|---|
Reply from <target> | The target is reachable | Move up: DNS, then the application |
Request timed out. | No answer came back in time | Target down, ping blocked by a firewall, or the path broken. Try tracert |
Destination host unreachable from your own IP | Your PC couldn't find the target (or gateway) on the LAN with ARP | Check the local network, mask and gateway |
Destination host unreachable from a router's IP | That router has no route to the target | The problem is at or after that router |
Ping request could not find host | The name didn't resolve | DNS problem: use nslookup |
General failure. | The PC couldn't send at all | Adapter disabled, no address, or local firewall/VPN software |
C:\> ping web.example.com Pinging web.example.com [203.0.113.10] with 32 bytes of data: Request timed out. Request timed out. Request timed out. Request timed out. Ping statistics for 203.0.113.10: Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
203.0.113.10, so DNS works. But no replies came back. Before blaming the network, open the website: many servers simply block ping.tracert: which way does it go?
tracert (trace route) lists every router between your PC and the target. It sends probes with a TTL (time-to-live, a hop counter in the IP header) of 1, then 2, then 3, and so on. Each router lowers the TTL by one; the router where it reaches zero throws the probe away and sends back an ICMP "time exceeded" message, which reveals its address. On Windows the probes are ICMP echo requests. See Traceroute for the details.
Syntaxtracert [-d] [-h max_hops] target
- 1. TTL 1: the gateway lowers TTL to 0, drops the probe and replies "time exceeded". Hop 1 found.
- 2. TTL 2: the probe dies at the ISP router, which reports back. Hop 2 found.
- 3. TTL 3: one hop further each time.
- 4. Target reached: the server sends an echo reply instead, and tracert stops.
C:\> tracert -d web.example.com Tracing route to web.example.com [203.0.113.10] over a maximum of 30 hops: 1 <1 ms <1 ms <1 ms 192.168.10.1 2 8 ms 7 ms 8 ms 198.51.100.1 3 12 ms 11 ms 12 ms 198.51.100.45 4 * * * Request timed out. 5 19 ms 18 ms 19 ms 203.0.113.1 6 20 ms 19 ms 20 ms 203.0.113.10 Trace complete.
-d skips looking up router names, which makes it much faster. Hop 4 shows stars, but hops 5 and 6 answer, so hop 4 just doesn't reply to tracert; traffic passes through it fine. If the stars had continued to hop 30, the path would stop after the last router that answered.arp -a: who has which MAC address?
To send a frame on the local network, the PC needs the MAC address of the next device. ARP (Address Resolution Protocol) finds it and stores it in the ARP cache. arp -a shows that cache.
Syntaxarp -a [-N interface_ip] arp -d * (admin: clear the cache)
C:\> arp -a Interface: 192.168.10.25 --- 0x7 Internet Address Physical Address Type 192.168.10.1 02-00-00-00-00-01 dynamic 192.168.10.5 02-00-00-00-00-05 dynamic 192.168.10.255 ff-ff-ff-ff-ff-ff static 224.0.0.22 01-00-5e-00-00-16 static 224.0.0.251 01-00-5e-00-00-fb static 239.255.255.250 01-00-5e-7f-ff-fa static 255.255.255.255 ff-ff-ff-ff-ff-ff static
dynamic entries were learned with ARP; here the gateway (.1) and the server (.5). The static entries are built in: the broadcast addresses map to ff-ff-ff-ff-ff-ff and the 224.x/239.x lines are multicast. Note there is no entry for 203.0.113.10: remote hosts never appear here, because the PC only ever needs the gateway's MAC to reach them (see ARP for local and remote destinations).💡 Spot a problem: if the gateway is missing from arp -a right after you pinged it, the PC never got an ARP reply. The gateway is unreachable at Layer 2. If two different IPs show the same MAC unexpectedly, look for an address conflict or ARP spoofing.
nslookup: what does DNS say?
nslookup (name server lookup) asks a DNS server to resolve a name and shows the answer, plus which server answered. That second part is what makes it so useful: it shows you exactly where the PC is sending its DNS questions. The online Nslookup tool on RouteLearn.net does the same from the internet.
Syntaxnslookup [-type=A|AAAA|MX|TXT|NS] name [dns_server]
C:\> nslookup web.example.com Server: dns1.office.example Address: 192.168.10.5 Non-authoritative answer: Name: web.example.com Address: 203.0.113.10
C:\> nslookup web.example.com 192.0.2.53 Server: UnKnown Address: 192.0.2.53 Non-authoritative answer: Name: web.example.com Address: 203.0.113.10
C:\> nslookup webb.example.com Server: dns1.office.example Address: 192.168.10.5 *** dns1.office.example can't find webb.example.com: Non-existent domain
DNS request timed out, which means the DNS server didn't answer at all.netstat -ano: what is connected?
netstat (network statistics) lists the PC's ports and connections. With -a it shows all connections and listening ports, -n shows numbers instead of names (faster), and -o adds the PID (process ID: the number Windows gives each running program). More on this in Viewing connections on your computer.
Syntaxnetstat -ano [| findstr :443]
C:\> netstat -ano Active Connections Proto Local Address Foreign Address State PID TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1012 TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4 TCP 0.0.0.0:3389 0.0.0.0:0 LISTENING 1180 TCP 192.168.10.25:52314 203.0.113.10:443 ESTABLISHED 6420 TCP 192.168.10.25:52318 203.0.113.10:443 TIME_WAIT 0 TCP 192.168.10.25:52320 198.51.100.20:443 SYN_SENT 6420 UDP 0.0.0.0:5353 *:* 2216 UDP 192.168.10.25:137 *:* 4
LISTENING on 0.0.0.0:3389 means this PC accepts Remote Desktop connections on every address. ESTABLISHED to 203.0.113.10:443 is a working HTTPS connection from program 6420. SYN_SENT to 198.51.100.20:443 is a connection that sent its first handshake message and got no answer yet: if it stays like that, something (often a firewall) is dropping it.| State | Meaning |
|---|---|
LISTENING | A program is waiting for incoming connections on this port |
SYN_SENT | This PC started the three-way handshake; no reply yet |
ESTABLISHED | Connection is up and data can flow |
TIME_WAIT | Connection recently closed; Windows keeps it briefly (see Closing a connection) |
CLOSE_WAIT | The other side closed; the program on this PC hasn't closed its end yet |
To find which program owns PID 6420:
C:\> tasklist /fi "PID eq 6420" Image Name PID Session Name Session# Mem Usage ========================= ======== ================ =========== ============ msedge.exe 6420 Console 1 182,344 K
route print: where does traffic go?
Every PC has a small routing table: a list of rules saying where to send packets for each destination network. route print shows it. Use route print -4 to see only IPv4.
Syntaxroute print [-4]
C:\> route print -4 =========================================================================== Interface List 7...02 00 00 00 00 25 ......Intel(R) Ethernet Connection I219-LM 1...........................Software Loopback Interface 1 =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.10.1 192.168.10.25 25 127.0.0.0 255.0.0.0 On-link 127.0.0.1 331 127.0.0.1 255.255.255.255 On-link 127.0.0.1 331 127.255.255.255 255.255.255.255 On-link 127.0.0.1 331 192.168.10.0 255.255.255.0 On-link 192.168.10.25 281 192.168.10.25 255.255.255.255 On-link 192.168.10.25 281 192.168.10.255 255.255.255.255 On-link 192.168.10.25 281 224.0.0.0 240.0.0.0 On-link 127.0.0.1 331 224.0.0.0 240.0.0.0 On-link 192.168.10.25 281 255.255.255.255 255.255.255.255 On-link 127.0.0.1 331 255.255.255.255 255.255.255.255 On-link 192.168.10.25 281 =========================================================================== Persistent Routes: None
0.0.0.0 / 0.0.0.0 is the default route: "anything not listed elsewhere goes to 192.168.10.1". 192.168.10.0 / 255.255.255.0 On-link means the local subnet is reached directly, with ARP, no gateway needed. When the PC has more than one 0.0.0.0 line (for example with a VPN connected), the one with the lowest metric wins.Putting it together: a real example
A user says Outlook works, but the company intranet site intranet.office.example "won't load".
ipconfig /all: address, gateway and DNS all look right. Layers 1 to 3 are configured.ping 192.168.10.1: replies. The LAN works.nslookup intranet.office.example: returns192.168.20.80. DNS works.ping 192.168.20.80: replies. The path works.netstat -ano | findstr 192.168.20.80: a connection to port 443 stuck inSYN_SENT.
Conclusion: the server is reachable but nothing answers on port 443. Either the web service on the server is stopped, or a firewall is blocking HTTPS. Pass it to the server team with this evidence. Five commands, and the network has been cleared.
When the commands themselves mislead you
- Ping blocked: Windows Firewall blocks incoming ping by default on many PCs. A PC that doesn't answer ping may be perfectly healthy.
- Wrong adapter: laptops show Ethernet, Wi-Fi, Bluetooth and VPN adapters. Make sure you are reading the one actually in use.
- VPN changes everything: with a VPN connected, DNS servers, routes and the default gateway can all change. Check
route printandipconfig /allwith the VPN on and off. - Old cache:
arp -aand the DNS cache can show stale entries for a few minutes after a change. - nslookup bypasses the cache: it asks the DNS server directly, while browsers use the Windows cache and the hosts file. If nslookup works but the browser doesn't, flush the cache and check the
hostsfile.
Common mistakes
Plain ipconfig hides the DNS servers and DHCP server, which are often the problem.
"Request timed out" can mean blocked, not broken. Test the real service too.
One silent hop in tracert is normal if later hops answer.
You cut your own connection. Chain /release and /renew in one line.
ipconfig /allfirst: address, mask, gateway, DHCP server and DNS servers. A169.254address means DHCP failed.pingtests reachability;tracertshows where along the path it stops.arp -ashows local MAC addresses only; remote hosts never appear.nslookupshows both the answer and which DNS server gave it.netstat -anoshows connections and listening ports with the owning program's PID;route printshows where traffic is sent.
Check yourself
ipconfig /all shows IPv4 Address 169.254.88.4 and no default gateway. What is the most likely problem?
ping 203.0.113.10 replies, but ping web.example.com says "could not find host". Which command should you run next?
You run arp -a and don't see an entry for the web server 203.0.113.10, even though the website works. Why?
netstat -ano shows a connection to 198.51.100.20:443 stuck in SYN_SENT. What does that suggest?
In tracert, hop 3 shows * * * Request timed out, but hops 4 to 7 reply and the trace completes. What should you conclude?
Related lessons
Use these commands inside a troubleshooting method, and learn the Linux and macOS versions in Essential Linux network commands. For the theory behind the output, see DHCP, DNS, ARP fundamentals and ICMP. Then put them to work in IP and gateway problems and DNS problems.