Routelearn.net
Course menu

Unit 14: Network TroubleshootingLesson 14.4 (4 of 10 in this unit)76 of 84 in the Network Fundamentals course

Essential Windows network commands

Eight commands answer most network questions on a Windows PC: what are my settings, can I reach it, which path does it take, what is my DNS saying, and what is connected. Learn the syntax, see real-looking output, and learn to read it.

Beginner · 18 min read · Before this: What is an IP address?, The default gateway, A troubleshooting method

Windows network commands are built-in command-line utilities, such as ipconfig, ping, tracert, arp, nslookup, netstat and route, used to view a Windows computer's network settings, test reachability, trace paths, query DNS and list its connections and routes.

In simple terms: They are short commands you type in a command prompt to see how your PC is connected and to find out why something on the network is not working.

When a Windows PC has a network problem, you don't need special software to investigate. A handful of built-in commands show what the PC believes about the network and test whether packets can get where they need to go. This lesson goes through each one, the way you would use it when following a troubleshooting method.

Before you start: opening a command prompt

A command prompt is a text window where you type commands and read the results. Windows has two: the classic Command Prompt (cmd) and the newer PowerShell. Every command here works in both.

  1. Press Windows + R, type cmd and press Enter. Or search for "Command Prompt" or "Terminal" in the Start menu.
  2. For commands that change settings (for example arp -d or netstat -b), right-click and choose Run as administrator.
  3. Type command /? (for example ipconfig /?) to see every option for a command.

💡 Copy text out of the window: select the output with the mouse and press Enter (Command Prompt) or Ctrl+C. Pasting the real output into a ticket is much better than describing it.

The commands at a glance

CommandQuestion it answersTroubleshooting step
ipconfigWhat are my IP address, mask and gateway?IP settings
ipconfig /allPlus MAC address, DHCP server, lease and DNS serversIP settings, services
ipconfig /release, /renewGive back my DHCP address and ask for a new oneServices (DHCP)
ipconfig /flushdnsForget all cached DNS answersServices (DNS)
pingCan I reach this address, and how fast?Reachability
tracertWhich routers does my traffic pass, and where does it stop?Reachability
arp -aWhich MAC address belongs to each local IP?Ethernet / IP
nslookupWhat IP address does this name turn into, and who told me?Services (DNS)
netstat -anoWhat connections and listening ports does this PC have?Application
route printWhere does this PC send traffic for each network?IP settings

All the examples use one office PC: address 192.168.10.25/24, default gateway 192.168.10.1, and a server at 192.168.10.5 that does both DHCP and DNS. The remote web server is web.example.com at 203.0.113.10.

PC-SALES-07192.168.10.25SwitchGateway192.168.10.1DHCP + DNS192.168.10.5Internetweb.example.com203.0.113.10
  1. 1. ipconfig /all, /renew: show and refresh the settings the PC got from the DHCP server.
  2. 2. arp -a and route print: the gateway's MAC address, and the rule that sends off-network traffic to it.
  3. 3. nslookup: asks the DNS server to turn web.example.com into 203.0.113.10.
  4. 4. ping and tracert: test the path to the server and list each router on the way.
  5. 5. netstat -ano: lists this PC's open connections, like the browser's HTTPS session.

ipconfig: what are my settings?

ipconfig (IP configuration) shows the network settings of every network adapter (each network card or Wi-Fi card) in the PC. It is almost always the first command to run, because a PC with wrong settings can't work no matter how healthy the network is.

Syntaxipconfig [/all | /release | /renew | /flushdns | /displaydns]

Example output from a Windows PC, written for this lesson
C:\> ipconfig
Windows IP Configuration


Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . : office.example
   Link-local IPv6 Address . . . . . : fe80::1c2a:5b3f:9e4d:7a10%7
   IPv4 Address. . . . . . . . . . . : 192.168.10.25
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.10.1

Wireless LAN adapter Wi-Fi:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
How to read it: find the adapter that is in use (here "Ethernet"). Check the IPv4 Address is in the right network, the Subnet Mask matches other devices, and a Default Gateway is set. The fe80:: line is an automatic IPv6 address every adapter has; you can ignore it for now. "Media disconnected" on the Wi-Fi adapter just means Wi-Fi isn't in use.

ipconfig /all: the full picture

Example output from a Windows PC, written for this lesson
C:\> ipconfig /all
Windows IP Configuration

   Host Name . . . . . . . . . . . . : PC-SALES-07
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : office.example

Ethernet adapter Ethernet:

   Connection-specific DNS Suffix  . : office.example
   Description . . . . . . . . . . . : Intel(R) Ethernet Connection I219-LM
   Physical Address. . . . . . . . . : 02-00-00-00-00-25
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::1c2a:5b3f:9e4d:7a10%7(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.10.25(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Monday, 5 October 2026 08:02:14
   Lease Expires . . . . . . . . . . : Tuesday, 6 October 2026 08:02:14
   Default Gateway . . . . . . . . . : 192.168.10.1
   DHCP Server . . . . . . . . . . . : 192.168.10.5
   DNS Servers . . . . . . . . . . . : 192.168.10.5
   NetBIOS over Tcpip. . . . . . . . : Enabled
LineWhat it tells youWarning signs
Physical AddressThe adapter's MAC address (Windows writes it with dashes)Needed when a switch or DHCP reservation is tied to a MAC
DHCP EnabledYes = settings came from DHCP. No = typed in by hand (static)"No" on a normal user PC often means someone set it manually
IPv4 AddressThe PC's address. "(Preferred)" means it is in use169.254.x.x = DHCP failed. "(Duplicate)" = address conflict
Lease Obtained / ExpiresWhen DHCP lent the address and when the loan endsVery old "Obtained" with fresh problems: try a renew
Default GatewayThe router for every other network (default gateway)Blank, or not in the PC's own subnet
DHCP ServerWhich server gave the addressAn unknown address here may be a rogue DHCP server (for example a home router plugged into the office)
DNS ServersWhere the PC sends name lookupsA typo, or a server that no longer exists
Example output from a Windows PC, written for this lesson
C:\> ipconfig /all
Ethernet adapter Ethernet:

   Physical Address. . . . . . . . . : 02-00-00-00-00-25
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   Autoconfiguration IPv4 Address. . : 169.254.37.12(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.0.0
   Default Gateway . . . . . . . . . :
   DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
                                       fec0:0:0:ffff::2%1
                                       fec0:0:0:ffff::3%1
A failure to recognise on sight. "Autoconfiguration IPv4 Address" starting 169.254 is an APIPA address (Automatic Private IP Addressing): Windows invented it because no DHCP server answered. There is no gateway, and the fec0:: DNS entries are placeholders. The real question is why DHCP didn't answer: cable, switch port, VLAN or the DHCP server itself.

ipconfig /release and /renew: get a fresh DHCP address

/release tells the DHCP server "I'm giving this address back" and removes it from the adapter. /renew runs the DHCP exchange again to get a new lease. Use them after fixing a cable or VLAN problem, or when a PC still holds settings from the wrong network.

Step 1 of 5 · Release
PC-SALES-07
02-00-00-00-00-25
Office LAN
192.168.10.0/24
DHCP server
192.168.10.5
After /renew
IPv4:
192.168.10.25
Gateway:
192.168.10.1
DNS:
192.168.10.5
Example output from a Windows PC, written for this lesson
C:\> ipconfig /renew
Windows IP Configuration

An error occurred while renewing interface Ethernet : unable to contact your DHCP server. Request has timed out.
If renewing fails like this, DHCP messages are not reaching the server (or its answers are not coming back). Go down to the physical and Ethernet checks. If it succeeds, Windows prints the new settings in the same format as ipconfig.

⚠️ Careful when working remotely. ipconfig /release cuts the PC off the network until the renew finishes. If you are connected to that PC by remote desktop, you will lose the session. Run ipconfig /release && ipconfig /renew as one line so the renew still happens.

ipconfig /flushdns: forget cached names

Windows remembers recent DNS answers in a DNS cache so it doesn't ask again every time. If a website moved to a new IP address, the PC may keep using the old one until the cached answer expires. /flushdns empties the cache; /displaydns shows what is in it.

Example output from a Windows PC, written for this lesson
C:\> ipconfig /flushdns
Windows IP Configuration

Successfully flushed the DNS Resolver Cache.
This only clears the PC's own cache. The browser has its own cache too (close and reopen it), and the DNS server may still hold the old answer.

ping: can I reach it?

ping sends small ICMP echo request messages to an address and waits for echo reply messages. Windows sends four by default. It tells you whether the target answers, how long the round trip takes, and whether any messages were lost. The full story is in Ping.

Syntaxping [-n count] [-t] [-l size] [-4] target

OptionMeaning
-n 10Send 10 echo requests instead of 4
-tKeep pinging until you press Ctrl+C. Good for watching a link while you move a cable
-l 1400Send 1400 bytes of data instead of 32
-4Force IPv4 when a name has both IPv4 and IPv6 addresses
Example output from a Windows PC, written for this lesson
C:\> ping 192.168.10.1
Pinging 192.168.10.1 with 32 bytes of data:
Reply from 192.168.10.1: bytes=32 time=1ms TTL=255
Reply from 192.168.10.1: bytes=32 time<1ms TTL=255
Reply from 192.168.10.1: bytes=32 time<1ms TTL=255
Reply from 192.168.10.1: bytes=32 time<1ms TTL=255

Ping statistics for 192.168.10.1:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 1ms, Average = 0ms
Success. Four replies, no loss. time is the round trip; on a LAN it is usually under 1 ms, across the internet 10 to 100 ms. TTL is the time-to-live left in the reply: it hints at the type of device and how many routers the reply crossed, but it is not a speed.
You seeIt meansNext step
Reply from <target>The target is reachableMove up: DNS, then the application
Request timed out.No answer came back in timeTarget down, ping blocked by a firewall, or the path broken. Try tracert
Destination host unreachable from your own IPYour PC couldn't find the target (or gateway) on the LAN with ARPCheck the local network, mask and gateway
Destination host unreachable from a router's IPThat router has no route to the targetThe problem is at or after that router
Ping request could not find hostThe name didn't resolveDNS problem: use nslookup
General failure.The PC couldn't send at allAdapter disabled, no address, or local firewall/VPN software
Example output from a Windows PC, written for this lesson
C:\> ping web.example.com
Pinging web.example.com [203.0.113.10] with 32 bytes of data:
Request timed out.
Request timed out.
Request timed out.
Request timed out.

Ping statistics for 203.0.113.10:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
The first line shows the name did resolve to 203.0.113.10, so DNS works. But no replies came back. Before blaming the network, open the website: many servers simply block ping.

tracert: which way does it go?

tracert (trace route) lists every router between your PC and the target. It sends probes with a TTL (time-to-live, a hop counter in the IP header) of 1, then 2, then 3, and so on. Each router lowers the TTL by one; the router where it reaches zero throws the probe away and sends back an ICMP "time exceeded" message, which reveals its address. On Windows the probes are ICMP echo requests. See Traceroute for the details.

Syntaxtracert [-d] [-h max_hops] target

PC192.168.10.25Hop 1192.168.10.1Hop 2 (ISP)198.51.100.1Hop 3198.51.100.45Target203.0.113.10
  1. 1. TTL 1: the gateway lowers TTL to 0, drops the probe and replies "time exceeded". Hop 1 found.
  2. 2. TTL 2: the probe dies at the ISP router, which reports back. Hop 2 found.
  3. 3. TTL 3: one hop further each time.
  4. 4. Target reached: the server sends an echo reply instead, and tracert stops.
Example output from a Windows PC, written for this lesson
C:\> tracert -d web.example.com
Tracing route to web.example.com [203.0.113.10]
over a maximum of 30 hops:

  1    <1 ms    <1 ms    <1 ms  192.168.10.1
  2     8 ms     7 ms     8 ms  198.51.100.1
  3    12 ms    11 ms    12 ms  198.51.100.45
  4     *        *        *     Request timed out.
  5    19 ms    18 ms    19 ms  203.0.113.1
  6    20 ms    19 ms    20 ms  203.0.113.10

Trace complete.
How to read it: each line is one router, with three round-trip times (three probes). -d skips looking up router names, which makes it much faster. Hop 4 shows stars, but hops 5 and 6 answer, so hop 4 just doesn't reply to tracert; traffic passes through it fine. If the stars had continued to hop 30, the path would stop after the last router that answered.

arp -a: who has which MAC address?

To send a frame on the local network, the PC needs the MAC address of the next device. ARP (Address Resolution Protocol) finds it and stores it in the ARP cache. arp -a shows that cache.

Syntaxarp -a [-N interface_ip] arp -d * (admin: clear the cache)

Example output from a Windows PC, written for this lesson
C:\> arp -a
Interface: 192.168.10.25 --- 0x7
  Internet Address      Physical Address      Type
  192.168.10.1          02-00-00-00-00-01     dynamic
  192.168.10.5          02-00-00-00-00-05     dynamic
  192.168.10.255        ff-ff-ff-ff-ff-ff     static
  224.0.0.22            01-00-5e-00-00-16     static
  224.0.0.251           01-00-5e-00-00-fb     static
  239.255.255.250       01-00-5e-7f-ff-fa     static
  255.255.255.255       ff-ff-ff-ff-ff-ff     static
How to read it: dynamic entries were learned with ARP; here the gateway (.1) and the server (.5). The static entries are built in: the broadcast addresses map to ff-ff-ff-ff-ff-ff and the 224.x/239.x lines are multicast. Note there is no entry for 203.0.113.10: remote hosts never appear here, because the PC only ever needs the gateway's MAC to reach them (see ARP for local and remote destinations).

💡 Spot a problem: if the gateway is missing from arp -a right after you pinged it, the PC never got an ARP reply. The gateway is unreachable at Layer 2. If two different IPs show the same MAC unexpectedly, look for an address conflict or ARP spoofing.

nslookup: what does DNS say?

nslookup (name server lookup) asks a DNS server to resolve a name and shows the answer, plus which server answered. That second part is what makes it so useful: it shows you exactly where the PC is sending its DNS questions. The online Nslookup tool on RouteLearn.net does the same from the internet.

Syntaxnslookup [-type=A|AAAA|MX|TXT|NS] name [dns_server]

Example output from a Windows PC, written for this lesson
C:\> nslookup web.example.com
Server:  dns1.office.example
Address:  192.168.10.5

Non-authoritative answer:
Name:    web.example.com
Address:  203.0.113.10
Server/Address (top) is the DNS server the PC used. Name/Address (bottom) is the answer. "Non-authoritative" just means the answer came from the server's cache or another server, not from the domain's own DNS server. That is normal.
Example output from a Windows PC, written for this lesson
C:\> nslookup web.example.com 192.0.2.53
Server:  UnKnown
Address:  192.0.2.53

Non-authoritative answer:
Name:    web.example.com
Address:  203.0.113.10
Adding a server address at the end asks that server instead. If your normal DNS server fails but another one answers, the problem is your DNS server, not the network. "UnKnown" only means the server's own name couldn't be looked up; it is harmless.
Example output from a Windows PC, written for this lesson
C:\> nslookup webb.example.com
Server:  dns1.office.example
Address:  192.168.10.5

*** dns1.office.example can't find webb.example.com: Non-existent domain
Non-existent domain (NXDOMAIN) means the DNS server worked fine, but the name does not exist: usually a typo. Compare this with DNS request timed out, which means the DNS server didn't answer at all.

netstat -ano: what is connected?

netstat (network statistics) lists the PC's ports and connections. With -a it shows all connections and listening ports, -n shows numbers instead of names (faster), and -o adds the PID (process ID: the number Windows gives each running program). More on this in Viewing connections on your computer.

Syntaxnetstat -ano [| findstr :443]

Example output from a Windows PC, written for this lesson
C:\> netstat -ano
Active Connections

  Proto  Local Address          Foreign Address        State           PID
  TCP    0.0.0.0:135            0.0.0.0:0              LISTENING       1012
  TCP    0.0.0.0:445            0.0.0.0:0              LISTENING       4
  TCP    0.0.0.0:3389           0.0.0.0:0              LISTENING       1180
  TCP    192.168.10.25:52314    203.0.113.10:443       ESTABLISHED     6420
  TCP    192.168.10.25:52318    203.0.113.10:443       TIME_WAIT       0
  TCP    192.168.10.25:52320    198.51.100.20:443      SYN_SENT        6420
  UDP    0.0.0.0:5353           *:*                                    2216
  UDP    192.168.10.25:137      *:*                                    4
How to read it: each line is one socket. LISTENING on 0.0.0.0:3389 means this PC accepts Remote Desktop connections on every address. ESTABLISHED to 203.0.113.10:443 is a working HTTPS connection from program 6420. SYN_SENT to 198.51.100.20:443 is a connection that sent its first handshake message and got no answer yet: if it stays like that, something (often a firewall) is dropping it.
StateMeaning
LISTENINGA program is waiting for incoming connections on this port
SYN_SENTThis PC started the three-way handshake; no reply yet
ESTABLISHEDConnection is up and data can flow
TIME_WAITConnection recently closed; Windows keeps it briefly (see Closing a connection)
CLOSE_WAITThe other side closed; the program on this PC hasn't closed its end yet

To find which program owns PID 6420:

Example output from a Windows PC, written for this lesson
C:\> tasklist /fi "PID eq 6420"
Image Name                     PID Session Name        Session#    Mem Usage
========================= ======== ================ =========== ============
msedge.exe                    6420 Console                    1    182,344 K
The connection belongs to the Edge browser. This is how you answer "is my server program actually listening?" or "what is this PC connecting to?"

route print: where does traffic go?

Every PC has a small routing table: a list of rules saying where to send packets for each destination network. route print shows it. Use route print -4 to see only IPv4.

Syntaxroute print [-4]

Example output from a Windows PC, written for this lesson
C:\> route print -4
===========================================================================
Interface List
  7...02 00 00 00 00 25 ......Intel(R) Ethernet Connection I219-LM
  1...........................Software Loopback Interface 1
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0     192.168.10.1    192.168.10.25     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    331
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    331
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    331
     192.168.10.0    255.255.255.0         On-link     192.168.10.25    281
    192.168.10.25  255.255.255.255         On-link     192.168.10.25    281
   192.168.10.255  255.255.255.255         On-link     192.168.10.25    281
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    331
        224.0.0.0        240.0.0.0         On-link     192.168.10.25    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    331
  255.255.255.255  255.255.255.255         On-link     192.168.10.25    281
===========================================================================
Persistent Routes:
  None
How to read it: 0.0.0.0 / 0.0.0.0 is the default route: "anything not listed elsewhere goes to 192.168.10.1". 192.168.10.0 / 255.255.255.0 On-link means the local subnet is reached directly, with ARP, no gateway needed. When the PC has more than one 0.0.0.0 line (for example with a VPN connected), the one with the lowest metric wins.

Putting it together: a real example

A user says Outlook works, but the company intranet site intranet.office.example "won't load".

  1. ipconfig /all: address, gateway and DNS all look right. Layers 1 to 3 are configured.
  2. ping 192.168.10.1: replies. The LAN works.
  3. nslookup intranet.office.example: returns 192.168.20.80. DNS works.
  4. ping 192.168.20.80: replies. The path works.
  5. netstat -ano | findstr 192.168.20.80: a connection to port 443 stuck in SYN_SENT.

Conclusion: the server is reachable but nothing answers on port 443. Either the web service on the server is stopped, or a firewall is blocking HTTPS. Pass it to the server team with this evidence. Five commands, and the network has been cleared.

When the commands themselves mislead you

  • Ping blocked: Windows Firewall blocks incoming ping by default on many PCs. A PC that doesn't answer ping may be perfectly healthy.
  • Wrong adapter: laptops show Ethernet, Wi-Fi, Bluetooth and VPN adapters. Make sure you are reading the one actually in use.
  • VPN changes everything: with a VPN connected, DNS servers, routes and the default gateway can all change. Check route print and ipconfig /all with the VPN on and off.
  • Old cache: arp -a and the DNS cache can show stale entries for a few minutes after a change.
  • nslookup bypasses the cache: it asks the DNS server directly, while browsers use the Windows cache and the hosts file. If nslookup works but the browser doesn't, flush the cache and check the hosts file.

Common mistakes

Using ipconfig without /all

Plain ipconfig hides the DNS servers and DHCP server, which are often the problem.

Treating timeouts as proof

"Request timed out" can mean blocked, not broken. Test the real service too.

Reading stars as the end

One silent hop in tracert is normal if later hops answer.

Releasing over remote desktop

You cut your own connection. Chain /release and /renew in one line.

Key takeaways
  • ipconfig /all first: address, mask, gateway, DHCP server and DNS servers. A 169.254 address means DHCP failed.
  • ping tests reachability; tracert shows where along the path it stops.
  • arp -a shows local MAC addresses only; remote hosts never appear.
  • nslookup shows both the answer and which DNS server gave it.
  • netstat -ano shows connections and listening ports with the owning program's PID; route print shows where traffic is sent.

Check yourself

Predict · scenario 1

ipconfig /all shows IPv4 Address 169.254.88.4 and no default gateway. What is the most likely problem?

Predict · scenario 2

ping 203.0.113.10 replies, but ping web.example.com says "could not find host". Which command should you run next?

Predict · scenario 3

You run arp -a and don't see an entry for the web server 203.0.113.10, even though the website works. Why?

Predict · scenario 4

netstat -ano shows a connection to 198.51.100.20:443 stuck in SYN_SENT. What does that suggest?

Predict · scenario 5

In tracert, hop 3 shows * * * Request timed out, but hops 4 to 7 reply and the trace completes. What should you conclude?

Related lessons

Use these commands inside a troubleshooting method, and learn the Linux and macOS versions in Essential Linux network commands. For the theory behind the output, see DHCP, DNS, ARP fundamentals and ICMP. Then put them to work in IP and gateway problems and DNS problems.

FAQ

Do I need to run these commands as administrator?
Most of them, no. ipconfig, ping, tracert, arp -a, nslookup and route print work in a normal Command Prompt. ipconfig /release and /renew work as a normal user on most PCs. netstat -b (show program names), arp -d (delete entries) and route add or delete need an administrator prompt.
Should I use Command Prompt or PowerShell?
Either. Every command on this page works in both. PowerShell also has its own newer commands, such as Get-NetIPConfiguration, Test-NetConnection and Resolve-DnsName, which give the same information as objects that are easier to filter. Learn the classic commands first: they appear in every guide and on every Windows version.
What is the difference between ipconfig and ipconfig /all?
Plain ipconfig shows the basics for each adapter: IP address, subnet mask and default gateway. ipconfig /all adds the MAC address, whether DHCP is on, which DHCP server gave the address, lease times and the DNS servers. When troubleshooting, use /all.
Why does tracert show stars on some lines but still finish?
A line of stars means that router didn't send back the ICMP 'time exceeded' message, often because it is set to ignore or rate-limit them. If later hops answer, traffic is passing through that router normally. Only stars that continue to the end of the trace point to a real stop.