Rıza KorkusuzTechnical Support
0 / 15 reviewed
← Back to Portfolio
Field guide · Windows Network CMD

Evidence first. Then the reset.

A practical Windows 10/11 guide for isolating network problems layer by layer — which command answers which question, how to read the output, and how to explain it in an interview.

15 sections 5-step workflow 8 command modules Safe recovery ladder 4 scenarios Interview Q&A
Question → Command → InspectEvery command page follows the same pattern: what question it answers, which fields to read, how to interpret them, and an interview sentence.
Evidence before resetsCapture ipconfig /all and test reachability before flushing, renewing or resetting. One controlled change at a time.
Practice out loudOpen the interview cards after you can explain the workflow without looking. Mark sections reviewed as you go.
1

Start here: use evidence before resets

PURPOSE · Windows 10 / 11

This guide helps you isolate a network problem layer by layer. The goal is not to memorize commands, but to know which diagnostic question each command answers.

Tickets that say “the internet is down” are symptoms. Fast support isolates whether the fault is local configuration, LAN reachability, upstream IP path, DNS, routing, or the application itself — then makes the smallest change that fits the evidence.

  • Administrator rights: some reset, ARP, route, firewall and netstat options need an elevated Command Prompt.
  • Reading pattern: Question → Command → What to inspect → Interpretation → Interview sentence.
  • Document: command, result, time, and any change you made.
Importantnetsh advfirewall reset can remove custom firewall rules. Do not run it on a managed device without authorization and a backup.
Interview principle“I start with scope and configuration, then test reachability, DNS, routing and the application layer. I make one controlled change at a time.”
2

Five-step diagnostic workflow

METHOD

Scope the outage, read local config, prove reachability, then name/route and the service — and write it down.

01

Scope

One device, one site, or everyone?

02

Local config

IP, mask, gateway, DHCP, DNS

03

Reachability

Loopback → gateway → internet

04

Name & route

DNS resolution and hop path

05

Service

Port, process, firewall, app

Minimum test sequence

ipconfig /all
ping 127.0.0.1
ping <default-gateway>
ping 8.8.8.8
nslookup example.com
tracert -d example.com

Result → meaning → next step

ResultLikely meaningNext step
No valid IPv4; 169.254.x.xDHCP lease was not obtained.Check link/Wi-Fi, DHCP and VLAN; then renew.
Gateway failsLocal LAN, adapter, VLAN, Wi-Fi or gateway issue.Inspect adapter, signal, cable, ARP and gateway.
8.8.8.8 works; name failsInternet path exists; DNS is the main suspect.Use nslookup; inspect configured DNS servers.
Ping fails; website worksICMP may be filtered; ping alone does not prove outage.Test the actual service/port and application.
Only one application failsLikely service, port, proxy, firewall or application issue.Use netstat -ano and application logs.
DocumentCommand, result, time, change. One change, one retest, one note.
3

Core concepts behind the commands

FOUNDATIONS

Terms you will see in tickets and interview answers — short definitions you can say out loud.

DHCP

Automatically assigns settings such as IP address, subnet mask, gateway and DNS.

Static IP

A fixed address configured manually or by reservation; useful for servers, printers and loggers.

Subnet mask

Separates the network and host portions of an IP address. 255.255.255.0 is /24 on many small networks.

Default gateway

The next-hop router used to reach destinations outside the local subnet.

DNS

Resolves names to IP addresses. If IP access works but names fail, suspect DNS.

NAT

Translates private addresses so multiple devices can share public connectivity.

VPN

Creates an encrypted tunnel and may change routing and DNS behavior.

TCP port

A numbered endpoint used by a service, such as 443 for HTTPS or 3389 for RDP.

Packet loss

The percentage of packets that do not arrive; it can cause retries and instability.

Latency

Round-trip delay measured in milliseconds; acceptable values depend on distance and workload.

Firewall

Applies rules to allow required traffic and block unwanted traffic.

NTP

Synchronizes clocks; critical for reliable logs, monitoring data and event correlation.

APIPA clueA 169.254.x.x address usually means Windows self-assigned an address because it could not obtain a DHCP lease. It does not normally provide routed internet access.
4

ipconfig: inspect local configuration

COMMAND 01

Which IP, mask, gateway, DNS and DHCP settings is this computer using?

ipconfig
ipconfig /all
ipconfig /displaydns
ipconfig /flushdns
ipconfig /release
ipconfig /renew
CommandUseInspect
ipconfigQuick adapter summaryIPv4, subnet mask, default gateway
ipconfig /allFull configurationDHCP enabled, DNS servers, MAC, lease times
/displaydnsView resolver cacheCached names, record types and TTLs
/flushdnsClear local DNS cacheUseful after stale/incorrect name resolution
/release + /renewDrop and request a DHCP leaseMay briefly disconnect the device
Do not renew firstCapture ipconfig /all first. Otherwise you may erase evidence such as the old address, gateway, DNS server or lease state.
Healthy pattern
  • Expected subnet (for example 192.168.1.x)
  • Gateway in the same subnet
  • DNS servers present
  • Correct adapter is connected
Red flags
  • 169.254.x.x address
  • No default gateway
  • Wrong VLAN/subnet
  • Unexpected static DNS or duplicate IP
Interview sentence“I use ipconfig /all to verify the IP address, subnet mask, default gateway, DNS servers and DHCP lease before changing anything.”
5

ping: test reachability, delay and loss

COMMAND 02

Ping sends ICMP Echo packets and gives quick evidence about reachability, approximate round-trip time and packet loss.

ping 127.0.0.1
ping <default-gateway>
ping 8.8.8.8
ping example.com
ping -t example.com
ping -n 20 example.com
TestMeaning
127.0.0.1Tests the local TCP/IP stack, not the cable or internet.
Default gatewayTests the path from the PC to the local router.
8.8.8.8Tests IP reachability to a public address; it does not test DNS resolution by itself.
example.comCombines name resolution with ICMP reachability.
-t / -n 20Continuous test until Ctrl+C / Fixed sample of 20 requests.

How to read the output: time is latency; Lost is packet loss. Compare several samples and look for consistency. One slow response does not prove a fault.

Critical caveatA timeout does not always mean the host is down. Firewalls and routers may block or rate-limit ICMP while the actual service still works.
Interview sentence“I ping the loopback address, the default gateway, a public IP and then a hostname. This separates local stack, LAN, internet and DNS problems.”
6

nslookup: isolate DNS problems

COMMAND 03

nslookup queries DNS directly and shows which IP address a name resolves to and which DNS server answered.

nslookup example.com
nslookup example.com 8.8.8.8
nslookup
> set type=mx
> example.com
> exit
ObservationInterpretation
Default DNS fails; 8.8.8.8 answersConfigured DNS server or the path to it may be faulty.
Both return NXDOMAINThe requested name may not exist, may be mistyped, or is unavailable in that DNS view.
Different answersCould be load balancing, CDN, split DNS, cache or propagation — not automatically a fault.
ping 8.8.8.8 works; nslookup failsGeneral IP connectivity exists; focus on DNS settings, reachability and policy.

Structured DNS check

  1. Run ipconfig /all and note the configured DNS servers.
  2. Query the default DNS: nslookup example.com.
  3. Query an approved alternate server for comparison.
  4. Use ipconfig /displaydns to inspect cache; flush only if stale cache is plausible.
  5. Retest the affected application, not only the command prompt.
Corporate DNSPublic DNS may not resolve internal names. On a VPN or domain network, using 8.8.8.8 can produce a misleading failure or bypass intended policy. Follow the organization's DNS design.
Interview sentence“If a public IP is reachable but a hostname is not, I compare the configured DNS server with an approved alternate and inspect the returned records.”
7

tracert & pathping: locate the path problem

COMMANDS 04–05

tracert increases the packet's TTL to reveal successive router hops. pathping adds repeated measurements to estimate loss at hops/links.

tracert example.com
tracert -d example.com
pathping example.com
Output clueDo not jump to conclusions
Asterisks at one hop, later hops respondThat router may de-prioritize ICMP. It is not proof of packet loss for forwarded traffic.
Delay begins at one hop and persists afterwardMay indicate congestion or a slow segment; repeat the test and compare.
Private IPs in early hopsNormal inside local/provider networks. Private hops are not automatically a problem.
Route changes between testsCould be dynamic routing or load balancing. Correlate with time and service symptoms.
Why -d?tracert -d skips reverse DNS lookups, so results appear faster and slow name resolution does not distract from the route.

Practical use

  1. Test the destination by name and, if known, by IP.
  2. Run tracert -d for a quick path.
  3. Use pathping when intermittent loss is suspected.
  4. Save the time, target and complete output.
Interview sentence“I use tracert to identify the network path and pathping to add loss measurements, but I do not treat a single silent hop as definitive evidence.”
8

netstat: connect ports to processes

COMMAND 06

Verify listening ports and active connections, and map them to a PID.

netstat -an
netstat -ano
netstat -abno
netstat -e
netstat -r
netstat -ano | findstr :443
tasklist /FI "PID eq 1234"
OptionMeaningUse
-aAll active connections and listening portsFind listeners and active sessions.
-nNumeric addresses and portsAvoid slow name/service lookups.
-oOwning process ID (PID)Map a connection to Task Manager or tasklist.
-bExecutable involved; often needs adminIdentify which application owns the connection.
-eEthernet statisticsReview bytes, errors and discards over time.
-rRouting tableEquivalent route view for troubleshooting.

Connection states

  • LISTENING — a local service waits for connections.
  • ESTABLISHED — a TCP session is active.
  • TIME_WAIT — closed session is waiting safely before reuse.
Diagnostic exampleIf an application should listen on TCP 502 but netstat -ano shows no listener, first check whether the service is running and configured for the correct interface. If it is listening locally but remote clients cannot connect, investigate firewall, routing and upstream ACLs.
PrivacyNetstat output can reveal internal IPs, remote services and process information. Redact sensitive details before sharing outside the support team.
Interview sentence“I use netstat with numeric output and PIDs to verify whether a service is listening and which process owns the connection.”
9

arp & route: local identity and next-hop decisions

COMMANDS 07–08

ARP maps local IPv4 addresses to MAC addresses. The routing table tells Windows which gateway and interface to use for a destination.

arp -a
arp -d *
route print
route print -4
route add 10.20.0.0 mask 255.255.0.0 192.168.1.1
route -p add 10.20.0.0 mask 255.255.0.0 192.168.1.1
route delete 10.20.0.0
FieldMeaning
Network Destination + NetmaskWhich destination range the route matches.
GatewayNext-hop router; “On-link” means directly reachable.
InterfaceLocal interface/address used to send.
MetricPreference/cost; more specific prefix wins first, then metric helps select.
Change controlarp -d * clears dynamic ARP entries and can briefly interrupt local communication. Static/persistent routes can redirect traffic after reboot. Record the original state and use changes only with authorization.
Interview sentence“ARP tells me which MAC address owns a local IPv4 neighbor, while the routing table tells me which next hop Windows selects for a destination.”
10

netsh & Wi-Fi: inspect and repair with care

COMMAND 09

Use netsh for interface and WLAN inspection first. Treat Winsock, IP and firewall resets as controlled changes — not the first step.

Low-risk inspection

netsh interface show interface
netsh wlan show interfaces
netsh wlan show profiles
netsh int tcp show global
CommandDiagnostic value
interface show interfaceAdministrative/connection state and interface type.
wlan show interfacesSSID, radio type, channel, signal and connection state.
wlan show profilesSaved Wi-Fi profile names; does not itself display passwords.
int tcp show globalCurrent global TCP settings; inspect before changing.

Repairs that require planning

netsh winsock reset
netsh int ip reset
netsh advfirewall export "%USERPROFILE%\Desktop\firewall-backup.wfw"
netsh advfirewall reset
  • Winsock reset — returns the Windows socket catalog to defaults.
  • IP reset — resets important TCP/IP configuration components.
  • Firewall reset — can remove custom firewall rules.
  • A reboot and reconfiguration of VPN/security agents may be required.
Saved Wi-Fi passwordnetsh wlan show profile name="SSID" key=clear can expose the saved key to an authorized administrator. Use it only on systems and networks you are permitted to manage; never paste the output into tickets or chat.
Interview sentence“I use netsh for interface and WLAN inspection first. I treat Winsock, IP and firewall resets as controlled changes, not as the first troubleshooting step.”
11

w32tm & NTP: keep timestamps trustworthy

COMMAND 10

Accurate time lets teams correlate events across devices. Large clock drift can break authentication, certificates, scheduled tasks and monitoring timelines.

w32tm /query /status
w32tm /query /source
w32tm /query /configuration
w32tm /resync
CheckWhat to inspect
/query /statusLast successful sync, stratum, source and offset-related status.
/query /sourceCurrent time source — domain hierarchy, configured NTP source or local clock.
/query /configurationWindows Time settings and policy-controlled values.
/resyncRequests synchronization; may require elevation and a reachable source.
Monitoring exampleIf a solar/PV data logger is five minutes ahead, its production samples and alarms can appear in the wrong place on the timeline. Verify the timezone, NTP source, reachability and last sync before blaming the monitoring platform.
Do not force arbitrary public NTPDomain-joined and managed devices may be required to follow the organization's time hierarchy. Changing the source can violate policy and create authentication problems.
Interview sentence“I verify the Windows time source and last synchronization because accurate timestamps are essential for event correlation, monitoring and authentication.”
12

Safe recovery ladder

RECOVERY

Climb from low-impact evidence gathering to high-impact resets only when evidence supports it.

1

Confirm scope; capture ipconfig /all, time and error

Preserves evidence and avoids treating a broad outage as a PC problem.

Low
2

Check link, Wi-Fi, airplane mode, cable, adapter and VPN

Physical and connection-state issues are common.

Low
3

Ping loopback, gateway, public IP; test DNS separately

Isolates stack, LAN, internet and name resolution.

Low
4

Flush DNS only when stale cache is plausible

Removes local cached records without resetting the whole stack.

Low
5

Release/renew DHCP after recording the lease

Requests fresh addressing; causes a short disconnect.

Medium
6

Restart affected adapter/service or reboot in an approved window

Clears transient state while keeping the change understandable.

Medium
7

Reset Winsock or TCP/IP when evidence supports it

Broad repair; can affect VPN/security software and requires reboot.

High
8

Back up and reset firewall only as a last resort with authorization

May remove required security and application rules.

High
Avoid the “seven-command reset” as a first moveRunning every reset at once destroys diagnostic evidence and makes it impossible to know which change fixed the issue. It can also create new problems.

Change record

Time:
User impact:
Before-state commands:
Change made:
After-state test:
Rollback or next escalation:
Support habitOne change, one retest, one note.
13

Scenarios: turn command output into a diagnosis

PRACTICE

Four common tickets. Open each card for the checks and interpretation.

1 Connected to Wi-Fi, but no internet

Checks

  • ipconfig /all: valid IP/gateway/DNS?
  • Ping gateway.
  • Ping public IP.
  • nslookup a hostname.

Interpretation

169.254.x.x suggests DHCP failure. Gateway failure points local. Public IP works but DNS fails points to DNS.

2 Website fails, other sites work

Checks

  • nslookup affected-site
  • tracert -d affected-site
  • Test browser/incognito and an approved alternate network.
  • Check proxy, certificate, status page and service port.

Interpretation

This is less likely to be a full internet outage. Consider DNS record, route/CDN, proxy, certificate, firewall or remote-service issues.

3 Intermittent monitoring connection

Checks

  • ping -n 50 gateway
  • pathping server
  • netstat -ano
  • w32tm /query /status

Interpretation

Correlate loss/latency with application logs and timestamps. Verify the process and service port. Do not blame a silent intermediate hop alone.

4 VPN connected, internal name fails

Checks

  • ipconfig /all: VPN DNS and suffix?
  • route print: internal route?
  • nslookup internal-name
  • Compare with approved VPN design.

Interpretation

Likely split-DNS, DNS suffix, route or VPN policy issue. Public DNS is not a valid test for internal names.

Escalate with evidenceInclude affected user/device, time, scope, IP/subnet, gateway/DNS, target, exact error, command output and changes already attempted.
14

Interview practice

INTERVIEW

Short answers that show diagnostic thinking. Open each card after you answer out loud.

Answer first, then reveal.

A user says “the internet is down.” What do you do?

“I first determine the scope, then check local configuration with ipconfig. I test the gateway, a public IP and DNS separately. This tells me whether the issue is local, upstream or name-resolution related.”

What does a 169.254 address tell you?

“It is an APIPA address. The device normally assigned it to itself because it did not obtain a DHCP lease, so I check link state, VLAN, DHCP reachability and lease behavior.”

8.8.8.8 responds, but google.com does not. What next?

“Basic IP connectivity exists, so I inspect the configured DNS servers and compare nslookup results. I also consider VPN or corporate split-DNS policy.”

When would you use netstat?

“To verify listening ports and active connections, and to map them to a PID. It helps separate an application-not-listening problem from a firewall or routing problem.”

Why is NTP important in monitoring?

“Accurate time lets us correlate alarms, logs and production data across devices. Clock drift can make a healthy system look inconsistent.”

Would you run a full network reset immediately?

“No. I preserve the current state, isolate the layer, and make the lowest-impact change supported by evidence. Broad resets are controlled last-resort actions.”

“My goal is not only to restore service, but to identify the failing layer, protect evidence and document a repeatable fix.”
15

Cheat sheet & references

QUICK REFERENCE

One-page command map for tickets and interview prep.

QuestionCommandKey clue
What is my configuration?ipconfig /allIP, mask, gateway, DNS, DHCP, lease
Is the local stack working?ping 127.0.0.1Local TCP/IP response
Can I reach the LAN gateway?ping <gateway>Local path and response/loss
Can I reach a public IP?ping 8.8.8.8IP reachability, not DNS
Does DNS resolve?nslookup example.comDNS server and returned records
Where does the route go?tracert -d example.comHop sequence
Where is loss observed?pathping example.comRepeated loss estimates
What is listening?netstat -anoPorts, states, PID
Which MAC owns a neighbor?arp -aIP-to-MAC cache
Which next hop is selected?route printDestination, mask, gateway, metric
What is the Wi-Fi state?netsh wlan show interfacesSSID, signal, radio, state
Is time synchronized?w32tm /query /statusSource and last sync
Remember
  • Ping failure may be ICMP filtering.
  • Latency thresholds depend on context.
  • 169.254.x.x usually points to DHCP.
  • Public DNS may not resolve internal names.
  • Map ports to PIDs before blaming firewall.
  • A single silent tracert hop is not definitive evidence.
  • Change one thing, then retest. Capture state before any reset.
References
  • Primary learning material: Tips 4 IT — “Top Network CMD Commands for Windows: Complete Troubleshooting & Diagnostic Guide” (June 1, 2026). Safety notes and the evidence-first sequence are editorial additions for practical support use.
  • Microsoft reference: Troubleshooting TCP/IP — Windows troubleshooting tools (accessed October 2026). This page is not Microsoft-endorsed.

Scope: Syntax and available options can vary by Windows version, policy and privileges. Use command /? on the target system, follow organizational procedures and test the actual affected service.