Where should you start investigating a problem with your home network? I searched from the network cable to the webpage in the order of the five levels, and the reverse order took me three more days to mess around

last month, the desktop in the study had a temper—WeChat files would drop halfway through, webpages would spin in circles, and after ten seconds or so it would come back to life. My first reaction was DNS malfunction, so I switched between 223.5.5.5 and 119.29.29.29, but it didn't work. Cleared the browser cache again, but still no effect. By the third day, my wife reminded me, "Is your chair always grinding the wire?" I squatted down to check—the latch on the crystal head was already broken, the cable was so loose you could pull it out by hand, and every time the chair wheels grinded, the contact was broken once again.
put his head down again, and everything was fine. What I did during those three days was: started investigating from the very top, and the higher I went, the slower it . To change DNS, you have to try it step by step in the background; to clear cache, you have to restart your browser; and to check a single cable, you only need to crouch down for two seconds. Later, I fixed the order of inspections at home, dividing them into five checkpoints, passing from bottom to top, so I never took another detour. These five levels are called layered models in textbooks. You don't need to memorize the names, just remember what each stage handles.
First Stage: Whether the Road Works or Not — Network Cables, Signals, Electrical
the very bottom of the checkpoint is the "carrier": whether the signal has a physical path to follow. Network cables, connectors, WiFi signals, device power supply—all of these matters. The advantage of its problems is that it's easy to detect, but the downside is that people are easiest to overlook—because people always think, 'As for the network cable, just plug it in and it's fine.'
the loosened crystal head at my house is a typical example: it stays plugged in but not securely. To judge whether this is a challenge, look at three points. First, check the icon: the Windows taskbar's network icon shows a red cross, indicating this level; The yellow exclamation mark may not be true, so don't jump to conclusions yet. Second, check the router background: log in to 192.168.31.1 and check the device list. You can instantly see if the machine is still in the list and if its online time has just reset to zero. Disconnection records are easy to see at a glance. Third, check the WiFi signal: Check the signal strength at the location where the phone occurs. Below -70 dBm is the edge position, so switching between onand off is very normal.
this step has the lowest verification cost, so always check first: replace the confirmed network cable, or move the device to the router and connect it again. There will definitely be an answer within two minutes. How to use your own line gauge when the wire in the wall breaks? I wrote an article about using an eight-lamp line gauge to find a breakpoint I also noted down the technique and sequence of the crystal head thread six scrap presses, .
Second Challenge: Does the Community Recognize You—WiFi Authentication and Address
the path is open, and the second customs control "entry." You connect to WiFi, the network cable plugs into the switch—that's just physically enough. The network still recognizes you: Is your WiFi password correct? Does the router remember your network card? Did it send you the house number? Handing out address numbers is done by DHCP. once, I accidentally turned off DHCP, and the whole house lost internet on the spot. That was the most severe fault type of this checkpoint.
this level has a golden checkpoint: IP addresses starting with 169.254 . Windows found a placeholder at home to use first, which means DHCP didn't issue the address at all. The problem lies in the lower two levels, so don't touch DNS. ipconfig is just a quick glance, it takes ten seconds.
there's a hidden bug in this level: 'door number collision': two devices use the same IP and intermittently connect, with PING intermittent and sometimes inactive. My cousin's NAS and the new TV box had a phone number overlap. arp -a checked and saw that the MAC address after the same IP was changing, which was confirmed on the spot . The solution is simple: the router's backend fixes all resident devices statically, solving the problem once and for all.
Third checkpoint: Is the exit gate opened—IP, gateway, router
The first two rounds are about your own neighborhood, and the third round starts with going out. The 'gate to your home's community' network is the gateway, usually the router itself; "Navigation routes" are simply routing tables. When this level went wrong, the symptoms were especially clear: the whole community was fine, but I just couldn't get out of the . LAN devices can find each other, NAS can connect, printers can connect, but none of the external networks can reach, and WeChat is gray too.
verification is simple: first ping the gateway, then ping an external IP address. ping 192.168.31.1 indicates that the previous two gates and the gateway itself are basically clean; Then ping 223.5.5.5, 'pass' means the door is open and the road is open. The problem lies in the two closures above; If it doesn't work, the problem is locked at the third level. This 'internal and external pincer attack' ping method I explained in my ping article why it effective.
the two most common pitfalls in the third level. First, when manually entering an IP, the gateway field is written incorrectly or left blank. The symptom is 'All connections within the same subnet but all outbound cells are disconnected.' I've written about what exactly or incorrect gateways what to fill in. Second, the router table mixed in with someone else's default router. After uninstalling the VPN, they didn't clear it properly, and all the data was flooded into a dead end. A glance at the route print showed that the extra line was the real culprit. I've been stuck in this trap all night .
Fourth Step: Can Letters Be Sent Out—TCP, UDP, and Ports
door is out, and the fourth gate is about 'how to send it.' For the same letter, TCP is like a registered mail, and the recipient must sign for it; Going UDP is like stuffing it into a mailbox—throw it out and you don't care. these two sending methods, each home application uses its own : web pages and WeChat files use TCP, while game voice and video calls use UDP. So this level has a distinctive symptom— pick bad : webpages open instantly, game voice lines freeze to electronic audio; Or conversely, the game is no-login, but the webpage is completely white.
in this stage's home scenario, the top suspect is the port. Ports are sorting slots on devices. Who set the numbers 3389 and 5005 and how to check conflicts? I've covered in the ports section. The easiest way to run into a service when installing your own PC is to run into 8080 when another program takes over it, the newly installed service won't start no matter what, and netstat -ano checks and the PID occupying the port is the culprit by following the trail. Another hidden role is MTU. The package is too big to pass through the tunnel, with the symptom "small packets all work, but large files and images can't be sent." This was discussed in detail before when talking about MTU, so I won't repeat it here.
the home verification method for this level is simple: switch devices for comparison. If your phone data is working fine but the same app fails on WiFi, your problem is below level four; If two devices on the same network are faulty and the other is good, it's usually the faulty firewall or port of the one that failed.
Fifth Hurdle: Didn't Handle the Tasks in the Letter—DNS, HTTP, and Caching
letter arrived, and the last section was about 'opening the letter to handle affairs.' Changing the URL to IP is DNS work; retrieving pages is HTTP work; retrieving old pages is caching work. This is the level everyone loves to mess with the most, and it's also the one I most want to advise: don't start by touching it right . My three days of detours started from this checkpoint, and the direction was completely reversed.
But when it really reaches this stage, the symptoms are easier to recognize. WeChat can log in, web pages won't open—classic DNS signatures—WeChat records direct IP connections, webpages need to check address books. Query the domain name to check if the resolution timed out and if the returned IP is correct. DNS I ran through the middle steps with nslookup and just follow them. After changing the EastThing, the webpage is still the same—the cache just keeps refusing to leave. F5 and Ctrl+F5 are not the same thing. How do you clear all four layers of cache one by one? I cleared it once and recorded the .
this level also has a high-risk area for wrongful convictions: the website itself is down. The errors on 502 and 504 are the webmaster's fault. If all five checkpoints at home are fine, wait ten minutes or try another website to prove it. Don't reset the router just because it won't turn on—that's the most costly move.
Five Consecutive Checks: I Saved Up the Order into a Set
the reasoning is explained, and now the work is ready to copy. I ran each of these five levels on my study computer, from start to finish in less than three minutes, leaving a fastest verification method for each level:
- first check: check the device list: check if the router's device list is in the backend, replug the network cable tightly, and wait two minutes;
- Second check: Check the address in ipconfig, check the IP. Issues starting with 169.254 are below. Normally, go down to 31.x;
- Third check: Clear the first two checks, then ping 223.5.5.5. If clear, you'll be fine when you leave.
- Fourth checkpoint: Try switching devices or using data on your phone to test the same app—good or bad is clear;
- fifth checkpoint: nslookup: domain resolution is normal, then consider caching and the website itself.
really runs the numbers: it takes just over one millisecond from my study to the gateway, TCP to 223.5.5.5 in fifteen milliseconds, DNS resolution in twelve milliseconds, and a green light all the way. If one day a certain number suddenly becomes timer, the timing will pop out on its own, much more reliable than it feels.
| symptoms | which level are most likely to get stuck on | actions to do first |
| red cross on icons, device list disappearing | first level | reconnect the network cable, replace it with a good one |
| IP starting with 169.254 | turn off the first and second | replug the cable, and check if DHCP is turned on |
| ping gateway is blocked | the first and second | switch cables and switch WiFi; once connected |
| the gateway is connected, but the external IP is blocked | third level | check the routing table and check dialing status |
| external IP connection, domain name not opening | fifth level | nslookup check resolution |
| pick the faulty application, everything else is fine | Fourth checkpoint | Change device for comparison and port |
order mnemonic is simple: first check the line, then ping the door; after leaving the door, check the . The underlying logic of bottom-up searches is cost—the lower the level, the cheaper the verification action: one line takes two seconds, one DNS takes ten minutes. Of course, this sequence manages chronic diseases that "suddenly broke down for no reason." If all the devices in the house go down at the same time, there's no need for inspection—it's usually just a modem, overdue bills, or a regional malfunction. the emergency outage ledger is more more targeted, so use both together.
