Your First Lab — Make Two Servers Talk
Hyperscaler Network Engineer · Module 1: Data Centers from Zero
Lesson 7 of 8
Prerequisites: What Is a Network, Really?, IP Addresses and Subnets for Absolute Beginners
What you'll be able to do: Give two servers their addresses, knock on one's door from the other, and diagnose exactly why a knock goes unanswered.
Moving into a new apartment, you knock on your neighbor's door. A knock comes back — good, someone's home. Silence could mean they're out. Or it could mean you knocked on the wrong door. Or the hallway between you is blocked.
Computers knock on each other's doors all day, millions of times, and "nobody answered" is the single most common clue in every network investigation you'll ever run. Learning to knock — and learning to read the difference between "not home" and "wrong hallway" — is your first real lab skill.
Here's the puzzle.
Scenario. Two servers, Host A and Host B, sit in the same rack, plugged into the same switch. You gave Host A the address 10.0.0.10/24 and Host B the address 10.0.0.200/25 — note the masks differ. You knock from A to B and hear… nothing. The website demo is in an hour, and "nobody answered" isn't a diagnosis.
Given artifacts. The lab topology (hover each device), the address assignments, the routing tables, the failed knock, and a 6-packet capture excerpt:
Host A — address assignment:
eth0: 10.0.0.10/24
Host A — routing table (where A believes it can reach):
10.0.0.0/24 dev eth0 → "everyone from 10.0.0.0 to 10.0.0.255 is my hallway neighbor"
Host B — address assignment:
eth0: 10.0.0.200/25
Host B — routing table:
10.0.0.128/25 dev eth0 → "my hallway is only 10.0.0.128 to 10.0.0.255"
(no other routes — B knows no way out of its hallway)
The failed knock, typed on Host A:
$ ping -c 5 10.0.0.200
PING 10.0.0.200 (10.0.0.200) 56(84) bytes of data.
--- 10.0.0.200 ping statistics ---
5 transmitted, 0 received, 100% packet loss, time 4096ms
Your task: Name the misconfigured parameter, give the ONE command that fixes it, and name the capture packet number (in S5) that proves where the conversation breaks.
Workspace: Analyze-and-answer. Three text boxes: (1) the misconfigured parameter (e.g. "the ___ on Host ___"), (2) the single fix command, (3) the packet number and one sentence on what it proves. Recorded, never graded.
Hint 1 — where to look
The capture shows A's side working perfectly — shouts heard, requests on the wire. So the fault isn't A, the cable, or the switch. Compare what B believes about the network — its routing table — with where A actually lives.Hint 2 — what to compare
B's routing table says its hallway is 10.0.0.128/25 — addresses .128 through .255. Host A lives at 10.0.0.10. Is .10 inside B's hallway? What does a host do with a knock from someone it believes lives in a different building?Hint 3 — the mechanism
A host only answers directly to senders it considers local hallway neighbors. If the sender looks like a stranger from another building — and there's no gateway to send the reply through — the reply dies silently inside B. Nothing appears on the wire. Which setting controls what B considers "local"?Commitment ritual: ☐ "I've attempted this challenge and thought it through." Check the box (your answers above are recorded either way) and the worked answer in S7 reveals. Nothing is graded — the struggle is the point.
Checking the box reveals the worked answer in S7 below. Returning learners stay unlocked.
Giving a machine its street address
A server doesn't know its address out of the box — you have to tell it. On Linux, the command is ip addr add, and it takes the address plus the mask together: ip addr add 10.0.0.10/24 dev eth0 says "this network card is 10.0.0.10, and its hallway is the whole /24." The mask isn't decoration — it becomes the machine's belief about who its neighbors are. Get the mask wrong and the machine misjudges every conversation it has, as you're about to see.
Why this matters for the challenge: someone typed a mask for Host B. That single number is the entire fault — find it and you've found the bug.
The knock and the knock-back
Once two machines have addresses, the simplest possible conversation is the ping (a tiny "are you there?" message — one packet out, one packet back). Underneath, ping uses ICMP echo (the internet's knock-and-answer mechanism: an "echo request" packet asks "are you there?", and the other machine must send an "echo reply"). If the reply comes back, the machine is alive and reachable. If nothing comes back, you learn the most useful fact in networking: where the silence starts.
Why this matters for the challenge: the exhibit shows 5 transmitted, 0 received. The silence itself is the clue — your job is to locate exactly where it starts.
"Who has this address?" — asking the hallway
Here's a subtlety: to send anything to a neighbor, a machine needs more than the neighbor's street address — it needs the neighbor's hardware address, the physical "door number" on the network card. So before the first knock, Host A shouts to the whole hallway: "Who has 10.0.0.200?" That shout is an ARP request (a broadcast question — "who owns this address?" — sent to every machine in the hallway), and Host B's ARP reply ("10.0.0.200 is at my hardware address") completes the introduction. In plain English: ARP is asking the hallway "which door belongs to this apartment number?" — and every conversation between neighbors starts with it.
Why this matters for the challenge: the capture shows ARP succeeding. That single fact eliminates the cable, the switch, and Host A's address as suspects — narrowing the fault to one remaining place.
Reading the reply time
When pings succeed, each reply carries a time: time=0.421 ms. That number is the round-trip time (RTT) (how long the knock took to go there and back — the hallway's latency, measured in thousandths of a second). On a local switch it's a fraction of a millisecond; across an ocean it's a tenth of a second or more. Engineers read RTT the way a doctor reads a pulse: steady and low is healthy, spiking or missing means something's wrong between you and the other end.
Why this matters for the challenge: you don't get RTTs here — you get silence. But knowing what a healthy knock looks like tells you how much is missing.
"Nobody answered" vs. "wrong hallway"
Not all silences are equal. If A knocks and the wire is broken, nothing moves at all — not even ARP. If A knocks and B receives but can't reply, you'll see A's requests marching out on the wire with no answers coming back — the onesided conversation in your capture. And if B believes A lives in a different building, B looks for a gateway to send the reply through; with no gateway configured, the reply dies quietly inside B — no error message, no packet, just absence. That's the cruelest failure in networking: everything looks connected, and the evidence of the fault is a packet that was never sent.
Why this matters for the challenge: the capture's one-sided conversation plus B's routing table is the complete fingerprint of this exact failure. We'll name it in the worked answer.
- Step 1 of 5: Host A wants to knock but doesn't know B's hardware address, so it broadcasts an ARP request — the orange "?" that expands to fill the whole hallway. Everyone hears it.
- Step 2 of 5: Only Host B answers: an ARP reply (green "!") carrying B's hardware address travels straight back to A. Now A knows exactly which door to knock on.
- Step 3 of 5: A sends the ICMP echo request (yellow "→") — the actual knock — addressed to B's hardware address. No more shouting; this one is point to point.
- Step 4 of 5: B sends the echo reply (green "←"). Knock answered — and the reply's travel time becomes the RTT you read in the ping output.
- Step 5 of 5: In the challenge, steps 1–3 happen perfectly and step 4 never does. A one-sided conversation means the fault is at B's decision to reply — not on the wire.
ARP + ICMP on the 2-host lab link (challenge capture)
green = healthy/expected · red = problem packet(s) · amber = noteworthy, not faulty · untinted = context
| No | Time | Source | Destination | Protocol | Length | Info |
|---|---|---|---|---|---|---|
| 1 | 0.000 | 02:42:0a:00:00:0a | ff:ff:ff:ff:ff:ff | ARP | 42 | Who has 10.0.0.200? Tell 10.0.0.10 |
| 2 | 0.001 | 02:42:0a:00:00:c8 | 02:42:0a:00:00:0a | ARP | 42 | 10.0.0.200 is at 02:42:0a:00:00:c8 |
| 3 | 0.002 | 10.0.0.10 | 10.0.0.200 | ICMP | 98 | Echo (ping) request id=1 seq=1 |
| 4 | 1.003 | 10.0.0.10 | 10.0.0.200 | ICMP | 98 | Echo (ping) request id=1 seq=2 |
| 5 | 2.004 | 10.0.0.10 | 10.0.0.200 | ICMP | 98 | Echo (ping) request id=1 seq=3 |
| 6 | 3.005 | 10.0.0.10 | 10.0.0.200 | ICMP | 98 | Echo (ping) request id=1 seq=4 |
| 7 | 0.002 | 10.0.0.200 | 10.0.0.10 | ICMP | 98 | Echo (ping) reply id=1 seq=1 (captured after the S7 fix) |
Step 1 of 4 · packets 1, 2: Host A doesn't know B's hardware address, so it shouts to the whole hallway (packet 1, broadcast). B answers directly (packet 2). ARP works — the wire, the switch, and A's address are all fine.
Step 2 of 4 · packets 3: A's echo request is well-formed and on the wire (packet 3, amber). A's half of the conversation is proven healthy — the knock is reaching B's door.
Step 3 of 4 · packets 6: Four requests in, zero replies (packet 6, red). The conversation is one-sided: B receives the knocks and never answers. The fault is B's decision, not A's wire.
Step 4 of 4 · packets 7: After the fix (see S7), the echo reply finally flows (packet 7, green) — the recovery packet. Compare it against the worked answer to see what changed on B.
| No | Time | Source | Destination | Protocol | Length | Info |
|---|---|---|---|---|---|---|
| 1 | 0.000 | 02:42:0a:00:00:0a | ff:ff:ff:ff:ff:ff | ARP | 42 | Who has 10.0.0.200? Tell 10.0.0.10 |
| 2 | 0.001 | 02:42:0a:00:00:c8 | 02:42:0a:00:00:0a | ARP | 42 | 10.0.0.200 is at 02:42:0a:00:00:c8 |
| 3 | 0.002 | 10.0.0.10 | 10.0.0.200 | ICMP | 98 | Echo (ping) request id=1 seq=1 |
| 4 | 1.003 | 10.0.0.10 | 10.0.0.200 | ICMP | 98 | Echo (ping) request id=1 seq=2 |
| 5 | 2.004 | 10.0.0.10 | 10.0.0.200 | ICMP | 98 | Echo (ping) request id=1 seq=3 |
| 6 | 3.005 | 10.0.0.10 | 10.0.0.200 | ICMP | 98 | Echo (ping) request id=1 seq=4 |
| 7 | 0.002 | 10.0.0.200 | 10.0.0.10 | ICMP | 98 | Echo (ping) reply id=1 seq=1 (captured after the S7 fix) |
Fixture: hand-authored to illustrate ARP resolution followed by one-sided ICMP echo; no production data
Platform: Linux (iproute2)
# PLAIN-ENGLISH: give Host A's network card the address 10.0.0.10, hallway = whole /24 (neighbors .0–.255)
sudo ip addr add 10.0.0.10/24 dev eth0
# PLAIN-ENGLISH: bring the network card up so it can actually send and receive
sudo ip link set eth0 up
# PLAIN-ENGLISH: knock on Host B's door 5 times and report which knocks got answers
ping -c 5 10.0.0.200
⚠️ Remove this, break that: without
ip addr add, the host has no address at all — every packet fails before it starts, and even ARP can't go out.
Platform: Linux (iproute2)
# PLAIN-ENGLISH: give Host B the address 10.0.0.200 — but the /25 mask is WRONG (see callout below)
sudo ip addr add 10.0.0.200/25 dev eth0
# PLAIN-ENGLISH: bring the network card up
sudo ip link set eth0 up
⚠️ Remove this, break that: this is the line that's wrong in the challenge —
/25makes B believe its hallway is only 10.0.0.128–.255, so it treats 10.0.0.10 as a stranger from another building. With no gateway to send the reply through, B silently drops it. Symptom: 100% packet loss with perfectly healthy ARP.
🔒 Revealed after the commitment ritual in S2 — attempt the challenge first. (Honor system: the page hides this until you check the box.)
Step 1 — Trust the capture, eliminate the obvious. Packets 1–2 show ARP succeeding: A shouted, B answered. That single fact kills three suspects at once — the cable, the switch, and Host A's address are all working. You might have suspected the switch first (it's the box in the middle) — here's the evidence ruling it out: B's ARP reply crossed it cleanly.
Step 2 — Read the one-sided conversation. Packets 3–6 are A's echo requests marching out with zero replies. A's half is proven healthy (packet 3 is well-formed and on the wire), so the silence starts at B. You might have suspected A's mask — but A's /24 covers 10.0.0.200, and the capture shows A's requests leaving correctly. A is innocent.
Step 3 — Ask what B believes. B's routing table says its hallway is 10.0.0.128/25 — addresses .128 through .255. Host A lives at 10.0.0.10. Is .10 inside .128–.255? No. So when A's knock arrives, B thinks: "this came from another building." B looks for a gateway to route the reply through — there is none — and drops the reply silently, inside its own network stack. Nothing appears on the wire. That's why the capture shows requests but no replies and no error: the fault is a belief, and beliefs don't emit packets.
Step 4 — Name it and fix it. The misconfigured parameter is Host B's subnet mask: /25 instead of /24. One command fixes it:
--- Host B (broken)
+++ Host B (fixed)
- sudo ip addr add 10.0.0.200/25 dev eth0
# PLAIN-ENGLISH: replace the address keeping .200 but widening the hallway to the full /24, so B recognizes .10 as a neighbor
+ sudo ip addr replace 10.0.0.200/24 dev eth0
Verify it worked: on Host A, run the knock again:
$ ping -c 4 10.0.0.200
PING 10.0.0.200 (10.0.0.200) 56(84) bytes of data.
64 bytes from 10.0.0.200: icmp_seq=1 ttl=64 time=0.312 ms
64 bytes from 10.0.0.200: icmp_seq=2 ttl=64 time=0.298 ms
64 bytes from 10.0.0.200: icmp_seq=3 ttl=64 time=0.305 ms
64 bytes from 10.0.0.200: icmp_seq=4 ttl=64 time=0.290 ms
--- 10.0.0.200 ping statistics ---
4 transmitted, 4 received, 0% packet loss, time 3003ms
Expected: 4 received, 0% packet loss, and capture packet 7 (the echo reply) now appears on the wire. The proving packet from the challenge is packet 6 — four requests, zero replies: A's healthy knocks with B's missing answers, locating the break at B's reply decision.
Check yourself — nothing here is graded. Wrong answers are the useful ones; each explains why.
Question 1. Host A (10.0.0.10/24) ARPs for 10.0.0.200 and gets a reply, but pings get no answer. What does the successful ARP prove?
Question 2. Why does Host B (10.0.0.200/25, no gateway) stay silent instead of sending an error back to A?
Question 3. What does `ping` actually measure when it reports `time=0.312 ms`?
Question 4. After fixing B's mask to /24, the first ping still shows 100% loss for 2 seconds, then replies start arriving. What happened?
Question 5. New symptom, same lab: you rebuild both hosts from scratch. Now Host A is 10.0.0.10/24, Host B is 10.0.0.200/24, and the ping works — but only every *other* reply arrives (50% packet loss, steady). ARP is clean. What do you check first?
- A mask is a belief about who your neighbors are — and a host that believes you're a stranger won't answer your knock.
- ARP is the hallway introduction ("who has this address?"); if it succeeds, the wire, switch, and sender are eliminated as suspects.
- A one-sided capture — requests marching out, no replies — locates the fault at the receiver's decision, not on the wire.
- With no gateway, a host that considers you remote can't reply at all — the reply dies silently inside it, leaving no error behind.
- RTT is there-and-back travel time: steady and low is healthy, missing entirely means something between you and the far end is wrong.
Next: Module Capstone — Draw and Defend Your First Mini Data Center — you've toured the kitchen, met the staff, and learned the recipes; now design your own restaurant: two racks, twelve servers, and a floor plan you can defend.