Packet Path/

Your First Lab — Make Two Servers Talk

Hyperscaler Network Engineer · Module 1: Data Centers from Zero

Lesson 7 of 8

Foundations⏱ 45 min

Prerequisites: What Is a Network, Really?, IP Addresses and Subnets for Absolute Beginners

What you'll be able to do: Give two servers their addresses, knock on one's door from the other, and diagnose exactly why a knock goes unanswered.

Moving into a new apartment, you knock on your neighbor's door. A knock comes back — good, someone's home. Silence could mean they're out. Or it could mean you knocked on the wrong door. Or the hallway between you is blocked.

Computers knock on each other's doors all day, millions of times, and "nobody answered" is the single most common clue in every network investigation you'll ever run. Learning to knock — and learning to read the difference between "not home" and "wrong hallway" — is your first real lab skill.

Here's the puzzle.

Scenario. Two servers, Host A and Host B, sit in the same rack, plugged into the same switch. You gave Host A the address 10.0.0.10/24 and Host B the address 10.0.0.200/25 — note the masks differ. You knock from A to B and hear… nothing. The website demo is in an hour, and "nobody answered" isn't a diagnosis.

Given artifacts. The lab topology (hover each device), the address assignments, the routing tables, the failed knock, and a 6-packet capture excerpt:

Host A — address 10.0.0.10/24. The knocker. Its routing table says the whole 10.0.0.0–255 hallway is local.Host A10.0.0.10/24 Switch S1 — a simple hallway switch. It forwards everything; it is not the suspect.S1switch Host B — address 10.0.0.200/25. The silent one. Its routing table says its hallway is only 10.0.0.128–255.Host B10.0.0.200/25
Host A — address assignment:
  eth0: 10.0.0.10/24
Host A — routing table (where A believes it can reach):
  10.0.0.0/24 dev eth0   →  "everyone from 10.0.0.0 to 10.0.0.255 is my hallway neighbor"

Host B — address assignment:
  eth0: 10.0.0.200/25
Host B — routing table:
  10.0.0.128/25 dev eth0  →  "my hallway is only 10.0.0.128 to 10.0.0.255"
  (no other routes — B knows no way out of its hallway)

The failed knock, typed on Host A:
  $ ping -c 5 10.0.0.200
  PING 10.0.0.200 (10.0.0.200) 56(84) bytes of data.

  --- 10.0.0.200 ping statistics ---
  5 transmitted, 0 received, 100% packet loss, time 4096ms

Your task: Name the misconfigured parameter, give the ONE command that fixes it, and name the capture packet number (in S5) that proves where the conversation breaks.

Workspace: Analyze-and-answer. Three text boxes: (1) the misconfigured parameter (e.g. "the ___ on Host ___"), (2) the single fix command, (3) the packet number and one sentence on what it proves. Recorded, never graded.

Hint 1 — where to look The capture shows A's side working perfectly — shouts heard, requests on the wire. So the fault isn't A, the cable, or the switch. Compare what B believes about the network — its routing table — with where A actually lives.
Hint 2 — what to compare B's routing table says its hallway is 10.0.0.128/25 — addresses .128 through .255. Host A lives at 10.0.0.10. Is .10 inside B's hallway? What does a host do with a knock from someone it believes lives in a different building?
Hint 3 — the mechanism A host only answers directly to senders it considers local hallway neighbors. If the sender looks like a stranger from another building — and there's no gateway to send the reply through — the reply dies silently inside B. Nothing appears on the wire. Which setting controls what B considers "local"?

Commitment ritual: ☐ "I've attempted this challenge and thought it through." Check the box (your answers above are recorded either way) and the worked answer in S7 reveals. Nothing is graded — the struggle is the point.

Checking the box reveals the worked answer in S7 below. Returning learners stay unlocked.

Giving a machine its street address

A server doesn't know its address out of the box — you have to tell it. On Linux, the command is ip addr add, and it takes the address plus the mask together: ip addr add 10.0.0.10/24 dev eth0 says "this network card is 10.0.0.10, and its hallway is the whole /24." The mask isn't decoration — it becomes the machine's belief about who its neighbors are. Get the mask wrong and the machine misjudges every conversation it has, as you're about to see.

Why this matters for the challenge: someone typed a mask for Host B. That single number is the entire fault — find it and you've found the bug.

The knock and the knock-back

Once two machines have addresses, the simplest possible conversation is the ping (a tiny "are you there?" message — one packet out, one packet back). Underneath, ping uses ICMP echo (the internet's knock-and-answer mechanism: an "echo request" packet asks "are you there?", and the other machine must send an "echo reply"). If the reply comes back, the machine is alive and reachable. If nothing comes back, you learn the most useful fact in networking: where the silence starts.

Why this matters for the challenge: the exhibit shows 5 transmitted, 0 received. The silence itself is the clue — your job is to locate exactly where it starts.

"Who has this address?" — asking the hallway

Here's a subtlety: to send anything to a neighbor, a machine needs more than the neighbor's street address — it needs the neighbor's hardware address, the physical "door number" on the network card. So before the first knock, Host A shouts to the whole hallway: "Who has 10.0.0.200?" That shout is an ARP request (a broadcast question — "who owns this address?" — sent to every machine in the hallway), and Host B's ARP reply ("10.0.0.200 is at my hardware address") completes the introduction. In plain English: ARP is asking the hallway "which door belongs to this apartment number?" — and every conversation between neighbors starts with it.

Why this matters for the challenge: the capture shows ARP succeeding. That single fact eliminates the cable, the switch, and Host A's address as suspects — narrowing the fault to one remaining place.

Reading the reply time

When pings succeed, each reply carries a time: time=0.421 ms. That number is the round-trip time (RTT) (how long the knock took to go there and back — the hallway's latency, measured in thousandths of a second). On a local switch it's a fraction of a millisecond; across an ocean it's a tenth of a second or more. Engineers read RTT the way a doctor reads a pulse: steady and low is healthy, spiking or missing means something's wrong between you and the other end.

Why this matters for the challenge: you don't get RTTs here — you get silence. But knowing what a healthy knock looks like tells you how much is missing.

"Nobody answered" vs. "wrong hallway"

Not all silences are equal. If A knocks and the wire is broken, nothing moves at all — not even ARP. If A knocks and B receives but can't reply, you'll see A's requests marching out on the wire with no answers coming back — the onesided conversation in your capture. And if B believes A lives in a different building, B looks for a gateway to send the reply through; with no gateway configured, the reply dies quietly inside B — no error message, no packet, just absence. That's the cruelest failure in networking: everything looks connected, and the evidence of the fault is a packet that was never sent.

Why this matters for the challenge: the capture's one-sided conversation plus B's routing table is the complete fingerprint of this exact failure. We'll name it in the worked answer.

Host A10.0.0.10/24 Host B10.0.0.200/24 ? ! → ← A shouts "Who has 10.0.0.200?" to the whole hallway… healthy conversation shown — in the challenge, the last two packets never come back
  1. Step 1 of 5: Host A wants to knock but doesn't know B's hardware address, so it broadcasts an ARP request — the orange "?" that expands to fill the whole hallway. Everyone hears it.
  2. Step 2 of 5: Only Host B answers: an ARP reply (green "!") carrying B's hardware address travels straight back to A. Now A knows exactly which door to knock on.
  3. Step 3 of 5: A sends the ICMP echo request (yellow "→") — the actual knock — addressed to B's hardware address. No more shouting; this one is point to point.
  4. Step 4 of 5: B sends the echo reply (green "←"). Knock answered — and the reply's travel time becomes the RTT you read in the ping output.
  5. Step 5 of 5: In the challenge, steps 1–3 happen perfectly and step 4 never does. A one-sided conversation means the fault is at B's decision to reply — not on the wire.

ARP + ICMP on the 2-host lab link (challenge capture)

green = healthy/expected · red = problem packet(s) · amber = noteworthy, not faulty · untinted = context

NoTimeSourceDestinationProtocolLengthInfo
10.00002:42:0a:00:00:0aff:ff:ff:ff:ff:ffARP42Who has 10.0.0.200? Tell 10.0.0.10
20.00102:42:0a:00:00:c802:42:0a:00:00:0aARP4210.0.0.200 is at 02:42:0a:00:00:c8
30.00210.0.0.1010.0.0.200ICMP98Echo (ping) request id=1 seq=1
41.00310.0.0.1010.0.0.200ICMP98Echo (ping) request id=1 seq=2
52.00410.0.0.1010.0.0.200ICMP98Echo (ping) request id=1 seq=3
63.00510.0.0.1010.0.0.200ICMP98Echo (ping) request id=1 seq=4
70.00210.0.0.20010.0.0.10ICMP98Echo (ping) reply id=1 seq=1 (captured after the S7 fix)

Fixture: hand-authored to illustrate ARP resolution followed by one-sided ICMP echo; no production data

Platform: Linux (iproute2)

# PLAIN-ENGLISH: give Host A's network card the address 10.0.0.10, hallway = whole /24 (neighbors .0–.255)
sudo ip addr add 10.0.0.10/24 dev eth0
# PLAIN-ENGLISH: bring the network card up so it can actually send and receive
sudo ip link set eth0 up
# PLAIN-ENGLISH: knock on Host B's door 5 times and report which knocks got answers
ping -c 5 10.0.0.200

⚠️ Remove this, break that: without ip addr add, the host has no address at all — every packet fails before it starts, and even ARP can't go out.

Platform: Linux (iproute2)

# PLAIN-ENGLISH: give Host B the address 10.0.0.200 — but the /25 mask is WRONG (see callout below)
sudo ip addr add 10.0.0.200/25 dev eth0
# PLAIN-ENGLISH: bring the network card up
sudo ip link set eth0 up

⚠️ Remove this, break that: this is the line that's wrong in the challenge — /25 makes B believe its hallway is only 10.0.0.128–.255, so it treats 10.0.0.10 as a stranger from another building. With no gateway to send the reply through, B silently drops it. Symptom: 100% packet loss with perfectly healthy ARP.

🔒 The worked answer is hidden until you commit...

Check yourself — nothing here is graded. Wrong answers are the useful ones; each explains why.

Question 1. Host A (10.0.0.10/24) ARPs for 10.0.0.200 and gets a reply, but pings get no answer. What does the successful ARP prove?

Question 2. Why does Host B (10.0.0.200/25, no gateway) stay silent instead of sending an error back to A?

Question 3. What does `ping` actually measure when it reports `time=0.312 ms`?

Question 4. After fixing B's mask to /24, the first ping still shows 100% loss for 2 seconds, then replies start arriving. What happened?

Question 5. New symptom, same lab: you rebuild both hosts from scratch. Now Host A is 10.0.0.10/24, Host B is 10.0.0.200/24, and the ping works — but only every *other* reply arrives (50% packet loss, steady). ARP is clean. What do you check first?

Next: Module Capstone — Draw and Defend Your First Mini Data Center — you've toured the kitchen, met the staff, and learned the recipes; now design your own restaurant: two racks, twelve servers, and a floor plan you can defend.