How Traceroute Works
Traceroute is a network diagnostic tool that maps the path packets take from your computer to a destination. It reveals every router (hop) along the way, helping you identify where slowdowns or failures occur.
The TTL Mechanism
Traceroute exploits the Time-To-Live (TTL) field in IP packets:
- Send a packet with TTL=1 → the first router decrements it to 0, drops the packet, and sends back an ICMP "Time Exceeded" message revealing its IP
- Send a packet with TTL=2 → gets past the first router, the second router responds
- Repeat with increasing TTL until the destination is reached
Reading Traceroute Output
1 192.168.1.1 1.2ms 0.9ms 1.1ms
2 10.0.0.1 5.4ms 5.1ms 5.3ms
3 203.0.113.1 12.3ms 11.8ms 12.1ms
4 * * *
5 8.8.8.8 15.2ms 14.9ms 15.0ms- Each line is a hop (router) along the path
- Three timing values show round-trip time for three probes
* * *means the router didn't respond (firewall or configured to ignore)- Large jumps in latency indicate the geographic or network distance between hops
Traceroute vs Ping
Ping tells you if a destination is reachable and how long it takes. Traceroute shows you the entire path. Use ping for quick connectivity checks; use traceroute to diagnose where a problem occurs.
Common Issues
- Asterisks (*): Routers configured to not respond — not necessarily a problem
- High latency at one hop: That router may be congested or geographically distant
- Loops: Packets cycling between routers indicate a routing misconfiguration
- Destination unreachable: The final destination isn't responding
Variants
- traceroute (Unix): Uses UDP packets by default
- tracert (Windows): Uses ICMP echo requests
- mtr: Combines traceroute and ping into a real-time display
- Paris traceroute: Avoids per-flow load balancing artifacts