Routelearn.net
Course menu

Unit 9: ICMP and Network TestingLesson 9.3 (3 of 3 in this unit)60 of 84 in the Network Fundamentals course

Traceroute: Finding the Path

Traceroute shows the routers between you and a destination. Learn the TTL trick it uses, step by step, how to read hops, times and stars, why some routers stay silent, and how Windows tracert (ICMP) differs from Linux traceroute (UDP).

Beginner · 14 min read · Before this: ICMP, Ping

Traceroute (tracert on Windows) is a diagnostic tool that lists the routers on the path to a destination by sending probes with a TTL (time to live) of 1, 2, 3 and so on. Each router that decrements a probe's TTL to zero discards it and returns an ICMP Time Exceeded message, revealing its address and the round-trip time.

In simple terms: Traceroute shows each router your traffic passes through on the way to a destination, one hop at a time, so you can see where along the path things slow down or stop.

A real-life situation

A branch office can't reach a partner's server. Ping only says "Request timed out", which tells you the traffic is lost somewhere, but not where. You run traceroute and see the path stop right after your own edge router. Now you know which device to investigate.

What traceroute is

Traceroute lists every router (every hop) on the way to a destination, with a response time for each one. On Windows, the command is tracert. On Linux, macOS and Cisco IOS it is traceroute.

It uses the TTL (time to live) field in the IP header. TTL is a counter that each router lowers by 1. When it reaches 0, the router drops the packet and sends back an ICMP Time Exceeded message. That message comes from the router's own IP address, so traceroute learns which router it is.

PCR1192.168.10.1R2198.51.100.1R3198.51.100.9Server203.0.113.80
  1. 1. TTL 1: R1 lowers the TTL to 0, drops the probe and returns Time Exceeded. Hop 1 = R1.
  2. 2. TTL 2: R1 forwards the probe; R2 lowers the TTL to 0 and replies. Hop 2 = R2.
  3. 3. TTL 3: R1 and R2 forward it; R3 lowers the TTL to 0 and replies. Hop 3 = R3.
  4. 4. TTL 4: The probe reaches the server, which replies itself. The trace is complete.

The TTL trick, step by step

Every IP packet carries a TTL so that it can't loop forever. Traceroute uses this safety feature on purpose:

  1. Send probes with TTL 1. The first router (your default gateway) lowers the TTL to 0, drops the probe and sends an ICMP Time Exceeded message (type 11) back. The source address of that message is the router's address. Hop 1 found.
  2. Measure the time. Traceroute records how long each answer took. It sends three probes per hop, so you see three times.
  3. Send probes with TTL 2. Router 1 lowers the TTL to 1 and forwards the probe. Router 2 lowers it to 0, drops the probe and replies. Hop 2 found.
  4. Keep going, adding 1 to the TTL each round: 3, 4, 5…
  5. Reach the destination. The probe now arrives with a TTL still above 0, so the target itself answers: with an echo reply (Windows, ICMP probes) or with ICMP Port Unreachable (Linux, UDP probes to a closed port). This different answer tells traceroute that it has arrived, so it stops.
  6. Or give up after the maximum number of hops (30 by default).
Step 1 of 6 · Probe TTL 1
tracert 203.0.113.80 · ICMP probes (Windows)
PC
192.168.10.25
R1
192.168.10.1
R2
198.51.100.1
Server
203.0.113.80

1. Probe TTL 1 · Echo request · TTL 1

R1 lowers the TTL to 0 and drops it.

Each round raises the TTL by one, so the next router along the path drops the probe and reveals itself.

A hop is one router on the path. The address shown for a hop is normally the address of the interface the router used to send the Time Exceeded message (usually the interface facing you). These intermediate routers don't know they are being traced. They are simply applying the same TTL rule they apply to every packet.

Windows, Linux and Cisco differences

Windows tracertLinux / macOS tracerouteCisco IOS traceroute
Probe typeICMP echoUDP to high ports (use -I for ICMP)UDP to high ports
Probes per hop333
Skip name lookupstracert -dtraceroute -ntraceroute 203.0.113.80 numeric
Destination portNone (ICMP has no ports)Starts at UDP 33434 and goes up by one per probeStarts at UDP 33434
How it knows it arrivedICMP echo reply (type 0)ICMP port unreachable (type 3, code 3)ICMP port unreachable
Maximum hops30 (-h to change)30 (-m to change)30

The probe type matters because a firewall may allow one type and block the other. If tracert and traceroute show different results to the same place, this is usually why.

Reading the output

Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
C:\> tracert -d 203.0.113.80
Tracing route to 203.0.113.80 over a maximum of 30 hops

  1     1 ms    <1 ms     1 ms  192.168.10.1
  2     9 ms     8 ms     9 ms  198.51.100.1
  3     *        *        *     Request timed out.
  4     *        *        *     Request timed out.
  5     *        *        *     Request timed out.
What to look for: hops 1 and 2 answer, but from hop 3 onward nothing comes back. The trouble is at or just after 198.51.100.1. That router may have no route onward, the next link may be down, or a firewall beyond it may be dropping the probes.
Example output · typical of Windows and Linux, written for this lesson, not captured from a real computer
$ traceroute -n 203.0.113.80
traceroute to 203.0.113.80 (203.0.113.80), 30 hops max, 60 byte packets
 1  192.168.10.1  0.812 ms  0.701 ms  0.689 ms
 2  198.51.100.1  8.934 ms  8.871 ms  9.102 ms
 3  * * *
 4  203.0.113.80  12.410 ms  12.388 ms  12.502 ms
What to look for: hop 3 shows stars, but the trace continues to the server at hop 4. That router simply isn't sending Time Exceeded messages (many are configured that way). It is not a fault.

Why some hops show *

A * means that one probe got no answer before the time limit (about 4 seconds on Windows and 5 seconds on Linux). The usual reasons are:

  • The router doesn't send Time Exceeded messages at all. Some operators turn them off.
  • ICMP rate limiting. Routers limit how many ICMP messages they generate per second, to protect their CPU. Three probes sent in quick succession can hit the limit, giving one or two stars on a line.
  • Filtering. A firewall on the path drops the probes (for example, it blocks UDP to high ports) or drops the ICMP replies on their way back.
  • A real break. The path stops there because there is no route onward or a link is down. Every hop after it then shows stars too.

Why stars and timings can fool you

  • Stars in the middle, then replies again: that hop ignores or rate-limits traceroute probes. Traffic still passes through it.
  • Stars from one hop to the end: the path really stops there, or a firewall blocks the probes from that point on.
  • One hop with a high time, later hops normal: the router was slow to answer, not slow to forward. Routers give low priority to creating their own ICMP replies.
  • Times jump up and stay high: a real delay starts at that hop, for example a long-distance or congested link.

The Cisco output below is based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#traceroute 203.0.113.80 numeric
Type escape sequence to abort.
Tracing the route to 203.0.113.80
VRF info: (vrf in name/id, vrf out name/id)
  1 198.51.100.1 8 msec 9 msec 8 msec
  2 198.51.100.9 11 msec 10 msec 11 msec
  3 203.0.113.80 12 msec *  12 msec
What to look for: each line is one hop, with three times in milliseconds. The single * on line 3 is one probe with no answer, often caused by rate limiting. The destination 203.0.113.80 still answered, so the path works. Press Ctrl+Shift+6 to stop a trace that keeps going.

What a broken path looks like

The real value of traceroute is showing where things go wrong. Two patterns are worth knowing:

Example output from a Windows PC, written for this lesson
C:\> tracert -d 203.0.113.80
Tracing route to 203.0.113.80 over a maximum of 30 hops

  1     1 ms    <1 ms     1 ms  192.168.10.1
  2    12 ms    11 ms    12 ms  198.51.100.1
  3   198.51.100.1  reports: Destination net unreachable.

Trace complete.
What to look for: the line 198.51.100.1 reports: Destination net unreachable. That router sent an ICMP Destination Unreachable message because it has no route to the destination network. Check that router's routing table.
Example output from a Windows PC, written for this lesson
C:\> tracert -d 203.0.113.80
Tracing route to 203.0.113.80 over a maximum of 30 hops

  1     1 ms    <1 ms     1 ms  192.168.10.1
  2     9 ms     8 ms     9 ms  198.51.100.1
  3    10 ms    10 ms    11 ms  198.51.100.9
  4    11 ms    10 ms    11 ms  198.51.100.1
  5    12 ms    11 ms    12 ms  198.51.100.9
  6    13 ms    12 ms    13 ms  198.51.100.1
What to look for: the same two addresses repeat until the 30-hop limit. That is a routing loop: each router thinks the other is the way to the destination. Real packets on this path bounce between them until their TTL runs out.

On Windows, pathping combines traceroute with a longer ping test to every hop and shows the packet loss at each one. On Linux, mtr does the same thing and updates live.

Common mistakes

  • Reading stars as a failure when later hops still answer. Only stars that continue to the end of the trace point to a real problem.
  • Blaming a hop that shows one high time. Routers give low priority to answering traceroute. Only a jump that stays high for every later hop is a real delay.
  • Forgetting the probe type. A firewall that allows ICMP but blocks UDP makes Linux traceroute fail where Windows tracert works.
  • Assuming the return path is the same. Traceroute only maps the path towards the destination, not the way back.
  • Waiting for name lookups. Reverse DNS lookups for every hop slow the trace down. Use tracert -d or traceroute -n to get results much faster.
✅ Key takeaways
  • Traceroute sends probes with TTL 1, 2, 3 and so on; each router that drops one answers with ICMP Time Exceeded.
  • Each line is one hop (router), with three round-trip times.
  • Windows tracert uses ICMP echo; Linux/macOS traceroute uses UDP to high ports by default.
  • Stars in the middle usually mean a silent or rate-limited router; stars to the end mean the path really stops.
  • Repeating addresses mean a routing loop.

Check yourself

Predict · scenario 1

You run traceroute and hop 2 shows the address of a router two hops away. What made that router send back an ICMP Time Exceeded message?

Predict · scenario 2

Hop 4 shows * * *, but hops 5 and 6 reply and the trace reaches the server. What do you conclude?

Predict · scenario 3

You run traceroute on a Linux server with its default UDP probes. Which message tells it that it has reached the destination?

Predict · scenario 4

A trace shows 198.51.100.1 and 198.51.100.9 alternating until hop 30. What is wrong?

Related lessons

Traceroute is built on the TTL field and on ICMP Time Exceeded messages. Use it after ping tells you a path is broken, then check the router it points to.

Learn more: RoutersIP and Gateway Problems

FAQ

Why do some hops show * * *?
No Time Exceeded message came back from that hop within the time limit. Usually the router is configured not to send them, it rate-limits them, or a firewall filters them. If later hops answer, traffic is passing through that hop normally. If every hop from there to the end shows stars, the path may really stop there.
Why do tracert and traceroute show different results?
Windows tracert sends ICMP echo requests, while Linux and macOS traceroute send UDP packets to high port numbers by default. A firewall may allow one and block the other, so the same path can look different. On Linux, traceroute -I uses ICMP, like Windows does.
Does traceroute show the return path?
No. It shows only the routers on the way to the destination. Replies may come back by a different path, which is one reason the times you see can be confusing.
How many hops can traceroute show?
By default, up to 30 hops on Windows, Linux and macOS. Most internet paths are roughly 8 to 20 hops long. You can raise the limit with tracert -h or traceroute -m.