A real-life situation
A branch office can't reach a partner's server. Ping only says "Request timed out", which tells you the traffic is lost somewhere, but not where. You run traceroute and see the path stop right after your own edge router. Now you know which device to investigate.
What traceroute is
Traceroute lists every router (every hop) on the way to a destination, with a response time for each one. On Windows, the command is tracert. On Linux, macOS and Cisco IOS it is traceroute.
It uses the TTL (time to live) field in the IP header. TTL is a counter that each router lowers by 1. When it reaches 0, the router drops the packet and sends back an ICMP Time Exceeded message. That message comes from the router's own IP address, so traceroute learns which router it is.
- 1. TTL 1: R1 lowers the TTL to 0, drops the probe and returns Time Exceeded. Hop 1 = R1.
- 2. TTL 2: R1 forwards the probe; R2 lowers the TTL to 0 and replies. Hop 2 = R2.
- 3. TTL 3: R1 and R2 forward it; R3 lowers the TTL to 0 and replies. Hop 3 = R3.
- 4. TTL 4: The probe reaches the server, which replies itself. The trace is complete.
The TTL trick, step by step
Every IP packet carries a TTL so that it can't loop forever. Traceroute uses this safety feature on purpose:
- Send probes with TTL 1. The first router (your default gateway) lowers the TTL to 0, drops the probe and sends an ICMP Time Exceeded message (type 11) back. The source address of that message is the router's address. Hop 1 found.
- Measure the time. Traceroute records how long each answer took. It sends three probes per hop, so you see three times.
- Send probes with TTL 2. Router 1 lowers the TTL to 1 and forwards the probe. Router 2 lowers it to 0, drops the probe and replies. Hop 2 found.
- Keep going, adding 1 to the TTL each round: 3, 4, 5…
- Reach the destination. The probe now arrives with a TTL still above 0, so the target itself answers: with an echo reply (Windows, ICMP probes) or with ICMP Port Unreachable (Linux, UDP probes to a closed port). This different answer tells traceroute that it has arrived, so it stops.
- Or give up after the maximum number of hops (30 by default).
1. Probe TTL 1 · Echo request · TTL 1
R1 lowers the TTL to 0 and drops it.
A hop is one router on the path. The address shown for a hop is normally the address of the interface the router used to send the Time Exceeded message (usually the interface facing you). These intermediate routers don't know they are being traced. They are simply applying the same TTL rule they apply to every packet.
Windows, Linux and Cisco differences
Windows tracert | Linux / macOS traceroute | Cisco IOS traceroute | |
|---|---|---|---|
| Probe type | ICMP echo | UDP to high ports (use -I for ICMP) | UDP to high ports |
| Probes per hop | 3 | 3 | 3 |
| Skip name lookups | tracert -d | traceroute -n | traceroute 203.0.113.80 numeric |
| Destination port | None (ICMP has no ports) | Starts at UDP 33434 and goes up by one per probe | Starts at UDP 33434 |
| How it knows it arrived | ICMP echo reply (type 0) | ICMP port unreachable (type 3, code 3) | ICMP port unreachable |
| Maximum hops | 30 (-h to change) | 30 (-m to change) | 30 |
The probe type matters because a firewall may allow one type and block the other. If tracert and traceroute show different results to the same place, this is usually why.
Reading the output
C:\> tracert -d 203.0.113.80 Tracing route to 203.0.113.80 over a maximum of 30 hops 1 1 ms <1 ms 1 ms 192.168.10.1 2 9 ms 8 ms 9 ms 198.51.100.1 3 * * * Request timed out. 4 * * * Request timed out. 5 * * * Request timed out.
198.51.100.1. That router may have no route onward, the next link may be down, or a firewall beyond it may be dropping the probes.$ traceroute -n 203.0.113.80 traceroute to 203.0.113.80 (203.0.113.80), 30 hops max, 60 byte packets 1 192.168.10.1 0.812 ms 0.701 ms 0.689 ms 2 198.51.100.1 8.934 ms 8.871 ms 9.102 ms 3 * * * 4 203.0.113.80 12.410 ms 12.388 ms 12.502 ms
Why some hops show *
A * means that one probe got no answer before the time limit (about 4 seconds on Windows and 5 seconds on Linux). The usual reasons are:
- The router doesn't send Time Exceeded messages at all. Some operators turn them off.
- ICMP rate limiting. Routers limit how many ICMP messages they generate per second, to protect their CPU. Three probes sent in quick succession can hit the limit, giving one or two stars on a line.
- Filtering. A firewall on the path drops the probes (for example, it blocks UDP to high ports) or drops the ICMP replies on their way back.
- A real break. The path stops there because there is no route onward or a link is down. Every hop after it then shows stars too.
Why stars and timings can fool you
- Stars in the middle, then replies again: that hop ignores or rate-limits traceroute probes. Traffic still passes through it.
- Stars from one hop to the end: the path really stops there, or a firewall blocks the probes from that point on.
- One hop with a high time, later hops normal: the router was slow to answer, not slow to forward. Routers give low priority to creating their own ICMP replies.
- Times jump up and stay high: a real delay starts at that hop, for example a long-distance or congested link.
The Cisco output below is based on Cisco documentation, not run on a lab device.
R1#traceroute 203.0.113.80 numeric Type escape sequence to abort. Tracing the route to 203.0.113.80 VRF info: (vrf in name/id, vrf out name/id) 1 198.51.100.1 8 msec 9 msec 8 msec 2 198.51.100.9 11 msec 10 msec 11 msec 3 203.0.113.80 12 msec * 12 msec
* on line 3 is one probe with no answer, often caused by rate limiting. The destination 203.0.113.80 still answered, so the path works. Press Ctrl+Shift+6 to stop a trace that keeps going.What a broken path looks like
The real value of traceroute is showing where things go wrong. Two patterns are worth knowing:
C:\> tracert -d 203.0.113.80 Tracing route to 203.0.113.80 over a maximum of 30 hops 1 1 ms <1 ms 1 ms 192.168.10.1 2 12 ms 11 ms 12 ms 198.51.100.1 3 198.51.100.1 reports: Destination net unreachable. Trace complete.
C:\> tracert -d 203.0.113.80 Tracing route to 203.0.113.80 over a maximum of 30 hops 1 1 ms <1 ms 1 ms 192.168.10.1 2 9 ms 8 ms 9 ms 198.51.100.1 3 10 ms 10 ms 11 ms 198.51.100.9 4 11 ms 10 ms 11 ms 198.51.100.1 5 12 ms 11 ms 12 ms 198.51.100.9 6 13 ms 12 ms 13 ms 198.51.100.1
On Windows, pathping combines traceroute with a longer ping test to every hop and shows the packet loss at each one. On Linux, mtr does the same thing and updates live.
Common mistakes
- Reading stars as a failure when later hops still answer. Only stars that continue to the end of the trace point to a real problem.
- Blaming a hop that shows one high time. Routers give low priority to answering traceroute. Only a jump that stays high for every later hop is a real delay.
- Forgetting the probe type. A firewall that allows ICMP but blocks UDP makes Linux traceroute fail where Windows tracert works.
- Assuming the return path is the same. Traceroute only maps the path towards the destination, not the way back.
- Waiting for name lookups. Reverse DNS lookups for every hop slow the trace down. Use
tracert -dortraceroute -nto get results much faster.
- Traceroute sends probes with TTL 1, 2, 3 and so on; each router that drops one answers with ICMP Time Exceeded.
- Each line is one hop (router), with three round-trip times.
- Windows
tracertuses ICMP echo; Linux/macOStracerouteuses UDP to high ports by default. - Stars in the middle usually mean a silent or rate-limited router; stars to the end mean the path really stops.
- Repeating addresses mean a routing loop.
Check yourself
You run traceroute and hop 2 shows the address of a router two hops away. What made that router send back an ICMP Time Exceeded message?
Hop 4 shows * * *, but hops 5 and 6 reply and the trace reaches the server. What do you conclude?
You run traceroute on a Linux server with its default UDP probes. Which message tells it that it has reached the destination?
A trace shows 198.51.100.1 and 198.51.100.9 alternating until hop 30. What is wrong?
Related lessons
Traceroute is built on the TTL field and on ICMP Time Exceeded messages. Use it after ping tells you a path is broken, then check the router it points to.
Learn more: RoutersIP and Gateway Problems