Linux traceroute Command: Trace Routers on the Way to a Host

traceroute investigates the routers along the path to a destination by gradually increasing the TTL or hop limit. It is used to check where delays or response interruptions occur.

What is the traceroute command?

The response of each hop is the result sent by that router to the diagnostic packet and does not indicate the definitive path of actual application traffic. The typical Linux implementation of traceroute uses UDP probes by default, -I selects ICMP, and -T selects TCP probes. The available methods depend on the implementation and permissions.

Basic syntax

traceroute [options] destination

The installed implementation and options may vary depending on the distribution. Check the description for your current system with man traceroute.

Examples

Basic path tracing

Check each step of the path and the response times.

traceroute example.com

View in numeric addresses

Focus on the path itself by excluding DNS reverse lookup time.

traceroute -n example.com

Select ICMP probe

When responses are limited in the basic UDP method, compare using other methods.

traceroute -I example.com

When interpreting hop-by-hop responses

traceroute investigates the hops to the destination using probe packets with varying TTLs. The following is an example output in numerical IP format to reduce DNS reverse lookup delays.

traceroute -n example.com

Example of output structure (actual route and times vary each time):

1  192.0.2.1  1.0 ms  0.9 ms  1.1 ms
2  * * *

Each line represents a hop, and the three values are the round-trip times of multiple probes. * indicates that there was no response for that probe, and if subsequent hops continue to appear, only that hop may be limiting responses. Since the path can be asymmetric, do not determine a faulty device based solely on this result.

Main Options and Format

Options/Format Description
-n Display addresses as numbers.
-I Use ICMP Echo probes.
-T Use TCP probes.
-m hop Limit the maximum number of hops.
-q count Specify the number of probes sent per hop.
-w time Adjust the response waiting time.

Precautions when using

Even if a * appears at one hop, if the subsequent hops continue to appear, it may only be that the diagnostic response of that router is restricted. Do not conclude a bottleneck solely from an increase in RTT for one segment; compare it with the responses of the final destination and repeated measurements. Some probing methods may require additional privileges.

Frequently Asked Questions

If a middle hop is shown as *, does that mean the packet was dropped there?

No. That router may not have sent or may have restricted the TTL expiration response. Observe the subsequent hops and destination responses together.

Official Documentation

You can check the exact behavior of the options and the differences in implementation in the official traceroute documentation.

More in This Category
Linux find Command: Search Files by Name, Type, Size, and Time

Linux find Command: Search Files by Name, Type, Size, and Time

Learn how to search with Linux find by name, file type, size, and modification time, combine expressions, run commands safely, and verify targets before deletion.

Linux cd Command: Change the Current Directory

Linux cd Command: Change the Current Directory

Learn how to use the Linux cd command to move between directories using absolute, relative, home, and previous paths, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux uptime Command: Check Uptime and Load Averages

Linux uptime Command: Check Uptime and Load Averages

Learn how to use the Linux uptime command to check how long the system has been running and interpret load averages, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux uniq Command: Remove or Count Adjacent Duplicate Lines

Linux uniq Command: Remove or Count Adjacent Duplicate Lines

Learn how to remove or count adjacent duplicate lines with the Linux uniq command, including practical examples, key options, and important precautions.

Linux Tutorial / File Types and Metadata: ls, file, stat, and readlink

Linux Tutorial / File Types and Metadata: ls, file, stat, and readlink

Learn what ls, file, stat, and readlink each reveal about a Linux file, including type, size, timestamps, and symbolic-link targets.

Linux journalctl Command: Read systemd Logs

Linux journalctl Command: Read systemd Logs

Learn how to read systemd Logs with the Linux journalctl command, including practical examples, key options, and important precautions.

Linux ssh-keygen Command: Generate SSH Keys and Inspect Fingerprints

Linux ssh-keygen Command: Generate SSH Keys and Inspect Fingerprints

Learn how to generate SSH Keys and Inspect Fingerprints with the Linux ssh-keygen command, including practical examples, key options, and important precautions.

A History of Linux: From a 1991 Hobby Project to Global Infrastructure

A History of Linux: From a 1991 Hobby Project to Global Infrastructure

Trace the history of Linux from Unix and the GNU Project through the first Linux kernel, distributions, enterprise adoption, cloud computing, containers, and modern infrastructure.

Linux modinfo Command: Inspect Kernel Module Details

Linux modinfo Command: Inspect Kernel Module Details

Learn how to inspect Kernel Module Details with the Linux modinfo command, including practical examples, key options, and important precautions.

Linux ps Command: Inspect Running Processes

Linux ps Command: Inspect Running Processes

Learn how to inspect Running Processes with the Linux ps command, including practical examples, key options, and important precautions.