Linux traceroute Command: Trace Routers on the Way to a Host
traceroute investigates the routers along the path to a destination by gradually increasing the TTL or hop limit. It is used to check where delays or response interruptions occur.
What is the traceroute command?
The response of each hop is the result sent by that router to the diagnostic packet and does not indicate the definitive path of actual application traffic. The typical Linux implementation of traceroute uses UDP probes by default, -I selects ICMP, and -T selects TCP probes. The available methods depend on the implementation and permissions.
Basic syntax
traceroute [options] destination
The installed implementation and options may vary depending on the distribution. Check the description for your current system with man traceroute.
Examples
Basic path tracing
Check each step of the path and the response times.
traceroute example.com
View in numeric addresses
Focus on the path itself by excluding DNS reverse lookup time.
traceroute -n example.com
Select ICMP probe
When responses are limited in the basic UDP method, compare using other methods.
traceroute -I example.com
When interpreting hop-by-hop responses
traceroute investigates the hops to the destination using probe packets with varying TTLs. The following is an example output in numerical IP format to reduce DNS reverse lookup delays.
traceroute -n example.com
Example of output structure (actual route and times vary each time):
1 192.0.2.1 1.0 ms 0.9 ms 1.1 ms 2 * * *
Each line represents a hop, and the three values are the round-trip times of multiple probes. * indicates that there was no response for that probe, and if subsequent hops continue to appear, only that hop may be limiting responses. Since the path can be asymmetric, do not determine a faulty device based solely on this result.
Main Options and Format
| Options/Format | Description |
|---|---|
-n |
Display addresses as numbers. |
-I |
Use ICMP Echo probes. |
-T |
Use TCP probes. |
-m hop |
Limit the maximum number of hops. |
-q count |
Specify the number of probes sent per hop. |
-w time |
Adjust the response waiting time. |
Precautions when using
Even if a * appears at one hop, if the subsequent hops continue to appear, it may only be that the diagnostic response of that router is restricted. Do not conclude a bottleneck solely from an increase in RTT for one segment; compare it with the responses of the final destination and repeated measurements. Some probing methods may require additional privileges.
Frequently Asked Questions
If a middle hop is shown as *, does that mean the packet was dropped there?
No. That router may not have sent or may have restricted the TTL expiration response. Observe the subsequent hops and destination responses together.
Official Documentation
You can check the exact behavior of the options and the differences in implementation in the official traceroute documentation.









