Super Traceroute
Enhanced traceroute mapping every hop to its ASN and organization. Visualize the AS-PATH your traffic takes across the internet.
Traceroute runs server-side. Results may differ from your local machine.
Advertisement · Anuncio
Traceroute is a network diagnostic tool that maps the path packets take from your machine to a destination host. It sends packets with incrementally increasing TTL (Time To Live) values. Each router decrements the TTL and, when it reaches zero, returns an ICMP "time exceeded" message, revealing that router's IP address and round-trip time.
An Autonomous System (AS) is a collection of IP networks under the control of a single organization with a unified routing policy. Each AS has a globally unique ASN (Autonomous System Number). The internet is essentially a network of ASes connected via BGP (Border Gateway Protocol). Every traceroute hop that crosses an AS boundary represents your traffic moving between different network operators.
The AS-PATH shows which autonomous systems your traffic traverses. A short AS-PATH (2–3 ASes) means well-peered networks with direct connections. Many AS hops may indicate indirect routing through transit providers. Traffic between major CDNs and cloud providers often stays within 1–2 AS hops due to extensive private peering agreements.
A hop showing * means no ICMP response was received within the timeout period. This can mean the router rate-limits or drops ICMP packets for security reasons, the packet was lost, or the router is configured not to respond to TTL-exceeded messages. Silent hops are common in large ISP backbone networks and do not necessarily indicate a problem.
BGP (Border Gateway Protocol) is the routing protocol that connects autonomous systems across the internet. It exchanges reachability information between ASes, allowing routers to determine the best path to any destination. BGP is policy-based: operators prefer routes based on peering agreements, cost, and performance rather than just hop count or latency.
Why does traceroute show different results each run?
Load balancers and ECMP (Equal-Cost Multi-Path) routing can send packets on different paths, causing hop variation between runs.
Why is the server-side result different from mine?
The traceroute originates from our server, not your machine. Traffic from different locations takes different BGP paths.
What does RTT tell me?
RTT (Round-Trip Time) measures latency to each hop. Sudden increases indicate congested links or geographic distance jumps.
Expert guide · Super Traceroute
Technical background
Traceroute exploits the IP Time To Live field. Every router that forwards a packet decrements the TTL (the Hop Limit in IPv6) by one, and when it reaches zero the router discards the packet and returns an ICMP Time Exceeded message, type 11 code 0 in RFC 792. By sending probes with TTL 1, 2, 3 and so on, and recording who replies and how long it took, traceroute reconstructs the forward path hop by hop. The classic Unix implementation, which this tool runs on its Linux server, sends UDP datagrams to high destination ports starting at 33434; the destination host replies with ICMP Port Unreachable, which marks the end of the trace. Windows tracert uses ICMP Echo Requests instead, and TCP traceroute sends SYN packets to a real service port such as 443, which is the most reliable way through firewalls that drop UDP and ICMP.
Reading the output correctly requires knowing what routers prioritise. Forwarding happens in hardware, but generating ICMP replies is done by the router's control plane, which is rate-limited and low priority. A hop that shows 180 ms while the next hops show 40 ms is not slow; it simply answered late. Likewise a row of asterisks in the middle of a path that still reaches the destination means that router does not answer probes, not that traffic is lost there. Only latency or loss that begins at a hop and persists through every later hop, including the target, is meaningful.
The path you see is only half the story. Internet routing is frequently asymmetric: the reply from each router, and the traffic back from the destination, can return over a completely different set of networks chosen by other operators' BGP policies. A high RTT at a hop can come from the return path, which traceroute cannot show; a trace from the destination back toward you is needed for a full picture. Equal-cost multipath load balancing (ECMP) can also send successive probes through parallel links, so adjacent hops may appear to come from different routers.
Some hops are invisible by design. MPLS networks can be configured not to propagate the IP TTL into the label stack, so an entire carrier backbone collapses into one apparent hop with a large latency jump. Routers that do expose MPLS hops may include label information through ICMP extensions (RFC 4950). Tunnels, VPNs and some cloud fabrics behave similarly.
The ASN column is derived from public BGP data, the same source used for RPKI origin validation (RFC 6811), and tells you which organization announces the prefix containing each hop. Interconnect links between two networks are often numbered from one party's address space, so the AS change can appear one hop earlier or later than the real boundary. For safety, this service refuses private (RFC 1918), loopback, link-local and other reserved targets.
Common errors and how to fix them
- Problem The tool replies 'Private, loopback, reserved or unresolvable targets are not allowed'.
- Fix The target resolved to an RFC 1918, loopback, link-local or other reserved address, or did not resolve at all. Trace internal hosts from a machine inside your network, and check that public hostnames have a public A record.
- Problem The trace ends in a series of asterisks and never reaches the destination.
- Fix A firewall near the target drops UDP probes or ICMP replies. That does not mean the service is down; test the actual port with a TCP traceroute (traceroute -T -p 443) or a TCP connection check.
- Problem One middle hop shows very high latency or 100% loss but later hops are fine.
- Fix That router deprioritises or rate-limits ICMP generation. Ignore it unless the higher latency or loss continues through every later hop to the destination.
- Problem Latency jumps by 100 ms or more between two adjacent hops.
- Fix Check the ASN and location: it is often a long-haul or submarine link, or an MPLS core hiding intermediate hops. If the jump is not explained by distance and persists to the end, collect a trace in both directions and send it to the network that owns the hop where it starts.
- Problem Your own traceroute and this one show different paths.
- Fix They start in different networks, so BGP selects different routes, and ECMP can vary between runs. Compare the AS sequence near the destination, which usually converges, rather than the first hops.
Do it from the command line
macOS
# Same parameters as this tool: numeric, 1 probe, 2 s wait, 20 hops
traceroute -n -q 1 -w 2 -m 20 example.com
# ICMP Echo probes instead of UDP
traceroute -I -n example.com
# IPv6 path
traceroute6 -n example.comWindows
# ICMP-based trace without reverse DNS, 20 hops, 2 s timeout
tracert -d -h 20 -w 2000 example.com
# Per-hop loss statistics over time
pathping -n example.com
# PowerShell equivalent
Test-NetConnection example.com -TraceRouteLinux
# Default UDP traceroute as run by this tool
traceroute -n -q 1 -w 2 -m 20 example.com
# TCP SYN to port 443 to pass firewalls
sudo traceroute -T -p 443 -n example.com
# Continuous trace with loss stats and AS numbers
mtr -rwzbc 100 example.comMore questions about Super Traceroute
What do asterisks (* * *) mean in traceroute?
No reply arrived for that probe within the timeout. Most often the router is configured not to send ICMP Time Exceeded messages, or it rate-limits them. If later hops and the destination respond, the asterisks are harmless. Only when every hop after a certain point shows asterisks is something blocking or dropping traffic.
Why does a hop in the middle show higher latency than the destination?
Routers forward traffic in hardware but answer traceroute probes with their slower, rate-limited control plane, so a hop can respond late while forwarding at full speed. The reply may also return over a different, longer path than the forward one. Trust latency that persists to the final hop.
What is the difference between traceroute and tracert?
Both rely on TTL expiry. Unix and macOS traceroute send UDP probes to high ports by default and can switch to ICMP (-I) or TCP (-T on Linux); Windows tracert always uses ICMP Echo Requests. Different probe types can be filtered differently, so the same destination may trace further with one method than another.
Why can't I traceroute to a private IP address with this tool?
The trace runs from our server, not your computer, so a private address like 192.168.1.1 would point at our own infrastructure, not your router. Blocking private, loopback and reserved targets also prevents the tool from being abused to scan internal networks. Run traceroute locally for hosts inside your LAN.
Why are some network hops missing from the path?
Carrier backbones using MPLS often do not copy the IP TTL into labels, so the whole core appears as a single hop with a big latency step. Tunnels, VPNs and some cloud networks behave the same way. Routers that are silent to probes also leave gaps, shown as asterisks.