How to Read a Traceroute: Every Hop, Every Asterisk, and When a Route Is Abnormal
2026-09-05 · undefined min
A traceroute answers the question that ping cannot: not just whether a destination is reachable, but which path the traffic takes to get there. It lists every router your packets pass through, one line at a time, with a round-trip time for each. The output looks like a simple numbered list, but each line is a clue about where on the internet your traffic slows down or stops.
The short version: read the latency, be skeptical of the asterisks, and notice when a hop looks private or repeats. Those three observations solve most routing questions.
1988
Traceroute is invented
Van Jacobson writes the first traceroute, using the TTL field to force routers to reveal themselves one hop at a time.
1990s
TTL-based probing becomes standard
The technique is formalized and built into every major OS, becoming the default tool for tracing network paths.
2000s
Modern networks complicate the picture
Load balancing, MPLS and tunnels make routes less linear, and many routers stop answering trace probes entirely.
Today
Reading routes with skepticism
Asterisks and silent hops are now so common that reading a traceroute means knowing which hops are trustworthy and which are not.
What each hop is telling you
Each numbered line is one router along the path. The first hops are almost always your own network - your router, then your ISP's edge. The middle hops are the long haul across the internet, and the final hops are the destination's network. The round-trip time on each line is how long a probe took to get to that router and come back.
Latency generally increases with distance, so a few extra milliseconds per hop is normal. A sudden jump - say, from 5ms to 90ms between two adjacent hops - often means the packets crossed a long distance, a congested peering point, or a different network entirely.
The asterisks: what a silent hop means
You will see asterisks (`* * *`) in place of a latency. This does not mean the route is broken. Many routers are configured to drop traceroute probes for security or to reduce load, so they simply do not answer. A missing reply is common and often tells you nothing about the health of the route.
A single asterisked hop between two responding hops is usually harmless. What matters is a pattern: if the destination itself returns asterisks but your traffic still works, the path is fine and the last router just does not answer probes. If the destination shows asterisks and traffic is broken, the silence is at the endpoint, not the path.
Traceroute reveals the path hop by hop, unlike a single ping which measures only the round trip to the destination.
Private, repeated and odd hops
You may see private addresses (like 192.168.x.x or 10.x.x.x) in the middle of a route. That is normal inside carrier networks using private addressing internally, or through a VPN. Seeing your own private address at the first hop is expected; seeing a private address deep in the route is a sign you are inside a tunnel or an ISP using carrier-grade NAT.
Repeated addresses are another clue. A router appearing twice in a row usually means load balancing between two paths, not a loop. A genuine loop - the same few addresses repeating endlessly until the traceroute hits its hop limit - is the real anomaly, and it means routing is broken.
When the route is actually abnormal
A traceroute is abnormal when the destination shows a high, consistent latency but the route between hops is clean, or when the route stops at a particular hop and never reaches the destination. The first case points to congestion or a slow server; the second points to a block or a failure at that specific hop.
The key is to compare the traceroute with the actual outcome. If the route looks clean but your connection is slow, the problem is not the path - it is the destination or your own network. If the route stops and traffic fails, the problem is at the last responding hop or beyond it.
要点总结
A traceroute is a map, not a verdict. Read the latency for clues, distrust the asterisks, and use the path to narrow the problem. Combined with a ping to the destination, it will tell you whether the fault is yours, your provider's, or the destination's - and where exactly it lives.
为防止滥用,请求会受到频率限制。此实例的运营者可以选择性地启用请求活动日志记录——如果启用,每次工具请求(您的 IP 地址、时间戳、使用的工具及输入的目标/查询内容)可能会被记录到数据库中,用于安全、防滥用和使用情况分析。此功能默认关闭。使用本网站即表示您同意上述条款;如果您不同意,请不要使用本网站。