---
title: "How to use traceroute to find routing problems | StreetHosting"
description: "Use traceroute on Linux and tracert on Windows, understand the asterisks and find out whether latency climbs at home, at your ISP, in transit or at the end."
url: "https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute"
type: "page"
language: "en-US"
---

Infrastructure · 8 min · Intermediate

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# Traceroute and tracert: read the route and tell local, transit and destination problems apart

Traceroute lists every router between you and the server and how long each one takes to answer. Read the right way, it shows whether the delay starts at your home, at your ISP, between networks or at the destination.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking) [Latency and ping](https://streethosting.com.br/en/guides/topics/latency) [Linux administration](https://streethosting.com.br/en/guides/topics/linux) [Windows and RDP](https://streethosting.com.br/en/guides/topics/windows)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=How%20to%20use%20traceroute%20to%20find%20routing%20problems&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute "Share on LinkedIn") [](https://wa.me/?text=How%20to%20use%20traceroute%20to%20find%20routing%20problems%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fhow-to-use-traceroute "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute.md)

In this guide 7 sections

* [How traceroute works](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#como-funciona)
* [Running it on Windows, Linux and Mac](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#rodar)
* [How to read the output](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#ler-saida)
* [What the asterisks mean](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#asteriscos)
* [Local, ISP, transit or destination](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#trechos)
* [Reading pitfalls](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#armadilhas)
* [Traceroute from the server side](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#onde-rodar)

Quick answer

To **use traceroute**, run `tracert -d IP` on Windows or `traceroute -n IP` on Linux. Each line is a router on the path, with three time measurements. Look for the first hop where latency climbs and stays high until the destination: at hop 1 the problem is your local network, on the ISP hops it is the internet provider, where networks hand off it is transit and on the last hops it is the destination. Isolated asterisks do not indicate a problem.

## How traceroute works[](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#como-funciona)

Every IP packet carries a counter called TTL (Time To Live). Each router that forwards the packet decrements that number by 1, and when it hits zero the router drops the packet and sends an ICMP time exceeded message back to the source. The mechanism exists to stop packets from circulating forever in a routing loop.

Traceroute uses that to its advantage. It sends a packet with TTL 1, and the first router answers. It sends one with TTL 2, and the second router answers. And so on until the destination answers or the 30 hop limit is reached. Each hop gets three probes, and each probe's time is the round trip to that router and back to you.

The type of packet changes with the system and the option. The result is almost always the same, but a firewall that blocks one type lets another through, so it is worth knowing how to switch:

| Command              | Probe type                           | When to use it                       |
| -------------------- | ------------------------------------ | ------------------------------------ |
| tracert (Windows)    | ICMP echo                            | Windows default                      |
| traceroute (Linux)   | UDP on high ports, starting at 33434 | Linux default                        |
| traceroute -I        | ICMP echo, like Windows              | Compare with the Windows result      |
| traceroute -T -p 443 | TCP SYN on the given port            | Destination that blocks ICMP and UDP |
| traceroute -U        | UDP on a fixed port, 53 by default   | Test the path of a UDP service       |
| tracepath            | UDP, no root needed                  | Also discover the path MTU           |

## Running it on Windows, Linux and Mac[](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#rodar)

On Windows, tracert is already installed. Open Command Prompt or PowerShell and run it with `-d`, which skips name resolution and makes the test much faster:

`tracert -d IP_DO_DESTINO tracert -d -h 40 IP_DO_DESTINO # raises the hop limit`

On Ubuntu, install the traceroute package. TCP mode needs sudo, and ICMP mode does too in most setups, because both open raw sockets:

`sudo apt install traceroute traceroute -n IP_DO_DESTINO # UDP, default sudo traceroute -n -I IP_DO_DESTINO # ICMP sudo traceroute -n -T -p 443 IP_DO_DESTINO # TCP on port 443 tracepath -n IP_DO_DESTINO # no root, shows the MTU`

On Mac, traceroute ships with the system, uses UDP by default and accepts `-I` for ICMP. `tracepath` deserves extra attention when the symptom is a connection that opens and then hangs, because it shows at which hop the maximum packet size drops, the subject of the guide on [MTU and fragmentation](https://streethosting.com.br/en/guides/infrastructure/what-is-mtu).

## How to read the output[](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#ler-saida)

An illustrative tracert, with documentation addresses, from a home connection to a server:

`Rastreando a rota para 203.0.113.10 com no máximo 30 saltos 1 <1 ms <1 ms <1 ms 192.168.0.1 2 3 ms 2 ms 3 ms 100.72.0.1 3 4 ms 4 ms 5 ms 198.51.100.9 4 * * * Esgotado o tempo limite do pedido. 5 17 ms 18 ms 17 ms 192.0.2.33 6 18 ms 18 ms 19 ms 203.0.113.10 Rastreamento concluído.`

* **First column:** the hop number, which is the TTL used in that round.
* **Three times:** one measurement per probe. Similar values indicate a stable segment; very different values indicate variation.
* **Address:** the router that answered. Without `-d` or `-n`, the reverse name also shows up, which usually carries the ISP's name and a city code.

In this example, hop 2 is in the 100.64.0.0/10 range, which shows the connection goes through [the ISP's CGNAT](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat). Hop 4 did not answer, but hops 5 and 6 did, so it is just a router that does not return ICMP. Latency rises from 4 to 17 ms between hops 3 and 5 and stays stable up to the destination: that is the cost of the segment between the ISP and the next network, and there is no sign of a problem.

## What the asterisks mean[](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#asteriscos)

An asterisk means the probe got no reply within the timeout. What it means depends on where it appears and how many there are:

* **One asterisk between two times:**a probe that was lost or dropped by the router's reply rate limit. Ignore it.
* **A whole hop of asterisks and normal hops after it:** the router forwards the traffic but does not generate the ICMP time exceeded message, or a filter drops that reply. Ignore it.
* **Asterisks from one point to the end of the list:** the destination, or a firewall in front of it, drops the type of probe being used. If the service works, it is just filtering; repeat with `-T -p` and the service port to see the full path.
* **Asterisks at the end and the service also down:** now there is a real break. The last hop that answered shows how far the traffic gets, and that is where support starts looking.

## Local, ISP, transit or destination[](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#trechos)

The question traceroute really answers is which segment the latency shows up in. The rule is to find the first hop where the time rises and stays high on every hop after it. The increase belongs to the link that arrives at that hop. Then work out who owns that segment:

| Segment                   | How to recognize it                                                          | Common causes                                                      | Who fixes it                          |
| ------------------------- | ---------------------------------------------------------------------------- | ------------------------------------------------------------------ | ------------------------------------- |
| Local network             | Hop 1, with an IP like 192.168.x.x or 10.x.x.x                               | Wi-Fi, bad cable, overloaded router, saturated upload              | You                                   |
| ISP access                | Hops 2 to 4, sometimes with a 100.64.x.x IP and the ISP's domain in the name | Regional congestion, ISP equipment                                 | Your ISP's support                    |
| ISP core                  | Same domain and same AS, names with city codes                               | Long route inside the network, full outbound link at peak          | Your ISP's support                    |
| Transit or exchange point | The domain and the AS change from one hop to the next                        | Congestion between networks, route through another city or country | The ISP or the destination's provider |
| Destination network       | Last two or three hops, with the server provider's domain                    | Datacenter network, firewall, overloaded server                    | The server provider                   |

Reverse names help place the route. Many ISPs use airport codes in router names, such as gru or sao for São Paulo, gig or rio for Rio de Janeiro, poa for Porto Alegre, for for Fortaleza and mia for Miami. There is no mandatory standard, so treat it as a clue. A jump from 10 to over 100 ms when the name starts pointing to Miami shows the traffic left the country. If the server is in Brazil, that is a bad route and worth a ticket with the ISP with the traceroute attached.

Between Brazilian networks, traffic usually meets at the IX.br exchange points, run by NIC.br, whose largest location is in São Paulo. That is why the server's location weighs so heavily on the number of hops and on latency for a domestic audience, a criterion discussed in [how to choose a datacenter in Brazil](https://streethosting.com.br/en/guides/infrastructure/how-to-choose-a-data-center-in-brazil).

## Reading pitfalls[](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#armadilhas)

Almost every wrong traceroute diagnosis falls into one of these situations:

1. **A spike on a single hop.** If hop 6 shows 80 ms and hop 7 goes back to 20 ms, hop 6 was just slow to generate the ICMP reply. Real traffic did not go through that delay.
2. **Several IPs on the same hop.** Networks with route load balancing send each probe down a parallel path, and the same hop number shows different routers. That is normal.
3. **Several hops with the same high latency.** In MPLS networks, the ICMP reply from internal routers can travel to the end of the tunnel before coming back to you, and a run of hops shows up with the same time as the last one.
4. **Private IPs in the middle of the path.**10.x or 172.16.x addresses inside the ISP's network are common and do not indicate an error.
5. **A different return route.**Traceroute shows the outbound path. Each hop's reply comes back along whatever path that network chooses, and a problem on the way back shows up in your test without the culprit being listed.
6. **A snapshot of one moment.** Three probes per hop do not catch an intermittent problem. A clean traceroute run after the incident does not prove the network was fine during it.

For the last two items, traceroute is not enough. [MTR](https://streethosting.com.br/en/guides/infrastructure/how-to-use-mtr) measures each hop continuously and accumulates loss and variation, and a complete diagnosis includes a test run from the server back to you.

## Traceroute from the server side[](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#onde-rodar)

When a player or customer complains about slowness, their traceroute shows the outbound path. What is missing is the way back, from the server to them. With a [StreetHosting VPS](https://streethosting.com.br/en/vps) you get root to install traceroute, use the TCP and ICMP modes and compare both directions on the spot. The VPS machines are in São Paulo, with a 1 Gbps uplink and Anti-DDoS included.

* **Game server:** the [Ryzen 9 9950X VPS](https://streethosting.com.br/en/vps/ryzen) ranges from R$ 40.00 (1 vCPU, 2 GB DDR5, 20 GB NVMe) to R$ 846.00 (14 vCPU, 64 GB, 640 GB NVMe), with clock speeds up to 5.7 GHz.
* **Websites, APIs and bots:** the Xeon VPS starts at R$ 26.00 with 2 vCPU and 2 GB and goes up to R$ 553.00 with 24 vCPU and 64 GB.

Before you sign up, you can measure from the cities where your audience is. The step-by-step, with ping, MTR and tests from several regions, is in [how to test a VPS's latency](https://streethosting.com.br/en/guides/vps/test-vps-latency).

In this guide

* [How traceroute works](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#como-funciona)
* [Running it on Windows, Linux and Mac](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#rodar)
* [How to read the output](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#ler-saida)
* [What the asterisks mean](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#asteriscos)
* [Local, ISP, transit or destination](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#trechos)
* [Reading pitfalls](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#armadilhas)
* [Traceroute from the server side](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute#onde-rodar)

## Frequently asked questions

What do the asterisks in traceroute mean?

Each asterisk is a probe that got no reply within the timeout. A whole hop of asterisks followed by hops that do answer is just a router that does not return the ICMP message, and it does not indicate a problem. Asterisks from the middle to the end of the list mean the destination or a firewall is dropping the type of probe being used.

What is the difference between tracert and traceroute?

They do the same thing. tracert is the Windows command and uses ICMP packets. Linux traceroute uses UDP by default and accepts ICMP with -I and TCP with -T, which helps when the destination blocks one of the types.

How can I tell from traceroute whether the problem is my internet?

Look at where latency climbs and stays high until the end. If hop 1, which is your router, already shows high or unstable times, the problem is the Wi-Fi or your home network. If the jump happens on hops carrying your ISP's name, the problem is theirs. If it happens on the last hops, it is the destination's network.

Why does traceroute stop in the middle and never reach the destination?

Most of the time, because the destination server or the firewall in front of it drops the type of packet traceroute uses. If the service works normally, the route is fine. Try another method, such as TCP on the service port, to see the full path.

Traceroute or MTR: which one should I use?

Use traceroute to see the path and MTR to measure its quality. Traceroute sends only three probes per hop and is a snapshot; MTR keeps measuring each hop for minutes and shows accumulated loss and variation, which is essential for intermittent problems.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen)

## Related guides

[Infrastructure Intermediate How to use MTR to diagnose network problems MTR combines traceroute and ping and shows, hop by hop, where latency climbs and where packets get lost. The trick is knowing which loss is real and which is just a router rationing its replies. 8 min Read guide](https://streethosting.com.br/en/guides/infrastructure/how-to-use-mtr) [Infrastructure Intermediate What is CGNAT and why it blocks your server With CGNAT, your ISP shares a single public IP among several customers and no connection from the outside ever reaches your home. Here is how to confirm whether that is your case and which workarounds actually work for hosting a server. 11 min Read guide](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat) [VPS Beginner How to test VPS latency from Brazil Good latency is the latency your users measure, not what you see from your own computer. Learn how to test with ping, TCP and MTR, how to measure from other cities without owning a machine there, and how to compare the numbers fairly. 9 min Read guide](https://streethosting.com.br/en/guides/vps/test-vps-latency)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
