skip to content

Time Exceeded and Traceroute

TTL hits zero, a router reports it, and traceroute turns those reports into a path map by raising TTL a hop at a time. How traceroute works and why some hops show stars are standard questions.

on this pageshow

questions

5

How does traceroute use the IPv4 TTL field and ICMP Time Exceeded messages to discover each router on a path?

level: middleimportance: must knowfreq 60%

answer

  1. make the packet die on purpose
  2. TTL 1, then 2, then 3
  3. the error's source address is the hop
  4. quoted header matches reply to probe
  5. a different reply marks the end

basics

~20 s

Traceroute sends probes with TTL 1, 2, 3 and upward. The router at hop n expires the TTL-n probe and returns ICMP Time Exceeded code 0 from its own address, so each reply names one hop until the destination answers.

solid answer

~50 s

Traceroute turns a safety rule into a measurement. It sends a probe with `TTL` 1: the first router reduces it to zero, discards it and, as RFC 1812 requires, returns ICMP type 11 code 0. The source address of that error identifies hop 1, and the time to the reply gives a round-trip estimate. It then sends TTL 2, TTL 3 and so on, usually a few probes per TTL. The error quotes the probe's IP header and first 8 payload bytes, so the tool matches each reply to the probe that caused it. The trace ends when the *destination* answers with something other than Time Exceeded — a port unreachable, an echo reply or a TCP SYN-ACK or RST, depending on the probe type — or when a maximum hop count is reached. It maps only the forward path, one probe at a time.

go deeper

for a junior

Recall the trick: send probes with TTL 1, 2, 3 and so on; each router that drops one answers with Time Exceeded, revealing itself. The destination answers differently and ends the trace.

for a middle

Walk through the mechanics: who decrements, who sends type 11 code 0, how the quoted header plus 8 bytes matches replies to probes, and which reply marks the destination for each probe type.

for a senior

Show what the output can mislead about: forward path only, return-side interface addresses, paths spliced by a mid-trace route change, and round-trip times that include the return path.

for a principal

Discuss the design tradeoff: traceroute reuses a mandatory error message rather than a dedicated protocol, which is why it works almost everywhere and why RFC 1393's purpose-built option never displaced it.

## The idea: make each router report itself Every IPv4 header carries an 8-bit **Time to Live** (`TTL`) field. Each router that forwards the packet reduces it by at least one, and RFC 1812 says that when it reaches zero the router **MUST discard** the packet and **MUST send** an **ICMP Time Exceeded, type 11, code 0 (TTL exceeded in transit)** back to the source. RFC 1812 even explains why this is mandatory: "ICMP Time Exceeded messages are required because the traceroute diagnostic tool depends on them." Traceroute uses that rule on purpose. Instead of setting a TTL big enough to reach the destination, it sets one just big enough to reach a particular router and no further, and lets that router announce itself. ## The procedure, step by step RFC 1393 summarises the classic algorithm. In practice: 1. Send a probe toward the destination with **TTL = 1**. The first router reduces it to 0, discards it and returns Time Exceeded code 0. The **source address** of that ICMP message is recorded as hop 1, and the delay between sending and receiving is that hop's round-trip time. 2. Send the next probe with **TTL = 2**. Router 1 forwards it with TTL 1; router 2 reduces it to 0 and reports itself. 3. Keep raising the TTL by one. Most implementations send several probes per TTL (three is a common default, an implementation choice) and wait a few seconds for each reply. 4. **Stop** when a reply comes from the destination itself rather than a Time Exceeded from a router, or when an implementation's maximum hop count is reached (commonly 30, again an implementation choice). A sending host can do this because RFC 1122 requires that an application be able to set the TTL of the UDP datagrams it sends. | Probe TTL | Who drops it | Reply received | |---|---|---| | 1 | first router | Time Exceeded, code 0 | | 2 | second router | Time Exceeded, code 0 | | n | router n | Time Exceeded, code 0 | | enough to arrive | nobody: the destination receives it | the destination's own response | ## How the end of the path is recognised The destination does not expire the probe: RFC 1122 says a host MUST NOT discard a datagram just because it arrived with a TTL below 2. It processes the probe normally, and the tool chooses a probe that draws a recognisable answer: - a **UDP** probe to an unlikely high port draws ICMP **Destination Unreachable, type 3, code 3 (port unreachable)**; - an **ICMP Echo Request** (type 8) draws an **Echo Reply** (type 0); - a **TCP SYN** draws a **SYN-ACK** if the port is listening or an **RST** if it is closed. ## Matching replies to probes Several probes are in flight at once, and replies can arrive late or out of order. Every ICMP error quotes the offending datagram's **IP header plus at least its first 8 bytes of payload** (RFC 792). For a UDP probe that includes the source and destination ports; for an Echo probe, the identifier and sequence number. By giving each probe distinct values in those fields, the tool knows which TTL a returning Time Exceeded belongs to. Classic UDP traceroute raises the destination port with every probe, starting by convention at 33434 — a tradition of the original tool, not an RFC rule. ## Which address a hop shows RFC 1812 §4.3.2.4 says the source address of an ICMP message a router originates MUST be one of the addresses of the interface **over which the ICMP message is transmitted**. So the address reported for a hop is normally the router's interface on its path back toward you, which need not be the interface the probe arrived on. Two traces in opposite directions can therefore show different addresses for the same router. RFC 5837 defines an ICMP extension in which a router can also report the incoming interface and the next hop it would have used. ## What the result does and does not show RFC 1393 lists the limitations of the method, and they still hold: - it maps **only the forward path**; replies may return by a different route, and their delay includes that return path; - each hop is discovered by a **separate probe**, so if routing changes mid-trace, the list can splice two paths together; - it costs many packets: every probe re-crosses all the nearer hops. RFC 1393 proposed a single-packet alternative, an IP Traceroute option with ICMP type 30, but it was never widely deployed; RFC 6918 lists type 30 as deprecated and records that RFC 6814 moved RFC 1393 to Historic. The TTL method remains the one in use. In IPv6 the same technique uses the **Hop Limit** field, and routers answer with ICMPv6 Time Exceeded, which is type 3 there, not 11.

  • Several traceroute probes are in flight at once. How does the tool know which TTL a returning Time Exceeded belongs to?
    The ICMP error quotes the probe's IP header and at least its first 8 payload bytes. The tool makes those bytes unique per probe: classic UDP traceroute raises the destination port each time, and an Echo-based trace varies the identifier or sequence number. Reading them back from the quote identifies the probe and therefore its TTL, even when replies arrive out of order.
  • Why can the address traceroute shows for a router differ from the address that router's neighbour uses to reach it?
    RFC 1812 requires a router to source an ICMP message from an address of the interface it sends that message out of. The Time Exceeded leaves on the interface toward you, which may not be the interface the probe came in on, so the trace shows the return-side address. RFC 5837's extension lets a router also report the incoming interface.
  • Why does a traceroute toward a host never show the routers on the path back from it?
    Each Time Exceeded reports where a forward probe died; nothing in the method sends packets along the reverse direction. Replies travel back by whatever route the network chooses for them, which can differ completely. Mapping the return path needs a trace launched from the other end.

It is like finding the stations on an unmarked railway by sending a series of letters, each stamped "return to sender after n stations". The letter stamped 1 comes back from the first station, the one stamped 2 from the second, and each returned letter carries the postmark of the station that sent it back. Nothing in a returned letter tells you which track it used to come home.

saying these in an interview costs you the question

  • Traceroute asks each router for its address with a special ICMP request
  • Each router appends its address to the probe as it passes through
  • The destination also drops the last probe and sends Time Exceeded
  • Traceroute shows the round-trip path, both forward and return
  • Starting at port 33434 is required by the ICMP specification
  • The address shown for a hop is always the interface the probe arrived on
open as a page

In IPv4, what does an ICMP Time Exceeded message (type 11) report, and which device sends each of its two codes?

level: juniorimportance: should knowfreq 42%

basics

~20 s

ICMP type 11 reports a datagram discarded because a limit ran out. Code 0, TTL exceeded in transit, comes from a router that dropped a packet whose TTL reached zero; code 1, fragment reassembly time exceeded, comes from the destination host.

open as a page

Traceroute can send UDP, ICMP Echo or TCP SYN probes; how does each mode recognise the destination, and why choose one over another?

level: middleimportance: should knowfreq 32%

basics

~20 s

In all three modes routers answer an expiring probe with ICMP Time Exceeded; only the ending differs: port unreachable for UDP, Echo Reply for Echo, SYN-ACK or RST for TCP SYN. Choose the probe the destination's filters admit.

open as a page

In an IPv4 traceroute, why can a middle hop show only asterisks while later hops answer, and why might the trace never reach the destination?

level: seniorimportance: should knowfreq 38%

basics

~20 s

An asterisk means no reply arrived in time. A silent hop followed by answering hops forwards fine, but its Time Exceeded is switched off, rate-limited or filtered; a trace that never ends usually meets a filter dropping that probe type or its reply.

open as a page

Why can an IPv4 traceroute across equal-cost multipath routing report two routers at one hop, or a link between routers that does not exist?

level: seniorimportance: nice to knowfreq 16%

basics

~20 s

Routers with equal-cost paths pick a next hop per flow by hashing header fields, often including ports. Classic UDP traceroute changes the destination port on every probe, so probes take different paths and the trace mixes routers from several of them.

open as a page