What Is Ping & Traceroute? A Complete Guide to Network Diagnostics

Last Updated: October 2026

Quick Summary

  • ✓ Ping sends ICMP Echo Request packets to a host and measures round-trip time (RTT) and packet loss.
  • ✓ Traceroute discovers every router (hop) along the network path by sending packets with incrementally increasing TTL values.
  • ✓ Use ping to check if a host is reachable and how fast; use traceroute to find where problems occur along the path.
  • ✓ MTR combines both tools, providing continuous per-hop statistics for diagnosing intermittent issues.
  • ✓ Asterisks (*) in traceroute are usually firewalls dropping ICMP — not necessarily a problem.
  • ✓ Try our Ping & Traceroute tool to run tests from our infrastructure.

What Is Ping?

Ping is the most fundamental network diagnostic tool. It tests whether a remote host is reachable and measures how long it takes for a packet to travel to the host and back. The name comes from sonar terminology — like a submarine sending out a sound pulse (ping) and listening for the echo.

Ping was written by Mike Muuss in December 1983 while working at the U.S. Army Ballistic Research Laboratory. It is available on virtually every operating system: Windows, macOS, Linux, iOS, Android, and even most network equipment (routers, switches, firewalls).

Ping uses the Internet Control Message Protocol (ICMP), specifically two message types: ICMP Echo Request (Type 8) and ICMP Echo Reply (Type 0). When you ping a host, your device sends an Echo Request packet. If the host is reachable and ICMP is not blocked, it responds with an Echo Reply packet.

How Ping Works

Here is the step-by-step process when you run a ping command:

  1. DNS resolution: If you ping a hostname (e.g., ping google.com), your system first resolves the hostname to an IP address via DNS. The resolved address is shown in the output.
  2. ICMP Echo Request: Your system constructs an ICMP Echo Request packet containing a sequence number, a timestamp, and optional payload data. The packet is encapsulated in an IP datagram and sent to the destination IP address.
  3. Network transit: The packet travels through your local network, your ISP, potentially multiple transit networks, and arrives at the destination host. Each router along the path decrements the IP header's TTL (Time to Live) field by 1.
  4. Echo Reply: The destination host receives the Echo Request, constructs an ICMP Echo Reply packet with the same sequence number and payload, and sends it back to your IP address.
  5. RTT calculation: When your system receives the Echo Reply, it calculates the Round-Trip Time (RTT) — the elapsed time between sending the request and receiving the reply. This is reported in milliseconds.
  6. Statistics: After all pings are sent (or you press Ctrl+C), the tool displays summary statistics: packets sent, packets received, packet loss percentage, and RTT statistics (minimum, average, maximum, and standard deviation/mdev).

Reading Ping Results

A typical ping output on Linux/macOS looks like this:

PING google.com (142.250.80.46) 56(84) bytes of data.
64 bytes from lax17s64-in-f14.1e100.net: icmp_seq=1 ttl=117 time=5.42 ms
64 bytes from lax17s64-in-f14.1e100.net: icmp_seq=2 ttl=117 time=5.38 ms
64 bytes from lax17s64-in-f14.1e100.net: icmp_seq=3 ttl=117 time=5.51 ms
64 bytes from lax17s64-in-f14.1e100.net: icmp_seq=4 ttl=117 time=5.44 ms

--- google.com ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3004ms
rtt min/avg/max/mdev = 5.380/5.437/5.510/0.047 ms

Here is what each field means:

64 bytes
The size of the reply packet (default payload is 56 bytes + 8 bytes ICMP header = 64 bytes).
icmp_seq
The sequence number of each ping packet. Sequential numbers help identify packet loss and out-of-order delivery. If you see icmp_seq=1, 2, 4 (missing 3), packet 3 was lost.
ttl (Time to Live)
The remaining TTL when the reply arrived. Most operating systems set an initial TTL of 64 (Linux), 128 (Windows), or 255 (network devices). By comparing the received TTL to these common starting values, you can estimate the number of hops: if TTL=117 and the initial was likely 128, the packet crossed approximately 11 routers.
time (RTT)
The round-trip time in milliseconds. Lower is better. Under 20ms is excellent (same region), 20–100ms is good (same continent), 100–200ms is acceptable (intercontinental), and over 200ms may cause noticeable delays for interactive applications.
min/avg/max/mdev
Summary statistics across all pings sent. min is the best-case latency, avg is the typical experience, max is the worst case, and mdev (mean deviation, or jitter) measures consistency. High mdev means the connection is unstable — latency is jumping around unpredictably.
Packet loss
The percentage of sent packets that did not receive a reply. 0% is ideal. Any non-zero packet loss indicates a problem. Consistent packet loss above 1–2% will degrade the user experience for real-time applications like video calls and gaming.

What Is Traceroute?

Traceroute (called tracert on Windows) is a network diagnostic tool that reveals the path packets take from your device to a destination, showing every intermediate router (hop) along the way. While ping tells you the total round-trip time to a destination, traceroute shows you where along the path latency is being introduced or where packets are being dropped.

Traceroute was written by Van Jacobson in 1987 and has become one of the most important tools for diagnosing routing issues, identifying network bottlenecks, and understanding internet topology.

How Traceroute Works

Traceroute exploits the TTL (Time to Live) field in the IP header. Every IP packet has a TTL value that limits how many routers it can pass through. Each router that forwards a packet decrements the TTL by 1. When a router receives a packet with TTL=1, it decrements it to 0, discards the packet, and sends an ICMP Time Exceeded message back to the sender. Traceroute uses this behavior systematically:

  1. TTL=1: Traceroute sends a probe packet with TTL set to 1. The first router in the path decrements it to 0, drops the packet, and sends back an ICMP Time Exceeded message. Traceroute records the router's IP address and the round-trip time.
  2. TTL=2: A second probe is sent with TTL=2. It passes through the first router (TTL becomes 1), reaches the second router (TTL becomes 0), and the second router sends back a Time Exceeded message. Traceroute records the second hop.
  3. TTL=3, 4, 5...: This process continues with incrementing TTL values, discovering each router along the path one hop at a time.
  4. Destination reached: When the probe finally reaches the destination host, instead of a Time Exceeded message, the host responds with either an ICMP Echo Reply (if ICMP probes are used) or an ICMP Port Unreachable message (if UDP probes are used). Traceroute recognizes this as the final hop and stops.

By default, traceroute sends three probes at each TTL level, which is why you see three latency values per hop in the output.

Traceroute vs Tracepath vs Tracert

Different operating systems provide different traceroute implementations with subtle but important differences:

traceroute (Linux)
The standard Linux traceroute uses UDP probe packets by default, targeting high-numbered ports (starting at 33434). It requires root privileges for ICMP or TCP mode. It supports multiple probe methods via flags: -I for ICMP Echo, -T for TCP SYN, and the default UDP. TCP mode (traceroute -T) is particularly useful because TCP SYN packets are less likely to be blocked by firewalls than UDP or ICMP.
traceroute (macOS)
macOS traceroute also uses UDP by default and has similar options to Linux. The syntax is nearly identical: traceroute example.com.
tracert (Windows)
Windows tracert uses ICMP Echo Request packets by default (the same type as ping). This means Windows tracert and Linux traceroute may produce different results for the same destination because routers and firewalls may handle ICMP and UDP differently. Windows tracert has limited options compared to Unix traceroute.
tracepath (Linux)
A simpler alternative to traceroute that does not require root privileges. It uses UDP and also discovers the Path MTU (Maximum Transmission Unit) — the largest packet size that can traverse the path without fragmentation. It is included in the iputils package on most Linux distributions.

Reading Traceroute Output

A typical traceroute output looks like this:

traceroute to google.com (142.250.80.46), 30 hops max, 60 byte packets
 1  router.local (192.168.1.1)       1.234 ms  1.112 ms  1.098 ms
 2  10.0.0.1                         8.456 ms  8.321 ms  8.512 ms
 3  isp-core-router.example.net      12.345 ms 12.123 ms 12.456 ms
 4  * * *
 5  72.14.237.126                    15.678 ms 15.234 ms 15.890 ms
 6  142.250.80.46                     16.012 ms 15.987 ms 16.123 ms

Here is how to interpret each element:

Hop number (1, 2, 3...)
The sequential number of each router in the path. Hop 1 is always your local gateway (home router). The last hop is the destination. More hops generally means a longer, more complex path.
Router hostname and IP
The hostname (if reverse DNS exists) and IP address of the router at each hop. Hostnames often contain useful clues: city codes (lax = Los Angeles, ord = Chicago, ams = Amsterdam), ISP names, and router roles (core, edge, border).
Three latency values
Traceroute sends three probes at each hop by default and reports the RTT for each. If all three values are similar, the hop is consistent. Large variation suggests intermittent congestion or load balancing across multiple paths.
Asterisks (* * *)
The router at this hop did not respond to the probes within the timeout period. This usually means the router's firewall is configured to drop or rate-limit ICMP/UDP probe packets. A single row of asterisks at an intermediate hop is very common and does not indicate a problem — as long as subsequent hops respond. If all remaining hops show asterisks, the destination or a downstream firewall is blocking the probes.

Common Network Issues Diagnosed with Ping

Ping is the first tool to reach for when diagnosing network problems. Here are common patterns and what they indicate:

High Latency

If ping RTT values are consistently high (e.g., 200ms+ to a server in the same country), possible causes include: network congestion on your ISP's network, a saturated local network (bandwidth being consumed by other devices), geographic distance (intercontinental connections naturally have higher latency due to the speed of light in fiber), poor routing (packets taking a suboptimal path), or an overloaded destination server.

Packet Loss

Any packet loss above 0% warrants investigation. Causes include: faulty network cables or connectors, failing network interface cards, wireless interference or weak signal, network congestion (buffers full, packets dropped), ISP issues, or destination server overload. Even 1–2% packet loss can degrade VoIP calls, video conferencing, and online gaming.

Destination Unreachable

If ping returns "Destination Host Unreachable" or "Network Unreachable," it means a router along the path cannot forward the packet to the destination. This could indicate: the destination host is down, there is no route to the destination network, a firewall is actively rejecting ICMP, or there is a routing configuration error.

Request Timed Out

"Request Timed Out" means your system sent the Echo Request but did not receive a reply within the timeout period. The host may be blocking ICMP, a firewall may be filtering packets, the host may be down, or the reply may have been lost on the return path. Unlike "Destination Unreachable," no router sent back an error — the packet simply vanished.

Intermittent Latency Spikes

If most pings show low latency but occasional pings spike to 200ms+, this usually indicates: shared bandwidth being consumed periodically (e.g., background downloads), Wi-Fi interference, bufferbloat (excessive buffering in a network device), or ISP-level congestion at peak hours.

Common Traceroute Patterns

First Hop = Your Router

Hop 1 is always your default gateway (typically 192.168.1.1 or 10.0.0.1). If the first hop shows high latency or packet loss, the problem is on your local network — check your Wi-Fi, Ethernet cable, or router.

Latency Jump at a Specific Hop

If latency is low for the first several hops and then suddenly increases at a specific hop (and stays elevated for all subsequent hops), the problem is at or near that hop. Check whether the jump corresponds to a geographic boundary (e.g., traffic crossing from North America to Europe) or a congested peering point between ISPs.

High Latency at One Hop, Normal After

If a single intermediate hop shows high latency but subsequent hops return to normal, this usually does not indicate a problem. Many routers prioritize forwarding traffic over responding to ICMP and deprioritize generating Time Exceeded messages. The router is forwarding your actual traffic at full speed but is slow to respond to traceroute probes. This is called ICMP rate limiting and is a common false positive.

Last Hop = Destination

The final hop is the destination host. If the destination shows high latency but intermediate hops are fast, the destination server itself may be overloaded, located far away from the last transit router, or responding slowly to ICMP while handling application traffic normally.

TCP vs ICMP vs UDP Traceroute

The choice of probe protocol significantly affects traceroute results because firewalls treat different protocols differently:

ICMP Traceroute (tracert on Windows, traceroute -I on Linux)
Uses ICMP Echo Request packets (the same as ping). Many corporate and cloud firewalls block ICMP, so this method often fails to reach the destination. However, it tends to get responses from more intermediate routers than UDP traceroute.
UDP Traceroute (default on Linux/macOS)
Sends UDP packets to high-numbered ports (33434+). When the probes reach the destination, the host responds with ICMP Port Unreachable (since no service is listening on those ports). This method works well when ICMP is blocked but UDP is allowed through firewalls.
TCP Traceroute (traceroute -T on Linux, or tcptraceroute)
Sends TCP SYN packets, typically to port 80 (HTTP) or 443 (HTTPS). This is the most likely to reach the destination because web traffic is rarely blocked by firewalls. When the SYN reaches the destination, it responds with SYN-ACK (if the port is open) or RST (if closed), indicating the final hop. This is the recommended method when other traceroute types fail.

MTR: Combining Ping and Traceroute

MTR (My Traceroute) is a powerful network diagnostic tool that combines the path discovery of traceroute with the continuous monitoring of ping. Instead of sending a single set of probes and stopping, MTR continuously sends probes and builds up per-hop statistics over time.

MTR provides the following statistics for each hop:

  • Loss%: Packet loss percentage at each hop, calculated over all probes sent.
  • Snt: Number of probes sent to each hop.
  • Last: RTT of the most recent probe.
  • Avg: Average RTT across all probes.
  • Best: Best (lowest) RTT observed.
  • Wrst: Worst (highest) RTT observed.
  • StDev: Standard deviation of RTT, measuring consistency (jitter).

How to Use MTR

  • mtr google.com — Launches MTR in interactive mode with a continuously updating display.
  • mtr -rw -c 100 google.com — Runs 100 probes and outputs a report (-r for report mode, -w for wide output showing full hostnames).
  • mtr --tcp -P 443 google.com — Uses TCP SYN probes to port 443, useful when ICMP is blocked.
  • mtr -4 google.com — Forces IPv4 only; -6 forces IPv6.

Reading MTR Reports

When analyzing MTR output, look for these patterns:

  • Packet loss at an intermediate hop that does not continue to the destination: This is ICMP rate limiting, not real packet loss. Many routers limit ICMP responses and show apparent loss without affecting actual traffic.
  • Packet loss that starts at one hop and continues to the destination: This indicates real packet loss at that hop. The problem is at or before the first hop showing loss.
  • Steadily increasing latency across hops: Normal behavior, especially across geographic boundaries. Each router adds a small amount of processing and transmission delay.
  • Large latency jump at a single hop: Could indicate congestion, geographic distance, or a slow link at that point. Use the hostname clues to determine the cause.

When to Use Ping vs Traceroute

Knowing which tool to use and when will make your network troubleshooting more efficient:

Use ping when:
  • You want a quick check of whether a host is reachable
  • You want to measure latency to a specific destination
  • You want to monitor for packet loss over time (e.g., ping -t on Windows or ping on Linux which runs until Ctrl+C)
  • You need a baseline measurement for network performance
  • You want to verify DNS resolution is working (ping a hostname)
Use traceroute when:
  • You know there is a problem (high latency or packet loss from ping) and want to find where it occurs
  • You want to understand the routing path between two points
  • You suspect an ISP or transit provider is causing issues
  • You want to verify that traffic is taking the expected path (e.g., not routing through an unexpected country)
  • You need to provide network diagnostics to your ISP's support team
Use MTR when:
  • You need to diagnose an intermittent problem (MTR runs continuously and catches transient issues)
  • You want per-hop packet loss and latency statistics over time
  • Your ISP asks for an MTR report to diagnose your connectivity issue
  • You want a single tool that provides both path discovery and latency monitoring

Frequently Asked Questions

What is the difference between ping and traceroute?

Ping tests whether a host is reachable and measures round-trip latency. Traceroute discovers every router along the network path, showing latency at each hop. Ping tells you "how fast" while traceroute tells you "where." They complement each other for network diagnostics.

What does high ping mean?

High ping means it takes a long time for data to make the round trip to the destination. For gaming, under 50ms is ideal; over 150ms causes noticeable lag. Causes include geographic distance, network congestion, poor routing, and ISP issues.

What is packet loss?

Packet loss occurs when data packets fail to reach their destination. Any loss above 0% indicates a problem. Common causes include network congestion, faulty hardware, wireless interference, and ISP issues. Even 1–2% loss degrades real-time applications like video calls.

Why does traceroute show asterisks (*)?

Asterisks mean the router at that hop did not respond within the timeout. This usually means the router's firewall is dropping ICMP packets. A few asterisks at intermediate hops are normal and do not indicate a problem as long as subsequent hops and the destination respond.

What is TTL (Time to Live)?

TTL is a field in the IP packet header that limits how many routers a packet can traverse. Each router decrements TTL by 1; when it hits 0, the packet is discarded and an ICMP Time Exceeded message is sent back. Traceroute uses this mechanism by sending packets with incrementally increasing TTL values.

What is MTR and how is it different from traceroute?

MTR combines ping and traceroute into one tool. It continuously sends probes and displays real-time statistics (loss, latency, jitter) for every hop. This makes it far more useful for diagnosing intermittent issues that a single traceroute snapshot might miss.

What is the difference between traceroute and tracert?

They serve the same purpose but use different default probes. Linux/macOS traceroute uses UDP packets; Windows tracert uses ICMP Echo Request packets. The different probe types can produce different results depending on how firewalls handle each protocol.

Can ping and traceroute be blocked by firewalls?

Yes. Many firewalls block or rate-limit ICMP traffic. When blocked, ping shows "Request timed out" and traceroute shows asterisks. The host may still be fully reachable via HTTP and other protocols. Use TCP-based traceroute (traceroute -T) to work around ICMP blocking.