Trace route (tracert) works by sending a packet to an open UDP port on a destination machine. For the initial three packets, trace route sets the TTL (see explanation of TTL) to 1 and releases the packet. The packet then gets transferred to the first router (completing the first hop), and the TTL gets decremented by the router from 1 to 0. The router then discards the packet and sends off an ICMP notification packet to the original host with the message that the TTL expired from the router. This tells tracert what the first hop is and how long it takes to get there. Traceroute repeats this, gradually incrementing the TTL until a path to the remote host is traced and it gets back an ICMP Port Unreachable message, indicating that the remote host has been reached.
Response times may vary dramatically because the packet is crossing long distances, other times the increases come from network congestion.
C:> tracert www.linux.org
C:> tracert 184.108.40.206
Tracing route to www.linux.org [220.127.116.11]
over a maximum of 30 hops:
1 <10 ms <10 ms <10 ms mn-bldg-rtr-vlan200-3.gw.more.net [18.104.22.168]
2 <10 ms <10 ms <10 ms co-r12-01-atm0-0-10.mo.more.net [22.214.171.124]
3 <10 ms 10 ms <10 ms kc-r12-01-atm1-0-131.mo.more.net [126.96.36.199]
4 <10 ms 10 ms <10 ms bb2-g8-0.kscymo.swbell.net [188.8.131.52]
5 <10 ms 10 ms 10 ms sl-gw9-kc-2-0.sprintlink.net [184.108.40.206]
6 * * *
7 50 ms 61 ms 60 ms 198.ATM7-0.XR2.TOR2.ALTER.NET [220.127.116.11]
8 50 ms 60 ms 60 ms 194.ATM7-0.GW1.TOR2.ALTER.NET [18.104.22.168]
9 50 ms 70 ms 60 ms att2-gw.customer.alter.net [22.214.171.124]
10 61 ms 60 ms 60 ms pos5-0-0.hcap1-ott.bb.attcanada.ca [126.96.36.199]
11 60 ms 70 ms 70 ms 188.8.131.52
12 60 ms 81 ms 70 ms router.invlogic.com [184.108.40.206]
13 70 ms 70 ms 80 ms www.linux.org [220.127.116.11]
Note the asterisks on line six. This can indicate that a response wasn't received. Some routers do not issue TTL-expired ICMP messages.
Traceroute can be accessed at a DOS or command prompt. An Internet connection must already be established.
C:> tracert www.emints.more.net