Module 8 · Archives, compression and the network
traceroute and diagnosing a path
See the routers between you and a host with traceroute, then put the whole module together in a step-by-step method for diagnosing a broken connection, followed by the module exam.
What you will learn
- Explain how traceroute uses the TTL to reveal each hop, and read its output, stars included.
- Diagnose a connection layer by layer: link, address, route, gateway, DNS, service.
- Combine archives and network tools to collect, ship and apply configuration.
Every IP packet carries a TTL (time to live): a counter that each router decrements by one. When it reaches zero the router drops the packet and sends back an ICMP *time exceeded* message, signed with its own address. That rule exists to stop packets looping forever, and traceroute turns it into a map: it sends probes with TTL 1, then 2, then 3, and each router along the path reveals itself by complaining.
~% traceroute -n 1.1.1.1 # on an ordinary network
traceroute to 1.1.1.1 (1.1.1.1), 30 hops max, 38 byte packets
1 192.168.1.1 0.712 ms 0.540 ms 0.498 ms
2 10.40.0.1 8.901 ms 8.322 ms 9.114 ms
3 * * *
4 1.1.1.1 12.210 ms 11.987 ms 12.034 ms
Each line is a hop: its address and three round-trip times (three probes per hop). * means no answer arrived within the wait time; a router in the middle that never answers is common and harmless if later hops appear. Useful options: -n skips name lookups (faster), -m N sets the maximum number of hops (default 30), -q N the probes per hop, -w SEC the wait per probe, and -I uses ICMP echo instead of UDP probes, which some firewalls let through more readily.
In this VM, traceroute -n -m 3 127.0.0.1 shows a one-hop path (bring lo up first). Towards the outside, with the network on, every hop is *: the emulator's virtual router answers pings but never sends *time exceeded*, because the real path lives inside your browser's HTTP requests. Use -m 5 -w 1 -q 1 there, or a 30-hop run full of stars will make you wait several minutes.
Diagnosing a connection, bottom up
*I can't reach the site* has a dozen possible causes. Check them in order, from the cable up, and stop at the first step that fails: each command is one you learned in this module.
- Link:
ip link show eth0. Is itUPwithLOWER_UP? If not,ip link set eth0 up. - Address:
ip addr show eth0. Noinetline? Get one withudhcpc -i eth0. - Route:
ip route. Nodefault vialine means no way off the subnet. - Gateway:
ping -c 2the gateway address. On a real network, failure here is a local problem. - Name:
nslookup NAME.bad addressor *can't resolve*? Read/etc/resolv.confand/etc/hosts. - Path: on a real network,
traceroute -n HOSTshows where packets stop. - Service:
wget -S -O /dev/null http://HOST/and read the status line. In TempMV this is the only real end-to-end test.
Commands in this lesson
| Command | What it does |
|---|---|
traceroute -n HOST | List the hops to HOST, numeric. |
traceroute -n -m 5 -w 1 -q 1 HOST | A short, fast trace: 5 hops, 1 probe each. |
traceroute -I HOST | Use ICMP echo probes instead of UDP. |
ip route | awk '/^default/ {print $3}' | Print just the default gateway. |
tar cf - diag | gzip > diag.tar.gz | Pack a diagnostics folder for sharing. |
Quiz
How does traceroute discover each router on the path?
- It asks the DNS server for the route
- It sends probes with increasing TTL; each router that drops one replies 'time exceeded'
- It reads the routing table of each router
- It pings every address in between
Module exam: which pipeline creates logs.tar.gz from the logs directory in this VM?
- gzip logs > logs.tar.gz
- tar cf - logs | gzip > logs.tar.gz
- tar tf logs | gzip > logs.tar.gz
- zcat logs | tar cf logs.tar.gz
Module exam: you must read one file from a large backup.tar without unpacking the rest. Which command?
- tar xf backup.tar
- tar xOf backup.tar etc/app.conf
- tar cf backup.tar etc/app.conf
- cat backup.tar/etc/app.conf
Module exam: eth0 is UP but has no `inet` line. What is the next step?
- Edit /etc/hosts
- Get an address, e.g. with udhcpc -i eth0
- Run traceroute
- Unzip the network configuration
Module exam: `ping 192.168.86.1` works but `wget http://httpbin.org/get` says "bad address 'httpbin.org'". Which layer is broken?
- The link
- Name resolution: check /etc/resolv.conf
- The routing table
- The web server
Module exam: what does `netstat -tln` show?
- The routing table
- TCP sockets in LISTEN state, numeric
- All network interfaces
- Established UDP connections
Module exam: which statement about TempMV's Built-in network is true?
- Ping replies prove the internet host is up
- Every port works, as on a real network
- HTTP on port 80 to CORS-friendly sites is the real end-to-end test
- traceroute shows the real internet path
Practice
Build a diagnostics report: create the directory `/root/lab/l80/diag` with `addr.txt` (output of `ip addr`), `routes.txt` (output of `route -n`) and `trace.txt` (output of `traceroute -n -m 3 127.0.0.1`), then pack the directory into `/root/lab/l80/diag.tar.gz`.
A colleague sent `/root/lab/l80/inbox/hosts.tar.gz`. It contains a file with a line for `/etc/hosts`. Unpack it, append its line to `/etc/hosts`, and confirm that `nslookup build.lab` returns the address it gives.
Network needed (Built-in mode). Make sure eth0 has an address (`udhcpc -i eth0` if not), write **only** the default gateway's IP address into `/root/lab/l80/gateway.txt`, and save the output of pinging that gateway twice into `/root/lab/l80/gwping.txt`.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.