Read

Module 8 · Archives, compression and the network

traceroute and diagnosing a path

See the routers between you and a host with traceroute, then put the whole module together in a step-by-step method for diagnosing a broken connection, followed by the module exam.

What you will learn

  • Explain how traceroute uses the TTL to reveal each hop, and read its output, stars included.
  • Diagnose a connection layer by layer: link, address, route, gateway, DNS, service.
  • Combine archives and network tools to collect, ship and apply configuration.

Every IP packet carries a TTL (time to live): a counter that each router decrements by one. When it reaches zero the router drops the packet and sends back an ICMP *time exceeded* message, signed with its own address. That rule exists to stop packets looping forever, and traceroute turns it into a map: it sends probes with TTL 1, then 2, then 3, and each router along the path reveals itself by complaining.

~% traceroute -n 1.1.1.1            # on an ordinary network
traceroute to 1.1.1.1 (1.1.1.1), 30 hops max, 38 byte packets
 1  192.168.1.1  0.712 ms  0.540 ms  0.498 ms
 2  10.40.0.1  8.901 ms  8.322 ms  9.114 ms
 3  *  *  *
 4  1.1.1.1  12.210 ms  11.987 ms  12.034 ms

Each line is a hop: its address and three round-trip times (three probes per hop). * means no answer arrived within the wait time; a router in the middle that never answers is common and harmless if later hops appear. Useful options: -n skips name lookups (faster), -m N sets the maximum number of hops (default 30), -q N the probes per hop, -w SEC the wait per probe, and -I uses ICMP echo instead of UDP probes, which some firewalls let through more readily.

In this VM, traceroute -n -m 3 127.0.0.1 shows a one-hop path (bring lo up first). Towards the outside, with the network on, every hop is *: the emulator's virtual router answers pings but never sends *time exceeded*, because the real path lives inside your browser's HTTP requests. Use -m 5 -w 1 -q 1 there, or a 30-hop run full of stars will make you wait several minutes.

Diagnosing a connection, bottom up

*I can't reach the site* has a dozen possible causes. Check them in order, from the cable up, and stop at the first step that fails: each command is one you learned in this module.

  1. Link: ip link show eth0. Is it UP with LOWER_UP? If not, ip link set eth0 up.
  2. Address: ip addr show eth0. No inet line? Get one with udhcpc -i eth0.
  3. Route: ip route. No default via line means no way off the subnet.
  4. Gateway: ping -c 2 the gateway address. On a real network, failure here is a local problem.
  5. Name: nslookup NAME. bad address or *can't resolve*? Read /etc/resolv.conf and /etc/hosts.
  6. Path: on a real network, traceroute -n HOST shows where packets stop.
  7. Service: wget -S -O /dev/null http://HOST/ and read the status line. In TempMV this is the only real end-to-end test.

Commands in this lesson

CommandWhat it does
traceroute -n HOSTList the hops to HOST, numeric.
traceroute -n -m 5 -w 1 -q 1 HOSTA short, fast trace: 5 hops, 1 probe each.
traceroute -I HOSTUse ICMP echo probes instead of UDP.
ip route | awk '/^default/ {print $3}'Print just the default gateway.
tar cf - diag | gzip > diag.tar.gzPack a diagnostics folder for sharing.

Quiz

  1. How does traceroute discover each router on the path?

    • It asks the DNS server for the route
    • It sends probes with increasing TTL; each router that drops one replies 'time exceeded'
    • It reads the routing table of each router
    • It pings every address in between
  2. Module exam: which pipeline creates logs.tar.gz from the logs directory in this VM?

    • gzip logs > logs.tar.gz
    • tar cf - logs | gzip > logs.tar.gz
    • tar tf logs | gzip > logs.tar.gz
    • zcat logs | tar cf logs.tar.gz
  3. Module exam: you must read one file from a large backup.tar without unpacking the rest. Which command?

    • tar xf backup.tar
    • tar xOf backup.tar etc/app.conf
    • tar cf backup.tar etc/app.conf
    • cat backup.tar/etc/app.conf
  4. Module exam: eth0 is UP but has no `inet` line. What is the next step?

    • Edit /etc/hosts
    • Get an address, e.g. with udhcpc -i eth0
    • Run traceroute
    • Unzip the network configuration
  5. Module exam: `ping 192.168.86.1` works but `wget http://httpbin.org/get` says "bad address 'httpbin.org'". Which layer is broken?

    • The link
    • Name resolution: check /etc/resolv.conf
    • The routing table
    • The web server
  6. Module exam: what does `netstat -tln` show?

    • The routing table
    • TCP sockets in LISTEN state, numeric
    • All network interfaces
    • Established UDP connections
  7. Module exam: which statement about TempMV's Built-in network is true?

    • Ping replies prove the internet host is up
    • Every port works, as on a real network
    • HTTP on port 80 to CORS-friendly sites is the real end-to-end test
    • traceroute shows the real internet path

Practice

  1. Build a diagnostics report: create the directory `/root/lab/l80/diag` with `addr.txt` (output of `ip addr`), `routes.txt` (output of `route -n`) and `trace.txt` (output of `traceroute -n -m 3 127.0.0.1`), then pack the directory into `/root/lab/l80/diag.tar.gz`.

  2. A colleague sent `/root/lab/l80/inbox/hosts.tar.gz`. It contains a file with a line for `/etc/hosts`. Unpack it, append its line to `/etc/hosts`, and confirm that `nslookup build.lab` returns the address it gives.

  3. Network needed (Built-in mode). Make sure eth0 has an address (`udhcpc -i eth0` if not), write **only** the default gateway's IP address into `/root/lab/l80/gateway.txt`, and save the output of pinging that gateway twice into `/root/lab/l80/gwping.txt`.

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.