Difficulty: Beginner
What is ICMP? How do ping and traceroute work, and how does traceroute discover each hop?
IP is a best-effort protocol: it sends packets and does not promise anything, and it has no built-in way to tell you when something went wrong. ICMP, the Internet Control Message Protocol, is the side channel used to report errors and answer diagnostic questions. It sits at the network layer, is carried inside IP packets with protocol number 1, and has no ports because it is not used to carry application data.
Common ICMP messages are identified by type and code. Type 8 is Echo Request and type 0 is Echo Reply (ping). Type 3 is Destination Unreachable, with codes for network unreachable, host unreachable, port unreachable and fragmentation needed. Type 11 is Time Exceeded, and type 5 is Redirect. These messages tell the sender what happened, for example when a router has no route or when a packet's TTL expired.
Ping is the simple one. It sends an ICMP Echo Request to the target and waits for an Echo Reply. The time between them is the round-trip time, and ping also reports packet loss. A reply means the host is reachable at layer 3 and its IP stack is alive. But no reply does not necessarily mean the host is down, since many firewalls and cloud security groups block ICMP. This is a very common interview point: ping failing is not proof of failure, and ping working is not proof that your web service is healthy.
Traceroute is where the cleverness lies. Every IP packet has a TTL field, Time To Live, which is decremented by each router; when it reaches zero the router drops the packet and sends back an ICMP Time Exceeded message that includes its own IP as the source. Traceroute exploits this. It sends probes with TTL 1, so the first router discards it and reveals itself. Then TTL 2 reveals the second router, and so on, until the packet reaches the destination. On Linux, traceroute sends UDP probes to high-numbered ports, so when the final destination receives it, it replies with ICMP Port Unreachable, which is the signal that the trace is complete. Windows tracert sends ICMP Echo Requests instead, and the destination answers with an Echo Reply.
Reading the output takes practice. Three stars on a line mean no response, usually a router configured not to answer ICMP, and does not necessarily mean a break, because later hops may still respond. A sudden latency jump at one hop that continues at every later hop suggests a real bottleneck, whereas a slow hop that recovers next hop is usually just that router deprioritising ICMP replies. Also, forward and return paths can differ (asymmetric routing), and load balancing can send different probes along different paths.
The same TTL idea prevents routing loops from circulating packets forever, which is why default TTL is commonly 64 (Linux), 128 (Windows) or 255 (network devices); you can even guess the OS of a remote host from the TTL you see. ICMP is also abused: ping flood, smurf attacks and tunnelling data in ICMP payloads, so networks rate-limit it instead of blocking it entirely, especially because blocking type 3 code 4 breaks Path MTU Discovery.
$ ping -c 3 example.com
64 bytes from 93.184.216.34: icmp_seq=1 ttl=56 time=18.4 ms
64 bytes from 93.184.216.34: icmp_seq=2 ttl=56 time=17.9 ms
64 bytes from 93.184.216.34: icmp_seq=3 ttl=56 time=18.1 ms
3 packets transmitted, 3 received, 0% packet loss
$ traceroute -n example.com
1 192.168.1.1 1.2 ms 1.1 ms 1.0 ms
2 10.10.0.1 4.8 ms 4.7 ms 5.0 ms
3 * * *
4 93.184.216.34 18.3 ms 18.1 ms 18.5 ms
Hop 3 is silent because that router does not send Time Exceeded replies. The trace still completes.
ICMP, Ping, Traceroute, TTL, Network Troubleshooting