[147386] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: Traceroute explanation

daemon@ATHENA.MIT.EDU (Steven Bellovin)
Thu Dec 8 16:35:21 2011

From: Steven Bellovin <smb@cs.columbia.edu>
In-Reply-To: <BA24CC8904B545D5AC25296C649AC715@work>
Date: Thu, 8 Dec 2011 16:33:09 -0500
To: "Meftah Tayeb" <tayeb.meftah@gmail.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org

On Dec 7, 2011, at 2:51 08PM, Meftah Tayeb wrote:

> big thank for that
> but, i am testing that for one day :)



Can you do an AStraceroute or manually translate those addresses into =
AS#s? =20
That is, might level3 and tinet  be using multiple AS#s, in which case =
this
isn't unreasonable?





>=20
>=20
> ----- Original Message ----- From: "Fred Baker" <fred@cisco.com>
> To: "Meftah Tayeb" <tayeb.meftah@gmail.com>
> Cc: <nanog@nanog.org>
> Sent: Thursday, December 08, 2011 11:23 PM
> Subject: Re: Traceroute explanation
>=20
>=20
> This is just a guess, but I'll bet the route changed while you were =
measuring it.
>=20
> Traceroute sends a request, awaits a response, sends a request, ... =
Suppose that the route was
>=20
> 172.28.0.1 -> 10.16.0.2
>          -> 41.200.16.1
>          -> 172.17.2.25
>          -> 213.140.58.10
>          -> 195.22.195.125
>          -> 4.69.151.13
>          -> 213.200.68.61
>          -> somewhere else
>=20
> and after the test got that far, two systems got inserted into the =
path before level3, resulting in the route entering level3 at a =
different point, 4.69.141.249. What you now have is
>=20
> 172.28.0.1 -> 10.16.0.2
>          -> 41.200.16.1
>          -> 172.17.2.25
>          -> 213.140.58.10
>          -> 195.22.195.125
>          -> unknown
>          -> unknown
>          -> 4.69.141.249
>          -> 77.67.66.154
>          -> and so on
>=20
> The effect would be to get a result like this.
>=20
> Next time you see something like this, suggestion: repeat the =
traceroute and see what you get.
>=20
>=20
> On Dec 7, 2011, at 12:12 PM, Meftah Tayeb wrote:
>=20
>> Hey folks,
>> i see a strange traceroute there
>>=20
>> D=E9termination de l'itin=E9raire vers www.rri.ro [193.231.72.52]
>> avec un maximum de 30 sauts :
>>=20
>> 1     2 ms     1 ms     1 ms  172.28.0.1
>> 2     1 ms     1 ms     1 ms  localhost [10.16.0.2]
>> 3    10 ms    10 ms    13 ms  41.200.16.1
>> 4    11 ms    10 ms    11 ms  172.17.2.25
>> 5    21 ms    21 ms    21 ms  213.140.58.10
>> 6    34 ms    31 ms    55 ms  pos14-0.palermo9.pal.seabone.net =
[195.22.197.125
>> ]
>> 7    34 ms    33 ms    35 ms  ae-5-6.bar2.marseille1.level3.net =
[4.69.151.13]
>> 8   106 ms    68 ms    67 ms  xe-1-1-0.mil10.ip4.tinet.net =
[213.200.68.61]
>> 9    74 ms    73 ms    74 ms  ae-1-12.bar1.budapest1.level3.net =
[4.69.141.249]
>> 10    63 ms    63 ms    79 ms  euroweb-gw.ip4.tinet.net =
[77.67.66.154]
>> 11    85 ms    84 ms    84 ms  v15-core1.stsisp.ro [193.151.28.1]
>> 12   100 ms   100 ms   102 ms  inet-crli1.qrli1.buh.ew.ro =
[81.24.28.226]
>> 13    81 ms    81 ms    81 ms  193.231.72.10
>> 14    92 ms    92 ms    93 ms  ip4-89-238-225-90.euroweb.ro =
[89.238.225.90]
>> 15    89 ms    89 ms    89 ms  webrri.rri.ro.72.231.193.in-addr.arpa =
[193.231.7
>> 2.52]
>> Itin=E9raire d=E9termin=E9.
>> C:\Documents and Settings\TAYEB>
>> Seabone, then level3, then Tinet, then level3, then tinet ?
>> if is that a routing stufs that i don't know, please let me know :)
>> i never saw that befaure
>>=20
>>   Meftah Tayeb
>> IT Consulting
>> http://www.tmvoip.com/
>> phone: +21321656139
>> Mobile: +213660347746
>>=20
>>=20
>> __________ Information from ESET NOD32 Antivirus, version of virus =
signature database 6695 (20111208) __________
>>=20
>> The message was checked by ESET NOD32 Antivirus.
>>=20
>> http://www.eset.com
>>=20
>=20
>=20
>=20
> __________ Information from ESET NOD32 Antivirus, version of virus =
signature database 6695 (20111208) __________
>=20
> The message was checked by ESET NOD32 Antivirus.
>=20
> http://www.eset.com
>=20
>=20
>=20
>=20
> __________ Information from ESET NOD32 Antivirus, version of virus =
signature database 6695 (20111208) __________
>=20
> The message was checked by ESET NOD32 Antivirus.
>=20
> http://www.eset.com
>=20
>=20
>=20
>=20
>=20


		--Steve Bellovin, https://www.cs.columbia.edu/~smb







home help back first fref pref prev next nref lref last post