[147386] in North American Network Operators' Group
Re: Traceroute explanation
daemon@ATHENA.MIT.EDU (Steven Bellovin)
Thu Dec 8 16:35:21 2011
From: Steven Bellovin <smb@cs.columbia.edu>
In-Reply-To: <BA24CC8904B545D5AC25296C649AC715@work>
Date: Thu, 8 Dec 2011 16:33:09 -0500
To: "Meftah Tayeb" <tayeb.meftah@gmail.com>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On Dec 7, 2011, at 2:51 08PM, Meftah Tayeb wrote:
> big thank for that
> but, i am testing that for one day :)
Can you do an AStraceroute or manually translate those addresses into =
AS#s? =20
That is, might level3 and tinet be using multiple AS#s, in which case =
this
isn't unreasonable?
>=20
>=20
> ----- Original Message ----- From: "Fred Baker" <fred@cisco.com>
> To: "Meftah Tayeb" <tayeb.meftah@gmail.com>
> Cc: <nanog@nanog.org>
> Sent: Thursday, December 08, 2011 11:23 PM
> Subject: Re: Traceroute explanation
>=20
>=20
> This is just a guess, but I'll bet the route changed while you were =
measuring it.
>=20
> Traceroute sends a request, awaits a response, sends a request, ... =
Suppose that the route was
>=20
> 172.28.0.1 -> 10.16.0.2
> -> 41.200.16.1
> -> 172.17.2.25
> -> 213.140.58.10
> -> 195.22.195.125
> -> 4.69.151.13
> -> 213.200.68.61
> -> somewhere else
>=20
> and after the test got that far, two systems got inserted into the =
path before level3, resulting in the route entering level3 at a =
different point, 4.69.141.249. What you now have is
>=20
> 172.28.0.1 -> 10.16.0.2
> -> 41.200.16.1
> -> 172.17.2.25
> -> 213.140.58.10
> -> 195.22.195.125
> -> unknown
> -> unknown
> -> 4.69.141.249
> -> 77.67.66.154
> -> and so on
>=20
> The effect would be to get a result like this.
>=20
> Next time you see something like this, suggestion: repeat the =
traceroute and see what you get.
>=20
>=20
> On Dec 7, 2011, at 12:12 PM, Meftah Tayeb wrote:
>=20
>> Hey folks,
>> i see a strange traceroute there
>>=20
>> D=E9termination de l'itin=E9raire vers www.rri.ro [193.231.72.52]
>> avec un maximum de 30 sauts :
>>=20
>> 1 2 ms 1 ms 1 ms 172.28.0.1
>> 2 1 ms 1 ms 1 ms localhost [10.16.0.2]
>> 3 10 ms 10 ms 13 ms 41.200.16.1
>> 4 11 ms 10 ms 11 ms 172.17.2.25
>> 5 21 ms 21 ms 21 ms 213.140.58.10
>> 6 34 ms 31 ms 55 ms pos14-0.palermo9.pal.seabone.net =
[195.22.197.125
>> ]
>> 7 34 ms 33 ms 35 ms ae-5-6.bar2.marseille1.level3.net =
[4.69.151.13]
>> 8 106 ms 68 ms 67 ms xe-1-1-0.mil10.ip4.tinet.net =
[213.200.68.61]
>> 9 74 ms 73 ms 74 ms ae-1-12.bar1.budapest1.level3.net =
[4.69.141.249]
>> 10 63 ms 63 ms 79 ms euroweb-gw.ip4.tinet.net =
[77.67.66.154]
>> 11 85 ms 84 ms 84 ms v15-core1.stsisp.ro [193.151.28.1]
>> 12 100 ms 100 ms 102 ms inet-crli1.qrli1.buh.ew.ro =
[81.24.28.226]
>> 13 81 ms 81 ms 81 ms 193.231.72.10
>> 14 92 ms 92 ms 93 ms ip4-89-238-225-90.euroweb.ro =
[89.238.225.90]
>> 15 89 ms 89 ms 89 ms webrri.rri.ro.72.231.193.in-addr.arpa =
[193.231.7
>> 2.52]
>> Itin=E9raire d=E9termin=E9.
>> C:\Documents and Settings\TAYEB>
>> Seabone, then level3, then Tinet, then level3, then tinet ?
>> if is that a routing stufs that i don't know, please let me know :)
>> i never saw that befaure
>>=20
>> Meftah Tayeb
>> IT Consulting
>> http://www.tmvoip.com/
>> phone: +21321656139
>> Mobile: +213660347746
>>=20
>>=20
>> __________ Information from ESET NOD32 Antivirus, version of virus =
signature database 6695 (20111208) __________
>>=20
>> The message was checked by ESET NOD32 Antivirus.
>>=20
>> http://www.eset.com
>>=20
>=20
>=20
>=20
> __________ Information from ESET NOD32 Antivirus, version of virus =
signature database 6695 (20111208) __________
>=20
> The message was checked by ESET NOD32 Antivirus.
>=20
> http://www.eset.com
>=20
>=20
>=20
>=20
> __________ Information from ESET NOD32 Antivirus, version of virus =
signature database 6695 (20111208) __________
>=20
> The message was checked by ESET NOD32 Antivirus.
>=20
> http://www.eset.com
>=20
>=20
>=20
>=20
>=20
--Steve Bellovin, https://www.cs.columbia.edu/~smb