Traceroute for modern networks.
TCP, UDP, ICMP and adaptive probes that pass firewalls, expose ECMP forks, find the path MTU and name every network in the way. IPv4 and IPv6. Open source, with WhoB — the one-line whois — in every tarball.
[host]$ lft -S -E eggs.gnu.org:587 TTL LFT trace to eggs.gnu.org (209.51.188.92):587/tcp 1 192.0.2.1 0/1/1 ±0ms ** [neglected] no reply packets received from TTLs 2 through 4 5 nyiix-px.jfk01.twdx.net (198.32.160.208) 2/2/2 ±0ms 6 bbr02-ae-4-901.bos01.twdx.net (198.160.63.126) 7/7/7 ±0ms 7 dcr03-hu-0-8-0-0.bsn04.twdx.net (198.160.62.201) 7/7/7 ±0ms ** [firewall] the next gateway may statefully inspect packets 8 mass-ix.fsf.org (206.53.143.61) 7/7/7 ±0ms 9 [target open] eggs.gnu.org (209.51.188.92):587 7.4ms
Send what the firewall expects
Default TCP SYN to port 443 — the one packet every border admits. Or -F FIN probes, -E adaptive, -u UDP, -p ICMP, -P RFC 1393. One probe method per trace, chosen by flag.
Read what's in the way
Adaptive mode cycles FIN, SYN-ACK and SYN and labels what it meets: a stateful inspector, a flag-based filter, a broken stack. The trace ends with a verdict — [target open], [target closed], [target filtered].
Every hop, owned
-A names the origin AS of every router straight from the live routing table via Prefix WhoIs (or RIPE RIS, Cymru, RADB); -N adds the network name. ASNs from the global routing table, not the paperwork.
What's new in LFT 4
IPv6 end to end, ECMP enumeration, nine output formats, a live watch mode with a path-change detector, WhoB annotation of any text, and a hardened privilege model. 4.01 is a maintenance release: it fixes interface selection on hosts with many network interfaces (VPN tunnels, VM bridges), and lft -v / whob -v now print the version. Full detail in the changelog.
End to end
The same default TCP method over IPv6; family matched to the target, forced with -4/-6; reverse DNS, whois and PMTUD via ICMPv6 Packet Too Big all resolve v6 hops.
Where one hop becomes three
Varies the source port per probe and sends more probes per hop so every load-balanced member appears — drawn as a diamond in every diagram.
ECMP →Same trace, nine renderings
Text, -o ASCII, -x XML, -g GraphViz, --svg, --mermaid, --json, --geojson, --kml. Keys never vanish; enums only grow.
Learn the path, then watch for changes
Continuous monitoring with per-hop loss, RTT, jitter and ownership — and a path-change detector that tells a reroute from a flap and an ECMP shift.
Watch mode →Tag every address in anything
Pipe any text through whob -e and every IPv4 or IPv6 address comes back followed by [ASn Org-Name]. Pick fields with -F.
Built defensively
Bounds-checked parsers throughout, least-privilege operation, and a clear security model documented for auditors and packagers.
Security model →┌──┤ Layer Four Traceroute (LFT) ├───────────┤ End-to-End RTT 7–17ms, 9 hops to tcp://eggs.gnu.org:587 ├────────────────────────────┤ Candlestick ├──┐ │ │ │ ┌─── SOURCE ────┐ ┌── HOP 1 ──┐ ┌─── HOP 2 ───┐ ┌ HOP 3 ┐ ┌── HOP 4 ───┐ ┌── HOP 5 ───┐ ┌── HOP 6 ───┐ ┌── HOP 7 ───┐ │ │ 1ms max 2ms max ░░░░░░░ 1ms max 7ms max 8ms max 7ms max │ │17ms ┤ ░░░░░░░ │ │ │ ░░░░░░░ │ │12ms ┤ ░░░░░░░ │ │ │ ░░░░░░░ │ │ 8ms ┤ ░░░░░░░ ─────┬────── ████████████ ████████████ │ │ │ ░░░░░░░ │ ─────┴────── ─────┴────── │ │ 3ms ┤ ─────┬───── ──────┬────── ░░░░░░░ ─────┬────── ████████████ │ │ │ ███████████ █████████████ ░░░░░░░ ████████████ │ │ 0ms min 0ms min ░░░░░░░ 1ms min 2ms min 6ms min 7ms min │ │ └─── SOURCE ────┘ └── HOP 1 ──┘ └─── HOP 2 ───┘ └ HOP 3 ┘ └── HOP 4 ───┘ └── HOP 5 ───┘ └── HOP 6 ───┘ └── HOP 7 ───┘ │ │ 104.248.55.1:522… -> 198.211.111.7 -> 143.244.192.144 -> cloaked -> 143.244.225.21 -> 198.32.160.208 -> 198.160.63.126 -> 198.160.62.201 │ │ 0/0/1ms 0/0/2ms TTL 3 1/1/1ms 2/2/7ms 6/7/8ms 7/7/7ms │ │ │ │ ┌── HOP 8 ──┐ ┌── HOP 9 ──┐ ┌ HOP 10-11 ┐ │ │ 7ms max 17ms max ░░░░░░░░░░░ │ │17ms ┤ ─────┬───── ░░░░░░░░░░░ │ │ │ │ ░░░░░░░░░░░ │ │12ms ┤ │ ░░░░░░░░░░░ │ │ │ ███████████ ░░░░░░░░░░░ │ │ 8ms ┤ ███████████ ─────┴───── ░░░░░░░░░░░ │ │ │ ─────┴───── ░░░░░░░░░░░ │ │ 3ms ┤ ░░░░░░░░░░░ │ ├────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤ │ HOP HOST LOSS% MIN AVG MAX JIT ASN NETNAME ORGNAME │ │ 1m ──────── current │ │ 1 198.211.111.7 0% 0.3 0 1.4 1 AS14061 DIGITALOCEAN-198 DigitalOcean, LLC ▂▂▂▂▃▂▂▂▃▂▂▂▂▂▃▄▂▃▂▂│ │ 2 143.244.192.144 0% 0.3 0 2.3 2 - - - ▂▂▂▂▂▂▂▂▂▂▁▂▂▁▂▂▂▂▂▂│ │ 3 * 100% 0.0 0 0.0 0 - - - ▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪│ │ 4 ae5.iar2.us-ewr1.as14061.net 5% 0.6 1 1.4 1 - - - ▆▅▅▃▅▄▄▄▄▄▄▄▅▃▄▄▄▄▄▄│ │ 5 nyiix-px.jfk01.twdx.net 0% 1.6 2 6.6 5 - - - ▃▃▃▃▃▃▃▂▂▃▃▄▂▂▃▃▂▃▃▃│ │ 6 bbr02-ae-4-901.bos01.twdx.net 23% 6.3 7 8.1 2 AS27552 TWDX-NETBLK-ARIN TowardEX Technologie ▪▆▪▇▪▇▪▆▆▆▪▆▪▇▆▇▆▆▆▆│ │ 7 dcr03-hu-0-8-0-0.bsn04.twdx.net 65% 6.6 7 7.5 1 AS27552 TWDX-NETBLK-ARIN TowardEX Technologie ▪▇▪▇▪▇▪▇▪▪▪▇▪▪▪▪▪▪▇▪│ │ 8 mass-ix.fsf.org 81% 6.3 7 7.5 1 - - - ▪▪▪▪▪▪▪▪▪▪▪█▪▪▪▪▪▪▪▪│ │ 9 eggs.gnu.org 88% 6.5 9 17.2 11 AS22989 HURRICANE-5 Hurricane Electric L ▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪│ │ *** PATH CHANGE DETECTED at 19:09:53 *** │ │ │ │ ⋮ │ └──┤ ⠦ ↓241 ↑479 ⬡ 9 ✔ ├────────────────────┤ Idle ~5s Cycle 43/∞ tcp://eggs.gnu.org:587 ├──────────────────────────────────────────────────┘
Enrich every IP address in your output.
Pipe anything through whob -e and each IPv4 or IPv6 address comes back tagged with the AS that announces it. Or ask about one address and get the routing-table answer in one line.
$ echo "2001:4860:4860::8888 and [2606:4700:4700::1111]:53" | whob -e 2001:4860:4860::8888 [AS15169 Google LLC] and [2606:4700:4700::1111]:53 [AS13335 Cloudflare, Inc.] $ whob -gnp 4.2.2.1 4.2.2.1 | origin-as 3356 (4.0.0.0/9) | as-path 8220 1299 3356 | LVLT-ORG-4-8 | Level 3 Parent, LLC $ whob me 203.0.113.7
Download
Credits and thanks
We thank the following contributors who coded, tested or debugged LFT (not intentionally ordered):
- Victor Opplemanproject maintainer, contributor
- Eugene Antsilevitchcontributor
- Sergey Kondryukovcontributor
- Zachary Kannercontributor
- Lane Daviscontributor
- Robb Ballardpackage maintainer
- Florin Andreipackage maintainer
- Jim McKimSolaris port contributor
- Nils McCarthyFFT's original author
Authors' note
To those who would ask "who did that first?" with regard to utilizing TCP for traceroute, the answer is "we don't know." LFT was first released to the public in 1998 under the name FFT, and that was the first we had heard of.
Reporting bugs
Send bug reports through the contact form (choose Technical Support) and include level-2 verbose output: lft -VV <target>.
LFT and WhoB are released under our open source license.