Skip to content
IPv4 cache refreshed 13 hr ago  ◆  IPv6 cache refreshed 12 hr ago  ◆  Prefixes in table 1,130,904 v4 · 263,906 v6  ◆  Peers 96 v4 · 22 v6  ◆  whois.pwhois.org:43 answering  ◆ 
Prefix WhoIs The Prefix
WhoIs Project
layer four traceroute · since 1998

Traceroute for modern networks.

TCP, UDP, ICMP and adaptive probes that pass firewalls, expose ECMP forks, find the path MTU and name every network in the way. IPv4 and IPv6. Open source, with WhoB — the one-line whois — in every tarball.

lft -S -E eggs.gnu.org:587
[host]$ lft -S -E eggs.gnu.org:587

TTL LFT trace to eggs.gnu.org (209.51.188.92):587/tcp
 1  192.0.2.1 0/1/1 ±0ms
**  [neglected] no reply packets received from TTLs 2 through 4
 5  nyiix-px.jfk01.twdx.net (198.32.160.208) 2/2/2 ±0ms
 6  bbr02-ae-4-901.bos01.twdx.net (198.160.63.126) 7/7/7 ±0ms
 7  dcr03-hu-0-8-0-0.bsn04.twdx.net (198.160.62.201) 7/7/7 ±0ms
**  [firewall] the next gateway may statefully inspect packets
 8  mass-ix.fsf.org (206.53.143.61) 7/7/7 ±0ms
 9  [target open] eggs.gnu.org (209.51.188.92):587 7.4ms
trace the protocol path, not just the network path
ENGINES

Send what the firewall expects

Default TCP SYN to port 443 — the one packet every border admits. Or -F FIN probes, -E adaptive, -u UDP, -p ICMP, -P RFC 1393. One probe method per trace, chosen by flag.

Engines & builder →
FIREWALLS

Read what's in the way

Adaptive mode cycles FIN, SYN-ACK and SYN and labels what it meets: a stateful inspector, a flag-based filter, a broken stack. The trace ends with a verdict — [target open], [target closed], [target filtered].

Getting through →
NAMES

Every hop, owned

-A names the origin AS of every router straight from the live routing table via Prefix WhoIs (or RIPE RIS, Cymru, RADB); -N adds the network name. ASNs from the global routing table, not the paperwork.

See examples →
new in 4.01

What's new in LFT 4

IPv6 end to end, ECMP enumeration, nine output formats, a live watch mode with a path-change detector, WhoB annotation of any text, and a hardened privilege model. 4.01 is a maintenance release: it fixes interface selection on hosts with many network interfaces (VPN tunnels, VM bridges), and lft -v / whob -v now print the version. Full detail in the changelog.

IPv6

End to end

The same default TCP method over IPv6; family matched to the target, forced with -4/-6; reverse DNS, whois and PMTUD via ICMPv6 Packet Too Big all resolve v6 hops.

--ecmp

Where one hop becomes three

Varies the source port per probe and sends more probes per hop so every load-balanced member appears — drawn as a diamond in every diagram.

ECMP →
OUTPUTS

Same trace, nine renderings

Text, -o ASCII, -x XML, -g GraphViz, --svg, --mermaid, --json, --geojson, --kml. Keys never vanish; enums only grow.

Outputs →
--watch

Learn the path, then watch for changes

Continuous monitoring with per-hop loss, RTT, jitter and ownership — and a path-change detector that tells a reroute from a flap and an ECMP shift.

Watch mode →
WHOB --annotate

Tag every address in anything

Pipe any text through whob -e and every IPv4 or IPv6 address comes back followed by [ASn Org-Name]. Pick fields with -F.

WhoB →
HARDENED

Built defensively

Bounds-checked parsers throughout, least-privilege operation, and a clear security model documented for auditors and packagers.

Security model →
--watch Watch mode, 43 cycles into a live session: candlesticks per hop, enrichment from Prefix WhoIs, and a path change caught as it happened. See watch mode →
┌──┤ Layer Four Traceroute (LFT) ├───────────┤ End-to-End RTT 7–17ms, 9 hops to tcp://eggs.gnu.org:587 ├────────────────────────────┤ Candlestick ├──┐
│                                                                                                                                                    │
│       ┌─── SOURCE ────┐    ┌── HOP 1 ──┐    ┌─── HOP 2 ───┐    ┌ HOP 3 ┐    ┌── HOP 4 ───┐    ┌── HOP 5 ───┐    ┌── HOP 6 ───┐    ┌── HOP 7 ───┐   │
│                               1ms max           2ms max         ░░░░░░░        1ms max           7ms max           8ms max           7ms max       │
│17ms ┤                                                           ░░░░░░░                                                                            │
│     │                                                           ░░░░░░░                                                                            │
│12ms ┤                                                           ░░░░░░░                                                                            │
│     │                                                           ░░░░░░░                                                                            │
│ 8ms ┤                                                           ░░░░░░░                        ─────┬──────      ████████████      ████████████    │
│     │                                                           ░░░░░░░                             │            ─────┴──────      ─────┴──────    │
│ 3ms ┤                       ─────┬─────      ──────┬──────      ░░░░░░░      ─────┬──────      ████████████                                        │
│     │                       ███████████      █████████████      ░░░░░░░      ████████████                                                          │
│                               0ms min           0ms min         ░░░░░░░        1ms min           2ms min           6ms min           7ms min       │
│       └─── SOURCE ────┘    └── HOP 1 ──┘    └─── HOP 2 ───┘    └ HOP 3 ┘    └── HOP 4 ───┘    └── HOP 5 ───┘    └── HOP 6 ───┘    └── HOP 7 ───┘   │
│       104.248.55.1:522… -> 198.211.111.7 -> 143.244.192.144 ->  cloaked  -> 143.244.225.21 -> 198.32.160.208 -> 198.160.63.126 -> 198.160.62.201   │
│                               0/0/1ms           0/0/2ms          TTL 3         1/1/1ms           2/2/7ms           6/7/8ms           7/7/7ms       │
│                                                                                                                                                    │
│       ┌── HOP 8 ──┐    ┌── HOP 9 ──┐    ┌ HOP 10-11 ┐                                                                                              │
│          7ms max         17ms max        ░░░░░░░░░░░                                                                                               │
│17ms ┤                   ─────┬─────      ░░░░░░░░░░░                                                                                               │
│     │                        │           ░░░░░░░░░░░                                                                                               │
│12ms ┤                        │           ░░░░░░░░░░░                                                                                               │
│     │                   ███████████      ░░░░░░░░░░░                                                                                               │
│ 8ms ┤  ███████████      ─────┴─────      ░░░░░░░░░░░                                                                                               │
│     │  ─────┴─────                       ░░░░░░░░░░░                                                                                               │
│ 3ms ┤                                    ░░░░░░░░░░░                                                                                               │
├────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ HOP  HOST                             LOSS%  MIN     AVG     MAX     JIT   ASN       NETNAME           ORGNAME                                     │
│                                                                                                                                1m ──────── current │
│   1  198.211.111.7                    0%     0.3     0       1.4     1     AS14061   DIGITALOCEAN-198  DigitalOcean, LLC       ▂▂▂▂▃▂▂▂▃▂▂▂▂▂▃▄▂▃▂▂│
│   2  143.244.192.144                  0%     0.3     0       2.3     2     -         -                 -                       ▂▂▂▂▂▂▂▂▂▂▁▂▂▁▂▂▂▂▂▂│
│   3  *                                100%   0.0     0       0.0     0     -         -                 -                       ▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪│
│   4  ae5.iar2.us-ewr1.as14061.net     5%     0.6     1       1.4     1     -         -                 -                       ▆▅▅▃▅▄▄▄▄▄▄▄▅▃▄▄▄▄▄▄│
│   5  nyiix-px.jfk01.twdx.net          0%     1.6     2       6.6     5     -         -                 -                       ▃▃▃▃▃▃▃▂▂▃▃▄▂▂▃▃▂▃▃▃│
│   6  bbr02-ae-4-901.bos01.twdx.net    23%    6.3     7       8.1     2     AS27552   TWDX-NETBLK-ARIN  TowardEX Technologie    ▪▆▪▇▪▇▪▆▆▆▪▆▪▇▆▇▆▆▆▆│
│   7  dcr03-hu-0-8-0-0.bsn04.twdx.net  65%    6.6     7       7.5     1     AS27552   TWDX-NETBLK-ARIN  TowardEX Technologie    ▪▇▪▇▪▇▪▇▪▪▪▇▪▪▪▪▪▪▇▪│
│   8  mass-ix.fsf.org                  81%    6.3     7       7.5     1     -         -                 -                       ▪▪▪▪▪▪▪▪▪▪▪█▪▪▪▪▪▪▪▪│
│   9  eggs.gnu.org                     88%    6.5     9       17.2    11    AS22989   HURRICANE-5       Hurricane Electric L    ▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪▪│
│                                                      *** PATH CHANGE DETECTED at 19:09:53 ***                                                      │
│                                                                                                                                                    │
│  ⋮                                                                                                                                                 │
└──┤ ⠦  ↓241   ↑479   ⬡ 9  ✔ ├────────────────────┤ Idle  ~5s  Cycle 43/∞  tcp://eggs.gnu.org:587 ├──────────────────────────────────────────────────┘
whob

Enrich every IP address in your output.

Pipe anything through whob -e and each IPv4 or IPv6 address comes back tagged with the AS that announces it. Or ask about one address and get the routing-table answer in one line.

whob
$ echo "2001:4860:4860::8888 and [2606:4700:4700::1111]:53" | whob -e
2001:4860:4860::8888 [AS15169 Google LLC] and [2606:4700:4700::1111]:53 [AS13335 Cloudflare, Inc.]

$ whob -gnp 4.2.2.1
4.2.2.1 | origin-as 3356 (4.0.0.0/9) | as-path 8220 1299 3356 | LVLT-ORG-4-8 | Level 3 Parent, LLC

$ whob me
203.0.113.7

Download

505 KB · released September 2026 · includes whob
MD5fd76432d9aa490034aa807710dfbd0b0
SHA-25677a2923dbd10b1e3d2b55d8f3c4144795a80f73772d4f41f5e27751d1f3f0c62
Verify before you build: shasum -a 256 lft-4.01.tar.gz
Direct link for scripts and packagers: https://pwhois.org/get/lft-4.01.tar.gz · release notes
Source only. Build with ./configure && make (Build & install →), or install the package: brew install lft (Homebrew) · pkg install lft (FreeBSD) · pkgin install lft (pkgsrc) · port install lft (MacPorts).
A few emails a year, only when a release ships. Privacy notice.

Credits and thanks

We thank the following contributors who coded, tested or debugged LFT (not intentionally ordered):

  • Victor Opplemanproject maintainer, contributor
  • Eugene Antsilevitchcontributor
  • Sergey Kondryukovcontributor
  • Zachary Kannercontributor
  • Lane Daviscontributor
  • Robb Ballardpackage maintainer
  • Florin Andreipackage maintainer
  • Jim McKimSolaris port contributor
  • Nils McCarthyFFT's original author

Authors' note

To those who would ask "who did that first?" with regard to utilizing TCP for traceroute, the answer is "we don't know." LFT was first released to the public in 1998 under the name FFT, and that was the first we had heard of.

Reporting bugs

Send bug reports through the contact form (choose Technical Support) and include level-2 verbose output: lft -VV <target>.

LFT and WhoB are released under our open source license.