examples
Real commands, real output.
Grouped by question, not by flag. Traces are reproduced from lft(8) and whob(1); source-side hops use documentation-range addresses. Copy any of them.
"Is the port open, and where does it get filtered?"
A plain TCP trace. Silent TTLs are listed as a [neglected] run, a reused-TTL gateway is called out, and the trace ends with a verdict. · Firewalls →
lft -S 4.2.2.2
[edge.lax]$ lft -S 4.2.2.2 TTL LFT trace to vnsc-bak.sys.gtei.net (4.2.2.2):80/tcp 1 ln-gateway.centergate.com (206.117.161.1) 0.5ms 2 isi-acg.ln.net (130.152.136.1) 2.3ms 3 isi-1-lngw2-atm.ln.net (130.152.180.21) 2.5ms 4 gigabitethernet5-0.lsanca1-cr3.bbnplanet.net (4.24.4.249) 3.0ms 5 p6-0.lsanca1-cr6.bbnplanet.net (4.24.4.2) 3.4ms 6 p6-0.lsanca2-br1.bbnplanet.net (4.24.5.49) 3.3ms 7 p15-0.snjpca1-br1.bbnplanet.net (4.24.5.58) 10.9ms 8 so-3-0-0.mtvwca1-br1.bbnplanet.net (4.24.7.33) 11.1ms 9 p7-0.mtvwca1-dc-dbe1.bbnplanet.net (4.24.9.166) 11.0ms 10 vlan40.mtvwca1-dc1-dfa1-rc1.bbnplanet.net (128.11.193.67) 11.1ms ** [neglected] no reply packets received from TTLs 11 through 20 ** [4.2-3 BSD bug?] the next gateway may errantly reply with reused TTLs 21 [target open] vnsc-bak.sys.gtei.net (4.2.2.2):80 11.2ms
lft -S 4.2.2.2"What is in the way?"
Adaptive mode cycles FIN, SYN-ACK and SYN and names the stateful inspector it meets. · Firewalls →
lft -S -E eggs.gnu.org:587
[host]$ lft -S -E eggs.gnu.org:587 TTL LFT trace to eggs.gnu.org (209.51.188.92):587/tcp 1 192.0.2.1 0/1/1 ±0ms ** [neglected] no reply packets received from TTLs 2 through 4 5 nyiix-px.jfk01.twdx.net (198.32.160.208) 2/2/2 ±0ms 6 bbr02-ae-4-901.bos01.twdx.net (198.160.63.126) 7/7/7 ±0ms 7 dcr03-hu-0-8-0-0.bsn04.twdx.net (198.160.62.201) 7/7/7 ±0ms ** [firewall] the next gateway may statefully inspect packets 8 mass-ix.fsf.org (206.53.143.61) 7/7/7 ±0ms 9 [target open] eggs.gnu.org (209.51.188.92):587 7.4ms
lft -S -E eggs.gnu.org:587"Whose routers are these?"
AS numbers from Prefix WhoIs on every hop, with timers and a source port of 53. · Engines & builder →
lft -S -A -T -d 80 -s 53 www.yahoo.com
[edge.lax]$ lft -S -A -T -d 80 -s 53 www.yahoo.com TTL LFT trace to w9.scd.yahoo.com (66.218.71.88):80/tcp 1 [226] ln-gateway.centergate.com (206.117.161.1) 1.0ms 2 [226] isi-acg.ln.net (130.152.136.1) 2.0ms 3 [226] isi-1-lngw2-atm.ln.net (130.152.180.21) 3.0ms 4 [1] gigether5-0.lsanca1-cr3.bbnplanet.net (4.24.4.249) 3.0ms 5 [1] p6-0.lsanca1-cr6.bbnplanet.net (4.24.4.2) 5.0ms 6 [1] p6-0.lsanca2-br1.bbnplanet.net (4.24.5.49) 3.0ms 7 [1] p1-0.lsanca2-cr2.bbnplanet.net (4.25.112.1) 3.0ms 8 [16852] pos4-0.core1.LosAngeles1.Level3.net (209.0.227.57) 3.0ms 9 [3356] so-4-0-0.mp1.LosAngeles1.Level3.net (209.247.10.193) 3.0ms 10 [3356] so-3-0-0.mp2.SanJose1.Level3.net (64.159.1.130) 11.0ms 11 [3356] gige10-0.ipcolo4.SanJose1.Level3.net (64.159.2.42) 11.0ms 12 [3356] cust-int.level3.net (64.152.81.62) 52.0ms 13 [10310] vl17.bas2.scd.yahoo.com (66.218.64.150) 53.0ms 14 [10310] [target open] w9.scd.yahoo.com (66.218.71.88):80 54.0ms
lft -S -A -T -d 80 -s 53 www.yahoo.com"Which network is each hop registered to?"
Netblock names with -N, ending at a filtered target. · Engines & builder →
lft -S -N www.microsoft.com
[edge.lax]$ lft -S -N www.microsoft.com TTL LFT trace to www.us.microsoft.com (207.46.197.113):80/tcp 1 [LOS-NETTOS-BLK4] ln-gateway.centergate.com (206.117.161.1) 2.0ms 2 [LOS-NETTOS] isi-acg.ln.net (130.152.136.1) 3.0ms 3 [LOS-NETTOS] isi-1-lngw2-pos.ln.net (130.152.80.30) 5.0ms 4 [GNTY-4-0] gigether5-0.lsanca1-cr3.bbnplanet.net (4.24.4.249) 4.0ms 5 [GNTY-4-0] p6-0.lsanca1-cr6.bbnplanet.net (4.24.4.2) 3.0ms 6 [GNTY-4-0] p6-0.lsanca2-br1.bbnplanet.net (4.24.5.49) 3.0ms 7 [GNTY-4-0] p15-0.snjpca1-br1.bbnplanet.net (4.24.5.58) 10.0ms 8 [GNTY-4-0] p9-0.snjpca1-br2.bbnplanet.net (4.24.9.130) 11.0ms 9 [GNTY-4-0] so-1-0-0.sttlwa2-br1.bbnplanet.net (4.0.3.229) 27.0ms 10 [GNTY-4-0] so-0-0-0.sttlwa1-hcr1.bbnplanet.net (4.24.11.202) 28.0ms 11 [GNTY-4-0] so-7-0-0.sttlwa1-hcr2.bbnplanet.net (4.24.10.234) 28.0ms 12 [GNTY-4-0] p1-0.sttlwa1-cr2.bbnplanet.net (4.24.10.241) 29.0ms 13 [GNTY-4-0] p2-0.msseattle.bbnplanet.net (4.25.89.6) 32.0ms 14 [MICROSOFT-GLOBAL-NET] 207.46.154.9 32.0ms 15 [MICROSOFT-GLOBAL-NET] 207.46.155.17 33.0ms 16 [MICROSOFT-GLOBAL-NET] [target filtered] 207.46.129.51:80 35.0ms
lft -S -N www.microsoft.com"Is this hop load-balanced?"
Three probes per hop with -m 3 catch a few ECMP members incidentally; --ecmp finds them all. · ECMP →
lft -S --ecmp -n www.yahoo.com
[edge.lax]$ lft -S --ecmp -n www.yahoo.com TTL LFT trace to 209.73.190.12:443/tcp 1 192.0.2.1 0/0/0 ±0ms 2 198.51.100.10 1/1/1 ±0ms ** [neglected] no reply packets received from TTL 3 4 184.104.193.142 9/11/13 ±1ms ** [neglected] no reply packets received from TTL 5 6 74.6.226.213 8/8/8 ±0ms │ 74.6.226.221 8/8/8 ±0ms │ 74.6.226.237 8.2ms │ 74.6.226.197 8.2ms │ 74.6.226.209 8/8/8 ±0ms │ 74.6.226.195 8.2ms │ 74.6.226.227 8.1ms │ 74.6.226.215 8.2ms │ 74.6.226.219 8.5ms │ 209.73.188.47 8/8/8 ±0ms │ 209.73.188.61 8/8/8 ±0ms │ 209.73.188.73 8/8/8 ±0ms 7 209.73.188.65 8/8/8 ±0ms │ 209.73.188.51 8.1ms │ 209.73.188.49 8/8/8 ±0ms │ 209.73.188.43 8.1ms ** [neglected] no reply packets received from TTLs 8 through 11 12 [target open] 209.73.190.12:443 8/8/8 ±0ms
lft -S --ecmp -n www.yahoo.com"Where does the MTU drop?"
IPv6 path MTU discovery: DF probes step down on Packet Too Big; the silent hop is flagged as the limit. · Engines & builder →
lft -S -6 -K mtu1280.test-ipv6.com:443
[host]$ lft -S -6 -K mtu1280.test-ipv6.com:443 TTL LFT trace to mtu1280.test-ipv6.com (2001:db8:1e::6666):443/tcp 1 2001:db8:4000:2::1 0.5ms 2 2001:db8:e:6b::1 10.8ms 3 2001:db8:30:2::1 10.2ms ** [MTU Limit] hop 4 did not respond to DF probe (1280 bytes, no PTB received) 5 2001:db8:30:3::71 10.1ms 6 [target open] 2001:db8:1e::6666:443 [MTU: 1280] 10.4ms
lft -S -6 -K mtu1280.test-ipv6.com:443"Give me the ASNs on the path as data."
JSON straight into jq. · Outputs →
lft --json -A www.example.com:443 | jq '[.hops[].responders[].asn | select(.)] | unique'
[edge.lax]$ lft --json -A www.example.com:443 | jq '[.hops[].responders[].asn | select(.)] | unique' … the distinct origin ASNs seen on the path, as a JSON array … # then, for the map: [edge.lax]$ lft --kml --geo-color rtt www.example.com:443 > path.kml
lft --json -A www.example.com:443 | jq '[.hops[].responders[].asn | select(.)] | unique'"Who routes this address? One line."
WhoB: origin ASN from the routing table, the prefix, and the network name. · WhoB →
whob 4.2.2.1
$ whob 4.2.2.1 4.2.2.1 | origin-as 3356 (4.0.0.0/8) | LVLT-ORG-4-8 $ whob -npr 204.74.68.0 204.74.68.0 | origin-as 226 (204.74.68.0/23) | radb-as 13361 | Internet Media Network $ whob me … your public address …
whob 4.2.2.1"Tag this log."
WhoB as a filter: every address in the input comes back with its AS and owner. · WhoB →
grep -h denied /var/log/firewall.log | whob --annotate | grep -oE 'AS[0-9]+ [^]]+' | sort | uniq -c | sort -rn
$ traceroute -n www.example.com | whob -e … every address tagged [ASn Org-Name] … $ grep -h denied /var/log/firewall.log | whob --annotate \ | grep -oE 'AS[0-9]+ [^]]+' | sort | uniq -c | sort -rn # illustrative: x 4.2.2.1 y → x 4.2.2.1 [AS3356 Level 3 Parent, LLC] y
grep -h denied /var/log/firewall.log | whob --annotate | grep -oE 'AS[0-9]+ [^]]+' | sort | uniq -c | sort -rn