Skip to content
IPv4 cache refreshed 26 hr ago  ◆  IPv6 cache refreshed 25 hr ago  ◆  Prefixes in table 1,107,739 v4 · 261,906 v6  ◆  Peers 91 v4 · 20 v6  ◆  whois.pwhois.org:43 answering  ◆ 
Prefix WhoIs The Prefix
WhoIs Project
examples

Real commands, real output.

Grouped by question, not by flag. Traces are reproduced from lft(8) and whob(1); source-side hops use documentation-range addresses. Copy any of them.

"Is the port open, and where does it get filtered?"
A plain TCP trace. Silent TTLs are listed as a [neglected] run, a reused-TTL gateway is called out, and the trace ends with a verdict. · Firewalls →
lft -S 4.2.2.2
[edge.lax]$ lft -S 4.2.2.2

TTL LFT trace to vnsc-bak.sys.gtei.net (4.2.2.2):80/tcp
 1  ln-gateway.centergate.com (206.117.161.1) 0.5ms
 2  isi-acg.ln.net (130.152.136.1) 2.3ms
 3  isi-1-lngw2-atm.ln.net (130.152.180.21) 2.5ms
 4  gigabitethernet5-0.lsanca1-cr3.bbnplanet.net (4.24.4.249) 3.0ms
 5  p6-0.lsanca1-cr6.bbnplanet.net (4.24.4.2) 3.4ms
 6  p6-0.lsanca2-br1.bbnplanet.net (4.24.5.49) 3.3ms
 7  p15-0.snjpca1-br1.bbnplanet.net (4.24.5.58) 10.9ms
 8  so-3-0-0.mtvwca1-br1.bbnplanet.net (4.24.7.33) 11.1ms
 9  p7-0.mtvwca1-dc-dbe1.bbnplanet.net (4.24.9.166) 11.0ms
10  vlan40.mtvwca1-dc1-dfa1-rc1.bbnplanet.net (128.11.193.67) 11.1ms
**  [neglected] no reply packets received from TTLs 11 through 20
**  [4.2-3 BSD bug?] the next gateway may errantly reply with reused TTLs
21  [target open] vnsc-bak.sys.gtei.net (4.2.2.2):80 11.2ms
lft -S 4.2.2.2
"What is in the way?"
Adaptive mode cycles FIN, SYN-ACK and SYN and names the stateful inspector it meets. · Firewalls →
lft -S -E eggs.gnu.org:587
[host]$ lft -S -E eggs.gnu.org:587

TTL LFT trace to eggs.gnu.org (209.51.188.92):587/tcp
 1  192.0.2.1 0/1/1 ±0ms
**  [neglected] no reply packets received from TTLs 2 through 4
 5  nyiix-px.jfk01.twdx.net (198.32.160.208) 2/2/2 ±0ms
 6  bbr02-ae-4-901.bos01.twdx.net (198.160.63.126) 7/7/7 ±0ms
 7  dcr03-hu-0-8-0-0.bsn04.twdx.net (198.160.62.201) 7/7/7 ±0ms
**  [firewall] the next gateway may statefully inspect packets
 8  mass-ix.fsf.org (206.53.143.61) 7/7/7 ±0ms
 9  [target open] eggs.gnu.org (209.51.188.92):587 7.4ms
lft -S -E eggs.gnu.org:587
"Whose routers are these?"
AS numbers from Prefix WhoIs on every hop, with timers and a source port of 53. · Engines & builder →
lft -S -A -T -d 80 -s 53 www.yahoo.com
[edge.lax]$ lft -S -A -T -d 80 -s 53 www.yahoo.com

TTL LFT trace to w9.scd.yahoo.com (66.218.71.88):80/tcp
 1  [226] ln-gateway.centergate.com (206.117.161.1) 1.0ms
 2  [226] isi-acg.ln.net (130.152.136.1) 2.0ms
 3  [226] isi-1-lngw2-atm.ln.net (130.152.180.21) 3.0ms
 4  [1] gigether5-0.lsanca1-cr3.bbnplanet.net (4.24.4.249) 3.0ms
 5  [1] p6-0.lsanca1-cr6.bbnplanet.net (4.24.4.2) 5.0ms
 6  [1] p6-0.lsanca2-br1.bbnplanet.net (4.24.5.49) 3.0ms
 7  [1] p1-0.lsanca2-cr2.bbnplanet.net (4.25.112.1) 3.0ms
 8  [16852] pos4-0.core1.LosAngeles1.Level3.net (209.0.227.57) 3.0ms
 9  [3356] so-4-0-0.mp1.LosAngeles1.Level3.net (209.247.10.193) 3.0ms
10  [3356] so-3-0-0.mp2.SanJose1.Level3.net (64.159.1.130) 11.0ms
11  [3356] gige10-0.ipcolo4.SanJose1.Level3.net (64.159.2.42) 11.0ms
12  [3356] cust-int.level3.net (64.152.81.62) 52.0ms
13  [10310] vl17.bas2.scd.yahoo.com (66.218.64.150) 53.0ms
14  [10310] [target open] w9.scd.yahoo.com (66.218.71.88):80 54.0ms
lft -S -A -T -d 80 -s 53 www.yahoo.com
"Which network is each hop registered to?"
Netblock names with -N, ending at a filtered target. · Engines & builder →
lft -S -N www.microsoft.com
[edge.lax]$ lft -S -N www.microsoft.com

TTL LFT trace to www.us.microsoft.com (207.46.197.113):80/tcp
 1  [LOS-NETTOS-BLK4] ln-gateway.centergate.com (206.117.161.1) 2.0ms
 2  [LOS-NETTOS] isi-acg.ln.net (130.152.136.1) 3.0ms
 3  [LOS-NETTOS] isi-1-lngw2-pos.ln.net (130.152.80.30) 5.0ms
 4  [GNTY-4-0] gigether5-0.lsanca1-cr3.bbnplanet.net (4.24.4.249) 4.0ms
 5  [GNTY-4-0] p6-0.lsanca1-cr6.bbnplanet.net (4.24.4.2) 3.0ms
 6  [GNTY-4-0] p6-0.lsanca2-br1.bbnplanet.net (4.24.5.49) 3.0ms
 7  [GNTY-4-0] p15-0.snjpca1-br1.bbnplanet.net (4.24.5.58) 10.0ms
 8  [GNTY-4-0] p9-0.snjpca1-br2.bbnplanet.net (4.24.9.130) 11.0ms
 9  [GNTY-4-0] so-1-0-0.sttlwa2-br1.bbnplanet.net (4.0.3.229) 27.0ms
10  [GNTY-4-0] so-0-0-0.sttlwa1-hcr1.bbnplanet.net (4.24.11.202) 28.0ms
11  [GNTY-4-0] so-7-0-0.sttlwa1-hcr2.bbnplanet.net (4.24.10.234) 28.0ms
12  [GNTY-4-0] p1-0.sttlwa1-cr2.bbnplanet.net (4.24.10.241) 29.0ms
13  [GNTY-4-0] p2-0.msseattle.bbnplanet.net (4.25.89.6) 32.0ms
14  [MICROSOFT-GLOBAL-NET] 207.46.154.9 32.0ms
15  [MICROSOFT-GLOBAL-NET] 207.46.155.17 33.0ms
16  [MICROSOFT-GLOBAL-NET] [target filtered] 207.46.129.51:80 35.0ms
lft -S -N www.microsoft.com
"Is this hop load-balanced?"
Three probes per hop with -m 3 catch a few ECMP members incidentally; --ecmp finds them all. · ECMP →
lft -S --ecmp -n www.yahoo.com
[edge.lax]$ lft -S --ecmp -n www.yahoo.com

TTL LFT trace to 209.73.190.12:443/tcp
 1  192.0.2.1 0/0/0 ±0ms
 2  198.51.100.10 1/1/1 ±0ms
**  [neglected] no reply packets received from TTL 3
 4  184.104.193.142 9/11/13 ±1ms
**  [neglected] no reply packets received from TTL 5
 6  74.6.226.213 8/8/8 ±0ms
 │  74.6.226.221 8/8/8 ±0ms
 │  74.6.226.237 8.2ms
 │  74.6.226.197 8.2ms
 │  74.6.226.209 8/8/8 ±0ms
 │  74.6.226.195 8.2ms
 │  74.6.226.227 8.1ms
 │  74.6.226.215 8.2ms
 │  74.6.226.219 8.5ms
 │  209.73.188.47 8/8/8 ±0ms
 │  209.73.188.61 8/8/8 ±0ms
 │  209.73.188.73 8/8/8 ±0ms
 7  209.73.188.65 8/8/8 ±0ms
 │  209.73.188.51 8.1ms
 │  209.73.188.49 8/8/8 ±0ms
 │  209.73.188.43 8.1ms
**  [neglected] no reply packets received from TTLs 8 through 11
12  [target open] 209.73.190.12:443 8/8/8 ±0ms
lft -S --ecmp -n www.yahoo.com
"Where does the MTU drop?"
IPv6 path MTU discovery: DF probes step down on Packet Too Big; the silent hop is flagged as the limit. · Engines & builder →
lft -S -6 -K mtu1280.test-ipv6.com:443
[host]$ lft -S -6 -K mtu1280.test-ipv6.com:443

TTL LFT trace to mtu1280.test-ipv6.com (2001:db8:1e::6666):443/tcp
 1  2001:db8:4000:2::1 0.5ms
 2  2001:db8:e:6b::1 10.8ms
 3  2001:db8:30:2::1 10.2ms
**  [MTU Limit] hop 4 did not respond to DF probe (1280 bytes, no PTB received)
 5  2001:db8:30:3::71 10.1ms
 6  [target open] 2001:db8:1e::6666:443 [MTU: 1280] 10.4ms
lft -S -6 -K mtu1280.test-ipv6.com:443
"Give me the ASNs on the path as data."
JSON straight into jq. · Outputs →
lft --json -A www.example.com:443 | jq '[.hops[].responders[].asn | select(.)] | unique'
[edge.lax]$ lft --json -A www.example.com:443 |
    jq '[.hops[].responders[].asn | select(.)] | unique'

… the distinct origin ASNs seen on the path, as a JSON array …

# then, for the map:
[edge.lax]$ lft --kml --geo-color rtt www.example.com:443 > path.kml
lft --json -A www.example.com:443 | jq '[.hops[].responders[].asn | select(.)] | unique'
"Who routes this address? One line."
WhoB: origin ASN from the routing table, the prefix, and the network name. · WhoB →
whob 4.2.2.1
$ whob 4.2.2.1
4.2.2.1 | origin-as 3356 (4.0.0.0/8) | LVLT-ORG-4-8

$ whob -npr 204.74.68.0
204.74.68.0 | origin-as 226 (204.74.68.0/23) | radb-as 13361 | Internet Media Network

$ whob me
… your public address …
whob 4.2.2.1
"Tag this log."
WhoB as a filter: every address in the input comes back with its AS and owner. · WhoB →
grep -h denied /var/log/firewall.log | whob --annotate | grep -oE 'AS[0-9]+ [^]]+' | sort | uniq -c | sort -rn
$ traceroute -n www.example.com | whob -e
… every address tagged [ASn Org-Name] …

$ grep -h denied /var/log/firewall.log | whob --annotate \
    | grep -oE 'AS[0-9]+ [^]]+' | sort | uniq -c | sort -rn

# illustrative: x 4.2.2.1 y  →  x 4.2.2.1 [AS3356 Level 3 Parent, LLC] y
grep -h denied /var/log/firewall.log | whob --annotate | grep -oE 'AS[0-9]+ [^]]+' | sort | uniq -c | sort -rn