Trace a Network Path and Discover Its MTU with tracepath

tracepath finds the hop-by-hop route to a host and the path MTU along it, without needing root the way a full traceroute setup sometimes does. This guide covers a basic trace, reading the hop and MTU output, testing IPv4 and IPv6 separately, and telling a completed trace from a blocked one. Allow about ten minutes.

You need a shell, a destination you are allowed to probe, and a working network connection. The examples use tracepath from iputils 20240117, installed here as package version 3:20240117-1ubuntu0.1. The command sends UDP probes and may be filtered by firewalls or routers. It does not need sudo or other elevated privileges.

Checkpoint: This guide observes a path only. It does not change routes, firewall rules, MTU settings or services.

1. Confirm the installed command

Check which executable will run and record the local version. Both commands are ordinary, read-only checks:

$ command -v tracepath
/usr/bin/tracepath
$ tracepath -V
tracepath from iputils 20240117
libcap: yes, IDN: yes, NLS: no, error.h: yes, getrandom(): yes, __fpending(): yes

Exact feature lines can differ between builds. The useful compatibility detail is the iputils release. This guide follows the options in the installed tracepath(8) manual rather than assuming another distribution has identical output.

2. Run a basic IPv4 trace

Replace HOSTNAME_OR_IP with a host you expect to reach. A DNS name is useful when you want names in the output; an IP address removes DNS lookup from the test:

$ tracepath HOSTNAME_OR_IP
 1:  router.example.net                                  0.412ms
 2:  198.51.100.1                                        4.891ms
 3:  203.0.113.25                                       12.447ms reached
     Resume: pmtu 1500 hops 3 back 3

For a local smoke test that does not depend on an external host, use loopback:

$ tracepath -n -m 1 127.0.0.1
 1:  127.0.0.1                                             0.052ms reached
     Resume: pmtu 65535 hops 1 back 1

Timing and spacing vary. What matters is exit status zero, reached, and a final pmtu value.

3. Make the output easier to scan

$ tracepath -n HOSTNAME_OR_IP
$ tracepath -b HOSTNAME_OR_IP
$ tracepath -n -m 5 HOSTNAME_OR_IP

Do not treat a missing name as a network failure. Name resolution and probe replies are separate things: start with -n when diagnosing a delay, then repeat with -b if names are useful. A maximum of five hops means the command may stop before the destination; that is a deliberate diagnostic limit, not evidence that the fifth router is broken.

4. Read hops, RTT and MTU changes

Each normal output line starts with the probe TTL, followed by the responding hop and an RTT in milliseconds. A question mark after the TTL means tracepath had to infer the value because the reply did not contain enough information.

The word asymm followed by a number is tracepath's estimate of the difference between forward and return hop counts. Treat it as a clue, not a packet-by-packet map of the reverse route: the manual explicitly warns that this estimate is not reliable in every case.

When the path MTU changes, a hop line may include pmtu N. The final resume line gives the path MTU detected for the completed view of the route. Path MTU is a property of this destination and path at this time; it is not necessarily the interface MTU or the maximum size available to every destination.

Tip: For IPv4, the installed manual explains that some commercial routers do not return enough information in ICMP errors. IPv6 generally gives tracepath the error-queue behaviour it needs more directly, but filtering can still hide hops or prevent completion.

5. Test IPv6 explicitly

Use -6 to force IPv6 rather than letting address selection choose between families:

$ tracepath -6 -n HOSTNAME_OR_IP
 1?: [LOCALHOST]                                          pmtu 1500
 1:  2001:db8::1                                           0.821ms
 2:  2001:db8::25                                         10.192ms reached
     Resume: pmtu 1500 hops 2 back 2

Use -4 for the equivalent IPv4-only test. These switches earn their keep when a hostname has both address families and only one route is failing:

$ tracepath -4 -n HOSTNAME_OR_IP

The [LOCALHOST] marker means the probe was not sent to a network hop. It is commonly seen on the first line while tracepath reports the local path MTU. Do not count that marker as a remote router.

6. Investigate an incomplete or failed trace

Run once with numeric output and a sensible hop limit before changing anything:

$ tracepath -n -m 30 HOSTNAME_OR_IP
$ printf 'exit status: %s\n' "$?"

Then look for one of the short error codes documented by tracepath(8):

OutputMeaning
!ACommunication administratively prohibited
!HDestination host unreachable
!NDestination network unreachable
pmtu NMessage too long for the reported path MTU
reachedThe destination replied with connection refused, which confirms the probe reached it
NET ERROR NAnother network error, with its numeric error value

Some destinations drop UDP probes, and some networks rate-limit or suppress ICMP errors, so a missing intermediate line is not proof that traffic cannot pass through that router. Compare -4 and -6, try -n, and confirm the destination name resolves to the address family you intended.

Warning: Do not fix a reported MTU by changing it immediately. First confirm the path and the application that fails. An MTU change affects other traffic and can disrupt a host or service. If an approved maintenance procedure does require a temporary change, record the previous value and use that procedure's rollback command; tracepath itself has no setting to undo.

7. Use packet length and port deliberately

-l pktlen changes the initial packet length. The manual's defaults are 65535 for IPv4 and 128000 for IPv6. A smaller explicit value can make a controlled test easier to compare, but it is not a request to change the interface MTU:

$ tracepath -n -4 -l 1400 HOSTNAME_OR_IP

Use -p port to set the initial destination UDP port when a network policy or test plan requires a particular port:

$ tracepath -n -p 33434 HOSTNAME_OR_IP

Only send probes to systems and ports covered by your operational authority. A selected port does not turn tracepath into an application connectivity test, and an allowed UDP probe does not prove that TCP or the target service is available.

Done means