TT Lab
Get started
Learn Learning paths Courses

Network Troubleshooting

Checking Reachability and Paths

Continue in TT Lab

Goal

You read interfaces and routing, interpret ping statistics, and run UDP-mode traceroute and mtr. At the end you prove for yourself that ICMP reachability and TCP reachability are different questions.

Why it matters

ping proves only up to the IP layer. It does not prove the port above it, the application, or even whether a large packet can pass. Conversely, a ping failure does not mean the server is down — many organizations block ICMP echo. In this lab environment, capabilities have been removed, so traceroute's ICMP mode and mtr's default mode do not work. This constraint itself is a good teaching aid: some diagnostic tools require privileges, and in an environment without privileges you need to know the alternative modes.

Steps

  1. Create the /root/reach directory and save a one-line-per-interface summary to /root/reach/iface.txt. lo must be included.
  2. Save the routing table to /root/reach/route.txt. There must be a line starting with default.
  3. Save the full output of a 3-count ping to 127.0.0.1 to /root/reach/ping-loop.txt. Packet loss must be 0%.
  4. Save the output of a 3-count ping to your own default interface IP to /root/reach/ping-self.txt. Loss must be 0%.
  5. From the step 3 result, write only the three RTT values min / avg / max, separated by spaces, on one line in /root/reach/rtt.txt.
  6. Run traceroute to 127.0.0.1, save the output to /root/reach/trace.txt, and write the mode you used, in lowercase, on one line in /root/reach/trace-mode.txt (udp, icmp, or tcp).
  7. Run an mtr report to 127.0.0.1 for 3 cycles and save it to /root/reach/mtr.txt. The Loss% header must be included.
  8. Make /root/reach/summary.txt with the following 3 lines. Each value must be the result of actually trying it. icmp=<ok|fail> / tcp2222=<ok|fail> / tcp9999=<ok|fail> (You judge ICMP with 127.0.0.1, and TCP with the corresponding port of 127.0.0.1.)

Notes

Checking the interface list

Create the /root/reach directory and save a one-line-per-interface summary to /root/reach/iface.txt. lo must be included.

The ip command has a one-line summary format (-br). Both the loopback and the real interface must be visible.

Checking the routing table

Save the routing table to /root/reach/route.txt. There must be a line starting with default.

The default route is the line that starts with default. The gateway address comes after via.

Loopback ping

Save the full output of a 3-count ping to 127.0.0.1 to /root/reach/ping-loop.txt. Packet loss must be 0%.

If you set the count with -c, the statistics summary is printed at the end. The loss rate is on that summary line.

Ping to your own IP

Save the output of a 3-count ping to your own default interface IP to /root/reach/ping-self.txt. Loss must be 0%.

Use the interface address you confirmed in step 01. A packet going to yourself must have no loss either.

Reading the RTT statistics

From the step 3 result, write only the three RTT values min / avg / max, separated by spaces, on one line in /root/reach/rtt.txt.

On the last line of the statistics, min/avg/max/mdev come out separated by slashes. Pull out only the first three values.

UDP-mode traceroute

Run traceroute to 127.0.0.1, save the output to /root/reach/trace.txt, and write the mode you used, in lowercase, on one line in /root/reach/trace-mode.txt (udp, icmp, or tcp).

This environment has no raw socket permission, so ICMP mode does not work. Check what traceroute's default mode is.

mtr report

Run an mtr report to 127.0.0.1 for 3 cycles and save it to /root/reach/mtr.txt. The Loss% header must be included.

mtr also needs UDP mode for the same reason. Use together the report mode that runs once and ends and the option that specifies the count.

Comparing ICMP and TCP

Make /root/reach/summary.txt with the following 3 lines. Each value must be the result of actually trying it. icmp=<ok|fail> / tcp2222=<ok|fail> / tcp9999=<ok|fail> (You judge ICMP with 127.0.0.1, and TCP with the corresponding port of 127.0.0.1.)

sshd is running on 2222 and nobody is listening on 9999. Think about what each of the three results proves.