Skip to content

Ping and Traceroute guide

Tool guide. Updated .

How the XGM Ping and Traceroute tools test a public host from the XGM server, what latency, packet loss and hops mean, and why some hosts never reply.

What ping measures

Ping sends small ICMP echo request packets and waits for echo replies. Each reply shows the round-trip time, the time from sending the request to receiving the answer. The summary adds packet loss, the share of requests that got no answer, and the minimum, average and maximum round-trip times.

The XGM Ping tool resolves the host name first, checks that the address is public, and pings that exact address from the XGM server. The result therefore shows reachability from a server on the internet, not from your own connection. The resolved address is shown with the result, so you know which of several addresses was tested.

What happens during an XGM pingThe host name is resolved to a public address, ten echo requests are sent from the XGM server, replies are timed, and the result shows loss and round-trip times.Resolve example.comPrivate, loopback and internal addresses arerefusedSend 10 ICMP echo requestsHalf a second apart; each waits up to 2seconds for a replyRecord repliesRound-trip time per reply in millisecondsSummariseTransmitted, received, loss %, min / avg / maxIf ICMP is unavailableFallback: TCP connection tests on ports 443and 80
The host name is resolved to a public address, ten echo requests are sent from the XGM server, replies are timed, and the result shows loss and round-trip times.

How to use Ping and Traceroute

  1. Open Ping and enter a public host name or IP address, for example example.com or 192.0.2.80.
  2. Read the verdict: all replies, partial loss, or no replies, with the probed address.
  3. If there is loss or high latency, switch to Traceroute mode with the same host to see the path.
  4. Compare with a test from your own network (ping and traceroute or tracert on your computer) to tell local problems from remote ones.
The same tests from your computer
# Linux and macOS
ping -c 4 example.com
traceroute example.com

# Windows
ping -n 4 example.com
tracert example.com

Reading ping results

Ping verdicts
VerdictMeaningWhat to do
Replied to every packetThe host answers ICMP with no lossReachability is fine; look at latency if something feels slow
Lost n% of packetsSome requests got no replyRun again; persistent loss suggests congestion or a failing link
No repliesEvery request timed outICMP may be blocked; test the service with the Port Scanner
Accepts TCP connectionsICMP was not available on the XGM server, so TCP ports 443/80 were testedThe host is reachable on those ports
Rough latency expectations
Round-trip timeTypical situation
Under 20 msSame city or region, or a nearby CDN edge
20–80 msSame continent
80–200 msBetween continents
Over 200 msVery long paths, satellite links or congestion

Latency depends on physical distance more than anything else, because light in fibre takes time. A host behind a CDN often answers from a location close to the XGM server, which says little about the origin server's location. Variation between replies, called jitter, matters for voice and video more than the average does.

Why a host does not answer ping

Many networks drop ICMP echo requests on purpose, either at a firewall or on the host itself. Cloud providers often block it by default in security groups, and some large services rate-limit or ignore ping entirely. The website or mail server can be completely healthy while ping shows 100% loss.

To test a service rather than ICMP, connect to its port. The Port Scanner tests TCP ports such as 443 for HTTPS or 25 for mail, and the HTTP Headers Checker shows whether a website actually responds. A host that refuses ping but accepts connections on 443 is up.

Allowing ping on your server

If you want monitoring by ping, allow ICMP echo requests in the host firewall and in any cloud security group. Rate-limit them rather than blocking completely; modern systems handle ICMP safely.

Reading a traceroute

Traceroute sends packets with increasing hop limits. Each router that discards a packet because the limit was reached answers with an ICMP time-exceeded message, which reveals its address and the time to reach it. The result is a list of hops from the XGM server toward the host, up to 12 hops.

Example traceroute output
 1  192.0.2.1        0.6 ms
 2  198.51.100.9     1.8 ms
 3  * * *
 4  203.0.113.14    12.4 ms
 5  203.0.113.77    13.1 ms
 6  192.0.2.80      13.6 ms  reached
Patterns in traceroute output
PatternUsually means
* * * on one hop, later hops fineThat router does not answer traceroute probes; not a problem
Latency jumps at one hop and stays higherA long physical link, such as crossing an ocean
Latency jumps at one hop, then drops againThat router deprioritises its own replies; not a problem
Stars from some hop to the endA firewall blocks the probes, or the path is broken there
Same addresses repeatingA routing loop

Only a problem that persists to the final hop matters. Routers often answer traceroute slowly or not at all while forwarding real traffic perfectly, so a single slow or silent hop in the middle is rarely the cause of anything.

Using the results to troubleshoot

  1. Ping from XGM and from your own network. If XGM reaches the host and you do not, the problem is between you and the internet.
  2. If neither reaches it, test the service port. If the port answers, only ICMP is blocked.
  3. If loss or latency starts at a hop and continues to the destination, the problem is at or after that network; the owner of the addresses can be found with the IP Intelligence.
  4. Check DNS: a host name that resolves to an old address sends the ping to the wrong machine. Use DNS Lookup.
  5. Share the result with your provider, including the time of the test, the probed address and the traceroute.

For intermittent problems, run the checks several times over a period. A single run can hit a brief spike, and the pattern over time is more convincing evidence for a provider support ticket.

FAQ

Why does ping show 100% loss for a website that works?

The host or its firewall blocks ICMP echo requests. Test the website's port with the Port Scanner instead.

Can I ping a private IP address?

No. XGM refuses private, loopback and internal addresses, because the test runs from a public server.

Why is the probed IP different from the one I expected?

The host name has several addresses, or resolves differently from the XGM server than from your network, for example through a CDN. The result shows the exact address tested.

What is a good ping time?

It depends on distance. Tens of milliseconds within a continent are normal, over 100 milliseconds between continents is expected.

What does * * * mean in traceroute?

That hop did not answer the probe in time. If later hops answer, the router just ignores traceroute and the path is fine.

Does ping use a port?

No. ICMP has no ports. When ICMP is unavailable, the tool falls back to TCP connection tests on ports 443 and 80 and says so.

Why does the traceroute stop before the destination?

Firewalls near the destination often drop traceroute probes, and the tool stops after 12 hops. A service can still be reachable; test its port.

Is IPv6 supported?

Addresses are accepted when the XGM server can reach them. If a host name has both IPv4 and IPv6 addresses, one of them is chosen and shown with the result.

Sources