Ping and Traceroute guide
How the XGM Ping and Traceroute tools test a public host from the XGM server, what latency, packet loss and hops mean, and why some hosts never reply.
What ping measures
Ping sends small ICMP echo request packets and waits for echo replies. Each reply shows the round-trip time, the time from sending the request to receiving the answer. The summary adds packet loss, the share of requests that got no answer, and the minimum, average and maximum round-trip times.
The XGM Ping tool resolves the host name first, checks that the address is public, and pings that exact address from the XGM server. The result therefore shows reachability from a server on the internet, not from your own connection. The resolved address is shown with the result, so you know which of several addresses was tested.
How to use Ping and Traceroute
- Open Ping and enter a public host name or IP address, for example
example.comor192.0.2.80. - Read the verdict: all replies, partial loss, or no replies, with the probed address.
- If there is loss or high latency, switch to Traceroute mode with the same host to see the path.
- Compare with a test from your own network (
pingandtracerouteortracerton your computer) to tell local problems from remote ones.
# Linux and macOS
ping -c 4 example.com
traceroute example.com
# Windows
ping -n 4 example.com
tracert example.comReading ping results
| Verdict | Meaning | What to do |
|---|---|---|
| Replied to every packet | The host answers ICMP with no loss | Reachability is fine; look at latency if something feels slow |
| Lost n% of packets | Some requests got no reply | Run again; persistent loss suggests congestion or a failing link |
| No replies | Every request timed out | ICMP may be blocked; test the service with the Port Scanner |
| Accepts TCP connections | ICMP was not available on the XGM server, so TCP ports 443/80 were tested | The host is reachable on those ports |
| Round-trip time | Typical situation |
|---|---|
| Under 20 ms | Same city or region, or a nearby CDN edge |
| 20–80 ms | Same continent |
| 80–200 ms | Between continents |
| Over 200 ms | Very long paths, satellite links or congestion |
Latency depends on physical distance more than anything else, because light in fibre takes time. A host behind a CDN often answers from a location close to the XGM server, which says little about the origin server's location. Variation between replies, called jitter, matters for voice and video more than the average does.
Why a host does not answer ping
Many networks drop ICMP echo requests on purpose, either at a firewall or on the host itself. Cloud providers often block it by default in security groups, and some large services rate-limit or ignore ping entirely. The website or mail server can be completely healthy while ping shows 100% loss.
To test a service rather than ICMP, connect to its port. The Port Scanner tests TCP ports such as 443 for HTTPS or 25 for mail, and the HTTP Headers Checker shows whether a website actually responds. A host that refuses ping but accepts connections on 443 is up.
Allowing ping on your server
Reading a traceroute
Traceroute sends packets with increasing hop limits. Each router that discards a packet because the limit was reached answers with an ICMP time-exceeded message, which reveals its address and the time to reach it. The result is a list of hops from the XGM server toward the host, up to 12 hops.
1 192.0.2.1 0.6 ms
2 198.51.100.9 1.8 ms
3 * * *
4 203.0.113.14 12.4 ms
5 203.0.113.77 13.1 ms
6 192.0.2.80 13.6 ms reached| Pattern | Usually means |
|---|---|
* * * on one hop, later hops fine | That router does not answer traceroute probes; not a problem |
| Latency jumps at one hop and stays higher | A long physical link, such as crossing an ocean |
| Latency jumps at one hop, then drops again | That router deprioritises its own replies; not a problem |
| Stars from some hop to the end | A firewall blocks the probes, or the path is broken there |
| Same addresses repeating | A routing loop |
Only a problem that persists to the final hop matters. Routers often answer traceroute slowly or not at all while forwarding real traffic perfectly, so a single slow or silent hop in the middle is rarely the cause of anything.
Using the results to troubleshoot
- Ping from XGM and from your own network. If XGM reaches the host and you do not, the problem is between you and the internet.
- If neither reaches it, test the service port. If the port answers, only ICMP is blocked.
- If loss or latency starts at a hop and continues to the destination, the problem is at or after that network; the owner of the addresses can be found with the IP Intelligence.
- Check DNS: a host name that resolves to an old address sends the ping to the wrong machine. Use DNS Lookup.
- Share the result with your provider, including the time of the test, the probed address and the traceroute.
For intermittent problems, run the checks several times over a period. A single run can hit a brief spike, and the pattern over time is more convincing evidence for a provider support ticket.
FAQ
Why does ping show 100% loss for a website that works?
The host or its firewall blocks ICMP echo requests. Test the website's port with the Port Scanner instead.
Can I ping a private IP address?
No. XGM refuses private, loopback and internal addresses, because the test runs from a public server.
Why is the probed IP different from the one I expected?
The host name has several addresses, or resolves differently from the XGM server than from your network, for example through a CDN. The result shows the exact address tested.
What is a good ping time?
It depends on distance. Tens of milliseconds within a continent are normal, over 100 milliseconds between continents is expected.
What does * * * mean in traceroute?
That hop did not answer the probe in time. If later hops answer, the router just ignores traceroute and the path is fine.
Does ping use a port?
No. ICMP has no ports. When ICMP is unavailable, the tool falls back to TCP connection tests on ports 443 and 80 and says so.
Why does the traceroute stop before the destination?
Firewalls near the destination often drop traceroute probes, and the tool stops after 12 hops. A service can still be reachable; test its port.
Is IPv6 supported?
Addresses are accepted when the XGM server can reach them. If a host name has both IPv4 and IPv6 addresses, one of them is chosen and shown with the result.