How to actually read MTR output
MTR lies to you. Not on purpose, but everyone treats it like gospel and then wonders why their "network issue" was actually their own firewall!
Here's the 30-second version. MTR sends ICMP probes. Each hop decrements TTL. When TTL hits zero, that hop spits back an ICMP Time Exceeded. The latency you see is ROUND TRIP to that hop, not "time through" to the destination.
Common trap: hop 5 shows 200ms. Everyone blames hop 5. But hop 6, 7, 8 are fine? Then hop 5 is rate-limiting ICMP replies, not actually slow. It prioritizes real traffic over your probe packets.
What could go wrong:
- Asymmetric routing
- MPLS tunnels hiding true paths
- ICMP de-prioritization
- Your own egress filter catching replies
Always check reverse MTR. Always run tcptraceroute as sanity check.
WARNINGS: never expose MTR results publicly without scrubbing your