Sent a data packet to xxxhub and found some ulterior secrets


Hello everyone, this is Jay Chou.

That day, I suddenly thought of a question:

When I visited the GitHub that fascinated thousands of otaku programmers, how did the data packets sent by my computer reach the GitHub server on the other side of the ocean, and what nodes did it pass through?

Let us explore this problem together, please pay attention to fasten your seat belts, the computer network express is about to start...

IP message

The Internet connects countless mobile phones, computers, servers, routers, switches and other devices together. If these devices communicate through the network, a set of communication protocols is naturally needed. TCP/IP is such a set of protocols.

The data sent by these applications, including browsers, are encapsulated by HTTP, TCP, and IP protocol layers, and finally form individual IP packets, which are sent to the underlying network card.

The IP packets are continuously routed and forwarded by nodes in the network, and finally arrive at the target server.

So how do you know which network nodes have passed during the routing and forwarding process?

tracert program on Windows and the traceroute program on Linux can do it.

How do they do it?

IP packets can't be forwarded indefinitely. What if you do a loop forwarding, wouldn't it be endless? The IP message in the network has a concept of time to live, which is located in the header field of the IP message——

TTL:time to live。


After each forwarding, the value of TTL will be reduced by 1. If a certain node finds that the TTL has become 0, it will discard the IP packet and send a timeout notification message to the sender of the data packet.

Tracert and traceroute take advantage of this feature in the IP protocol. The TTL value is incremented from 1. Observing who sent this notification back to yourself can determine which nodes have been experienced during the routing process.

The difference between these two programs is that tracert sends ICMP packets, while traceroute sends UDP packets.

Trace route

Well, the basic knowledge is explained, let's try it quickly and visit the situation of GitHub.

First I pinged and got the IP address of GitHub: Note that this address may be different for people in different regions.

Next, let's trace the route:


通过最多 30 个跃点跟踪
到 [] 的路由:

  1    <1 毫秒   <1 毫秒   <1 毫秒 10.??.??.1
  2    <1 毫秒   <1 毫秒   <1 毫秒 10.??.??.??
  3     2 ms     1 ms     1 ms
  4     *        *        *     请求超时。
  5     1 ms     *        2 ms
  6     *       25 ms     *
  7     *        *        *     请求超时。
  8    36 ms    37 ms    36 ms
  9   184 ms   191 ms   185 ms
 10   195 ms   194 ms   194 ms []
 11   190 ms   190 ms   190 ms []
 12   324 ms   325 ms   324 ms []
 13     *        *      333 ms []
 14   334 ms     *        * []
 15     *      327 ms   325 ms []
 16     *        *        *     请求超时。
 17     *        *        *     请求超时。
 18   332 ms   332 ms   340 ms []
 19     *        *        *     请求超时。
 20   343 ms   338 ms     * []
 21   355 ms   353 ms   353 ms []
 22   335 ms   334 ms   338 ms []
 23   340 ms   341 ms   341 ms
 24     *        *        *     请求超时。
 25     *        *        *     请求超时。
 26   335 ms   343 ms   343 ms []

It can be seen that after the forwarding of 26 nodes, it finally reached the GitHub server. In other words, the TTL of the IP message sent by your computer must be at least 26 to reach GitHub, otherwise it will fall apart.

[Supporting technical documents]

Next, let's take a look, where did all the way go?


After the data packet is sent from my computer, the first forwarding node encountered is my local LAN gateway: 10.??.??.1. For security, I desensitized the IP address and replaced the middle two paragraphs with ?.

After this, the second node is still the address of the local area network. It can be seen that the network structure where I am is only connected to the public network after two levels of local area network routing and forwarding.


The third forwarding node is a public network address: I checked it and found that it is located in the Wuhou District of Chengdu, which is consistent with my actual situation.



The next fourth routing node is a bit fascinating, all three time points are *, and tracert shows that the request has timed out. The appearance of this means that the tracert program did not receive a notification after setting the TTL to 4, or it waited too long. Some nodes in the network may not send timeout notifications for security reasons.

In this way, tracert cannot know who the fourth node is.


The fifth node is:, still in Chengdu.



At the sixth node:, we have arrived in Beijing.


[Supporting technical documents]



The seventh node is the same as the fourth, and can't be seen.


The eighth node:, came to Shanghai.



The ninth node:, still in Shanghai.



The tenth node: I went abroad, California, USA.


Let’s not look at the rest, which is the forwarding of each node in the United States.

Let's take a look next, what kind of path is this?


After the network data packet leaves our local local area network, it will finally be connected to the larger backbone network through the metropolitan area network provided by the telecom operator.

There are four main civil backbone networks in mainland China:


Among them, China Telecom's 163 backbone network and China Unicom's 169 backbone network are the two most important backbone networks, which carry most of China's Internet traffic.

The network I was in was finally connected to the 163 backbone network of China Telecom. The following is a rough network topology diagram of the 163 backbone network.


The 163 backbone network has a total of 9 core nodes in the country:


Each of the 9 core nodes is responsible for a part of mainland China.

Under the three super cores of Beijing, Shanghai, and Guangzhou, there are also international interconnection equipment (X routers). ChinaNet uses X routers to interconnect and communicate with other operators in the world.

Therefore, going abroad through the 163 network must pass through one of the three core nodes of Beijing, Shanghai, and Guangzhou.

GitHub's server is located in the United States. For a data package going abroad, its approximate journey before going abroad is as follows:

Local Area Network -> Municipal Network -> Provincial Network -> Core Node -> International Export -> Overseas Access Point

This process is consistent with the path traced by tracert above.

Unexpectedly, as soon as you enter the car, the data packets go to so many places. The computer network is really a magical thing.

[Supporting technical documents]

阅读 1.6k


149 声望
341 粉丝
0 条评论


149 声望
341 粉丝