The quick download
Pietrasanta Traceroute gives Windows 11 users a faster, deeper network path diagnosis than the built-in tracert command.
-
It runs UDP, TCP, and QUIC probes, and its TCP InSession mode holds one connection open to slip past firewall filtering and reveal stable load-balanced paths.
-
It analyzes ECN and L4S congestion signals, flags ECN bleaching, and improves path MTU discovery so you see what classic tracert misses.
-
It’s open source on GitHub, built by Catchpoint’s network engineers, now part of LogicMonitor.
-
Install it through WSL and Ubuntu 22.04 LTS today, then pair it with LM Internet Performance Monitoring for continuous visibility beyond the firewall.
Traceroute is one of the oldest network diagnostic tools. It was first built to answer the thorny question: where are the packets going? Various challenges introduced by firewalls and load balancers have made the original traceroute less useful and reliable than it once was. Catchpoint’s network engineers, now part of LogicMonitor, developed Pietrasanta Traceroute to overcome these limitations and introduce more advanced monitoring capabilities. The tool is named after the town where it was created.
Catchpoint initially released Pietrasanta Traceroute for Linux (it’s based on Dmitry Butskoy’s Linux Traceroute), but now with Windows Subsystem for Linux (WSL), you can also use it on Windows systems. WSL lets you run Linux applications natively on Windows, so you don’t need a virtual machine or dual-boot setup. This article explains how to install Pietrasanta Traceroute on Windows 11 using WSL and Ubuntu 22.04 LTS.
But first, why should you install Pietrasanta Traceroute?
Why use Pietrasanta Traceroute instead of classic tracert
There are multiple reasons to install Pietrasanta Traceroute. Here are the leading ones:
- Speed. Tracert is notoriously slow. Pietrasanta Traceroute obtains traceroute results as quickly as possible.
- Run UDP, TCP and QUIC traceroutes for clearer path identification. Tracert is only on ICMP.
- Run a TCP InSession Traceroute to simulate application packet traffic and prevent false packet loss.
- Assess ECN and L4S for levels of congestion and throughput analysis, including ECN bleaching detection to determine if your network is ready for L4S. This isn’t possible on tracert.
Plus many more capabilities (including path MTU performance improvements and reporting ToS/DSCP hop by hop).
Learn more and access the code directly on GitHub and share your feedback. We’re eager to hear from you.
How to install WSL and Ubuntu 22.04 LTS
Recommended: Open PowerShell as Administrator and run wsl –install -d Ubuntu-22.04. This single command installs WSL 2 and Ubuntu 22.04 LTS together. If you’d rather configure each component yourself, or the one-line install isn’t available in your environment, use the manual steps below.
Prerequisites: You’ll need administrator privileges on Windows 11 and WSL 2. To run all traceroute modes without sudo, you’ll grant raw-packet capabilities (the setcap command shown later handles this).
Step 1 To start, we’ll need to enable the Virtual Machine Platform module and Windows Subsystem for Linux feature. Open up your Start menu and locate the Turn Windows features on or off menu.

Step 2 Next, find the Virtual Machine Platform and Windows Subsystem for Linux options. Check both of these boxes and then press OK to enable these features.

Step 3 Windows will make the desired changes, which may take a minute or two, then it will ask you to restart your system for the changes to take effect. Proceed with the reboot.

Step 4 Download and update the WSL 2 Linux Kernel:
- Access the latest WSL 2 Linux Kernel package from Microsoft at aka.ms/wsl2kernel

- Install the downloaded MSI package.

Step 5 Set WSL 2 as the default version:
- In PowerShell as Administrator, enter: wsl –set-default-version 2

Step 6 Get Ubuntu 22.04 LTS from the Microsoft Store:
- Open the Microsoft Store app and search for “Ubuntu 22.04 LTS.”

- Download and install the Ubuntu 22.04 app.

Step 7 Complete Ubuntu 22.04 LTS setup:
- Launch the installed Ubuntu 22.04 app and create a username and password for your Linux account.

- Congratulations, you’ve successfully installed WSL and Ubuntu 22.04 LTS on your Windows 11 device. You can now use the terminal window to run Linux commands and applications.
How to install Pietrasanta Traceroute on Ubuntu 22.04 LTS
Once Ubuntu 22.04 LTS is set up within WSL on your Windows 11 device, follow these steps to install and use the Pietrasanta Traceroute program:
- Download and make the program executable:
- Open the terminal window within Ubuntu 22.04 LTS.
- Run:
- curl https://raw.githubusercontent.com/catchpoint/Networking.traceroute/main/binaries/ubuntu22/traceroute > ./cp_traceroute

- Make the downloaded binary file executable:
chmod +x ./cp_traceroute

Note: To execute all traceroute modes without requiring sudo or root access, we recommend running the following command:
Command: sudo setcap cap_net_raw+ep ./cp_traceroute
Run Pietrasanta Traceroute for advanced network analysis
As discussed, Pietrasanta Traceroute offers a variety of traceroute enhancements that extend beyond traditional traceroute functionalities. Each of these enhancements serves a specific purpose in network diagnostics and analysis. Let’s break down what each command does and how it can be helpful:
| Mode | Best for |
| UDP | Diagnosing connectivity issues along the UDP path |
| TCP | Troubleshooting TCP service connection problems |
| TCP InSession | Avoiding firewall filtering and load-balancer path changes |
| QUIC | Checking a destination’s QUIC and HTTP/3 support |
| ECN / L4S | Identifying congestion and L4S readiness |
UDP Traceroute:
- Command: ./cp_traceroute <target>
- Purpose: UDP traceroute typically utilizes UDP packets with incremental TTL values, not dependent on specific ports. It sends UDP packets incrementing port numbers at each hop. It’s instrumental in diagnosing connectivity issues, revealing the route traversed by UDP traffic across various routers, aiding in understanding potential bottlenecks or disruptions.

TCP Traceroute:
- Command: ./cp_traceroute -T <target>
- Purpose: TCP traceroute employs TCP packets and generally operates by sending SYN packets to port 80. It’s invaluable for pinpointing the path and latency encountered by TCP traffic, essential for troubleshooting TCP service-related connection problems.

TCP InSession:
- Command: ./cp_traceroute –tcpinsession <target>
Purpose: Different from the classic TCP traceroute, where each traceroute packet is a SYN packet, TCP InSession first establishes a TCP connection with the destination, then it sends 1-byte data packets within the opened session with incremental TTL, until the destination is reached. To avoid bothering the destination application, it inserts a gap into the stream of sequence numbers, with the aim of avoiding any data that’s delivered to the application level (since it’s incomplete).
The main advantages of TCP InSession are:
- Each traceroute doesn’t risk being seen as a SYN flood attack and therefore being filtered by firewall protection rules, because only one SYN is sent per traceroute
- Probes are more likely to cross the same IP-level path, because they belong to the same TCP session, and thus load balancers are more likely to treat them equally.
One drawback of TCP InSession, however, is that it requires an application to listen on the destination port, in order for the TCP session to be established.

QUIC Traceroute:
- Command: ./cp_traceroute –quic <target>
- Purpose: QUIC is a modern protocol that runs more and more of the Internet (specifically the World Wide Web). Although it’s based on UDP, it provides mechanisms such as connection establishment, congestion control, and encryption. For instance, HTTP/3 uses QUIC as its transport layer.
During traceroute, the probes sent correspond to QUIC Initial packets, instrumental in the initial handshake phase as mandated by the QUIC protocol.
The primary objective of a QUIC traceroute is to unveil the route taken by these QUIC initial packets and ascertain the destination’s support for QUIC. Given the default target port of 443 (HTTPS), this type of traceroute is also beneficial for determining the likelihood of whether the destination will support HTTP/3.

ECN / L4S Analysis:
- Purpose: ECN (Explicit Congestion Notification) and L4S (Low Latency, Low Loss, Scalable throughput) analysis typically operates at the transport layer without specific dedicated ports for their functionality. They belong to the TCP/IP protocol suite and don’t rely on separate ports for their analysis functions. Analysing ECN with TCP or QUIC assists in identifying congestion issues and exploring advancements like L4S, aiming to refine network performance and congestion management.
Classic ECN with TCP:
- Command: ./cp_traceroute -T –ecn=1 -O info <target>

AccECN (L4S) with TCP:
- Command: ./cp_traceroute -T –ecn=1 -O info -O acc-ecn <target>

ECN over QUIC:
- Command: ./cp_traceroute –ecn=1 –quic <target>
You’ve now successfully installed WSL, Ubuntu 22.04 LTS, and the Pietrasanta Traceroute program on your Windows 11 device. Don’t forget you can also do it on Linux.
Traceroute shows you one leg of the path. LogicMonitor connects that leg to the rest of the picture, correlating Internet path diagnostics with application and infrastructure health so you can tell where a problem actually starts and who it affects.
Beyond traceroute: Internet path visibility in context
Installing Pietrasanta Traceroute gives you a more accurate way to investigate Internet paths, whether you’re troubleshooting application connectivity, validating QUIC and L4S behavior, or analyzing how traffic moves across the network. Those diagnostics become even more valuable when viewed alongside application performance and infrastructure telemetry. As part of the LogicMonitor platform, Pietrasanta Traceroute complements Internet Performance Monitoring, LM Envision, and Edwin AI, helping teams move beyond identifying network paths to understanding how Internet conditions affect user experience and overall service health.
Further Resources
- To try out the Pietrasanta Traceroute program, visit our GitHub page at: https://github.com/catchpoint/Pietrasanta-traceroute
- To learn about Pietrasanta Traceroute watch: https://ripe87.ripe.net/archives/video/1171/
- To learn more about detecting ECN bleaching with Pietrasanta Traceroute, watch: https://ripe88.ripe.net/archives/video/1298/
Diagnose the network paths your business depends on with LogicMonitor.
See how Internet Performance Monitoring extends the capabilities of the open-source Traceroute InSession with continuous visibility into Internet paths beyond your firewall.
FAQs
What makes Pietrasanta Traceroute better than the classic tracert on Windows 11?
Classic tracert relies on ICMP and often stalls or returns incomplete paths on modern networks. Pietrasanta Traceroute runs faster and supports UDP, TCP, and QUIC probes. Its TCP InSession mode keeps a single connection open, so it avoids firewall filtering and load-balancer path changes that confuse standard tools.
How do I install Pietrasanta Traceroute on Windows 11?
You install it through the Windows Subsystem for Linux (WSL) running Ubuntu 22.04 LTS. Once WSL and Ubuntu are set up, you build the tool from its open-source code on GitHub.
What network problems can Pietrasanta Traceroute help me diagnose?
It analyzes ECN and L4S congestion signals, checks L4S readiness, and detects ECN bleaching along the path. It also improves path MTU discovery and reports ToS/DSCP values hop by hop. These details help you find where latency, filtering, or misconfiguration happens across a route.




