cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5808
Views
5
Helpful
2
Replies

why is "ip-177-27-177-xxx.user,vivozap.com.br" the firs hop in a PC tracert

comcat_tc
Level 1
Level 1

Hi

I am new to networking and my Cisco 887w so this may be a simple question but after I completed the configuration of my Cisco 887w I did a tracert from a Windows PC  and was presented with the first hop as an address in Brazil i.e. - ip-177-27-177-xxx.user,vivozap.com.br. I have an Australian commercial ISP (Telstra) The address is the default gatway or Router address as well but it has the extention of "user.vivozap.com.br" included. I Google to find out what I could but there was nothing. I have tried everything I know to discover how and where this address is coming from and have come up with blanks any help would appreciated .

Thanks   

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

By default tracert will do a DNS lookup of the addreses that are returned. If you happen to number your local private LAN segment using a public IP block that matches what is assigned to that company formally, the DNS lookup will give that misleading return.

You can confirm the registration of a Brazilian telecom via the Regional Internet Registry for that area - LACNIC. See:

     http://lacnic.net/cgi-bin/lacnic/whois?lg=EN

There are other, less likely, explanations involving malware and botnets but the one I posited is the most likely.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

By default tracert will do a DNS lookup of the addreses that are returned. If you happen to number your local private LAN segment using a public IP block that matches what is assigned to that company formally, the DNS lookup will give that misleading return.

You can confirm the registration of a Brazilian telecom via the Regional Internet Registry for that area - LACNIC. See:

     http://lacnic.net/cgi-bin/lacnic/whois?lg=EN

There are other, less likely, explanations involving malware and botnets but the one I posited is the most likely.

comcat_tc
Level 1
Level 1

Hi

I reset the IP block all good, all working well  

Thank you Marvin