I have a question about the first line in tracert.

We just had some network guys come in and set up a new network and firewall. Things suddenly got a lot slower accessing the internet. In every tracert, the first line times out.

Is this a DNS problem? Like is it trying to resolve using the local domain server first, then giving up and trying the ISP's?

Here's an example:

Tracing route to

[] over a maximum of 30 hops:

1 * * * Request timed out. 2 18 ms 30 ms 15 ms [] 3 8 ms 18 ms 12 ms [] 4 12 ms 12 ms 15 ms [] 5 12 ms 14 ms 11 ms [] 6 13 ms 12 ms 14 ms [] 7 18 ms 19 ms 14 ms [] 8 34 ms 33 ms 40 ms [] 9 43 ms 34 ms 37 ms [] 10 32 ms 36 ms 34 ms [] 11 38 ms 33 ms 35 ms []
Well...usually the first hop is your gateway...which in most cases is or on the brand you bought. Usually when you get * * * , I can't think exactly what it is...but I want to say the router's/firewall's setting disables ping requests. This helps enables better security but I don't see how it would slow you down. Now the more security you get and the more features you enable...the more time it takes for traffic to come in and out of your router/firewall. Your DNS is fine because DNS is the domain name service. If DNS was not working properly...when you type in the command "tracert
" you would get an error because the DNS would not know where to would only go by the IP address. I hope this helps.
Your first hop (most likely your router) is denying ICMP

You can also disable name looksup in tracert with a -d flag.

This is normal with some gateway devices and unrelated to your slowdown. It means specifically that the firewall is not replying to ICMP echo (colloquially "ping") requests (if you did this from Windows), or is not sending ICMP "time exceeded" or "host unreachable" replies if you sent it from a Linux box. Traceroute and tracert work a little differently between platforms.

