The true networking value of an overseas VPS cannot be judged from just a few simple ping commands or one-way speed-test scripts. Cross-border public internet transfers operate in a complex, dynamic environment shaped by transoceanic submarine-cable routing, carrier Peering & Transit policies, and congestion control within each autonomous system (AS).
Users new to optimized routes such as China Telecom CN2 GIA, China Unicom 9929, and China Mobile CMIN2 often make two mistakes because of inconsistent test methods: judging network quality from only a local outbound-route test, or mistaking protective ICMP drops by backbone routers for link failures. A standardized, reproducible bidirectional diagnostic process is essential for objectively evaluating the network quality delivered by optimized-routing providers such as BandwagonHost and DMIT.
One. Core Testing Principles: Asymmetric Bidirectional Routing and the Return-Path Dominance Rule#
Public IP routing is stateless and independently determined in each direction by design. When a local client accesses an overseas VPS, outbound and return packets follow routes selected independently by the BGP tables at their respective origins and along the path. The routes rarely match exactly; this phenomenon is known asAsymmetric Routing。
[本地客户端] ──(去程: 本地运营商分配)──> [城域网] ──> [普通骨干出口] ──> [跨洋海缆] ──> [境外 VPS]
▲ │
└─────────(回程: 机房 BGP 广播与特定选路) <── [顶级优化专网] <── [高端上联端口] ───────┘1. Why Does the Return Route Dominate the Network Experience?#
- Severely Asymmetric Upload and Download Traffic Volumes:在绝大多数业务场景(静态页面加载、流媒体拉流、文件拉取、API 响应)中,客户端发出的请求通常只有数十字节至数千字节(TCP ACK、HTTP GET 头),而服务器回传的数据载荷则高达数百 KB 乃至数百 MB。
- Congestion Mainly Occurs in the Direction Carrying More Traffic: when transoceanic outbound links become congested during evening peak hours, the return path, which carries dozens of times more downstream data, is the first to experience queuing delays and packet loss. If that return route uses a congested ordinary consumer backbone, actual available download bandwidth will plummet regardless of how low the outbound latency is.
- Premium Route Costs Are Concentrated in the Return Path: For premium bandwidth optimized for mainland China, such as China Telecom CN2 GIA, China Unicom AS9929, and China Mobile CMIN2, quality providers primarily invest in expensive, guaranteed return-path Transit purchased from tier-one telecom carriers.
2. Test Timing and Provider Risk-Control Restrictions#
When performing intensive network diagnostics and stress tests on a newly provisioned instance, define sensible testing limits to avoid violating refund eligibility or risk-control rules:
- Test Usage Limits: If you are unhappy with a newly provisioned instance's network, preserve refund eligibility. BandwagonHost requires new-purchase refund requests within 30 days and monthly usage below 10% of the allowance. DMIT's full-refund policy generally requires a request within 3 days of activation and no more than 30GB transferred; beyond that threshold or within the 30-day window, prorated partial-refund terms based on remaining value apply. Monitor usage closely when running highly concurrent multi-node MTR or iperf3 speed tests.
- Lifecycle and Billing Mechanisms: Both providers generate monthly renewal invoices 7 days before expiration. BandwagonHost does not initiate unauthorized credit card or PayPal charges by default, although sufficient account credit can be deducted automatically. DMIT generally retains suspended instances for only a 3-day grace period before deleting data. Keep track of expiration dates during long-term network monitoring and comparative testing.
Two. Test Preparation: Operations Console and In-Server Environment Setup#
A fundamental prerequisite for systematic network diagnostics is having the ability to operate simultaneously onLocal Terminaland VPS 内部a stable channel for bidirectional probing. If incorrect test parameters or restrictive firewall rules make SSH inaccessible, you must rely on the underlying console as a fallback.
1. Differences in Remote Instance Management and Emergency Access#
- BandwagonHost (KiwiVM Panel): The KiwiVM panel password is completely independent of the Billing client area password and system root password. If incorrect iptables or interface settings interrupt networking during testing, log in to KiwiVM and use the built-in Interactive Console perform low-level out-of-band troubleshooting without requiring public IP network connectivity.
- DMIT (Portal Access Panel): For security, DMIT's system images often disable remote root password login by default and require SSH key authentication. Before testing, use the panel's SSH Keys 页面录入公钥,并 Passed instance 的 Access 管理页将密钥推送至 instance 。需要特别注意:在 DMIT 面板更换公钥或 Reset root 密码后,必须依照面板提示重启 instance 才能完全生效. If a public key mismatch occurs, use the emergency Console terminal provided on the console page to connect and investigate.
2. Troubleshooting Flagged IPs and Routing Restrictions#
When testing a newly assigned IP, unexplained 100% packet loss at the first hop in both directions or at the data center gateway warrants checking whether the IP is blocked or blacklisted. With BandwagonHost, a blacklisted instance IP usually restricts KiwiVM's **self-service Data Center Migration (DC Migration)** feature, preventing a smooth switch to another data center. In that case, first contact support or request an IP replacement under the applicable rules.
Three. Probe Protocols and Underlying Mechanisms#
任何路由追踪工具的底层都基于 IP 协议报头的 TTL (Time to Live) mechanism.
发送方 (TTL=1) ──> [路由节点 A] (TTL归零,抛弃数据包并回送 ICMP Type 11 超时报文) ──> 发送方记下节点 A 延迟
发送方 (TTL=2) ──> [路由节点 A] (TTL减为1,转发) ──> [路由节点 B] (TTL归零并回送超时) ──> 发送方记下节点 B 延迟
... 依次递增直至抵达目标主机1. 常见探测报文 Type Compare #
Different protocols face very different forwarding policies at backbone nodes and data center gateways. Choosing the wrong probing method can distort the diagnosis:
| Probe Type | Example Implementation Parameters | Traversal Capability | Backbone Response Characteristics | Suitable Diagnostic Scenarios |
|---|---|---|---|---|
| ICMP | mtr -I / traceroute -I | Moderate | Most Susceptible to Router CPU-Protection Rate Limits, Often Producing False Nonresponses | General Network Connectivity and Basic Jitter Testing |
| TCP SYN | nexttrace -T -p 443 | 最高 | Most Enterprise Firewalls and NAT Devices Allow Common Ports Such as 80/443, Making This Closest to Real Application Behavior | Traverse Data Center Firewalls and Diagnose Packet Loss and Blocking on Specific Ports |
| UDP | Classic traceroute Default | Relatively Low | Many public network nodes completely filter or limit responses to high-port UDP packets, often displaying * * * | Traditional Unix Compatibility Testing |
2. MPLS Labels and Hidden Transit Hops#
On international backbones, such as China Telecom's CN2 core and the international Level3/Lumen core, packets often enter MPLS (Multiprotocol Label Switching) tunnel forwarding. Some carriers enable “RFC 4950 ICMP Extensions,” including MPLS label information in returned timeout messages. Others disable core Label Switching Routers' (LSR) ICMP responses to TTL-expiration events, causing several consecutive hops in the backbone core to appear as asterisks (* * *), while the packets are actually being forwarded at extremely high speed in hardware.
Four. MTR Production Testing Standards and In-Depth Result Interpretation#
traceroute 仅能提供某一瞬时的跳数快照,缺乏统计学意义;而 mtr(My Traceroute) combines the following in a unified interface: ping long-duration packet statistics and hop-by-hop route tracing serve as the de facto troubleshooting benchmark in network engineering.
1. Standardized Test Commands#
Never judge network quality from an arbitrary screenshot with fewer than 10 probes. A meaningful report should cover at least 60~100 consecutive probe cycles:
# 本地终端或 VPS 内部执行规范命令 (需要 root / sudo 权限)
# -r: 启用报告模式 (Report),测试完成后统一格式化输出
# -n: 强制关闭 DNS 反向域名解析,避免因反查耗时引入测量偏差
# -c 100: 严格发送 100 轮探测包,获得具备置信度的平均值与方差
# -w: 宽字符模式,防止主机名或 IP 被截断
mtr -rn -c 100 <目标 IP 地址>2. 诊断字段解析与数学指标#
The standard report headers contain the following key metrics:
- Loss%: Packet loss percentage at the current node;
- Snt: the total number of probe packets sent;
- Last: Round-trip time (RTT, in milliseconds) of the most recent probe packet;
- Avg: The arithmetic mean RTT during the test period;
- Best / Wrst: The lowest latency and highest latency spike during the test period;
- StDev (Standard Deviation):Standard Deviation (Key Jitter Metric). Lower StDev means a more stable network. If Avg is 130ms but StDev reaches 40ms, the connection has severe jitter or micro-congestion.
3. Criteria for Distinguishing “Apparent Packet Loss” from “Real Packet Loss”#
场景 A:典型的假性丢包(CoPP 机制引, from)#
Host Loss% Snt Last Avg Best Wrst StDev
1. 192.168.1.1 0.0% 100 0.8 0.9 0.6 2.1 0.2
2. 100.64.0.1 0.0% 100 4.2 4.5 3.9 8.1 0.6
3. 202.97.xx.xx 80.0% 100 15.1 16.2 14.8 35.2 2.8 <-- 【假性丢包】
4. 59.43.xx.xx 0.0% 100 18.9 19.5 18.2 24.1 0.9 <-- 【下游恢复正常】
5. 59.43.yy.yy 0.0% 100 135.2 135.8 134.9 140.2 0.8
6. 154.xx.xx.xx (目标 VPS) 0.0% 100 135.0 135.6 134.7 138.9 0.7 <-- 【终点 0% 丢包】- How to Interpret the Results: 第 3 跳呈现 80% 的高丢包率,但第 4 跳及最终目标服务器的丢包率直接归零(0.0%)。
- 底层原理: Carrier core routers, such as Huawei NE5000E and Cisco 8000 series devices, followSeparation of Forwarding and Control Planesdesign. Dedicated ASIC hardware forwards application traffic at line rate, while ICMP packets addressed to the router itself must be sent to its CPU. To resist DoS attacks and protect the CPU, routers commonly configure CoPP (Control Plane Policing),对 ICMP 超时生成严厉限速。由于数据包穿过该节点向下一跳转发并未受阻,因此第 3 跳的丢包为 100% 假象。
Scenario B: Genuine Physical-Link Packet Loss (Cascading Downstream Failure)#
Host Loss% Snt Last Avg Best Wrst StDev
1. 192.168.1.1 0.0% 100 0.8 0.9 0.7 1.5 0.1
2. 202.97.12.34 0.0% 100 12.1 12.5 11.9 18.2 0.8
3. 202.97.56.78 (海缆出口) 22.0% 100 145.2 158.4 142.1 220.1 21.5 <-- 【故障起始节点】
4. 218.30.xx.xx (跨洋上联) 24.0% 100 148.1 160.2 143.5 218.4 22.1 <-- 【丢包继承并持续】
5. 154.xx.xx.xx (目标 VPS) 23.0% 100 147.9 159.8 143.0 215.0 21.8 <-- 【末端真丢包】- How to Interpret the Results: Starting at the transoceanic gateway switch on hop 3, packet loss suddenly reaches 22%, accompanied by a step increase in RTT across the ocean. Every subsequent hop (hops 4 and 5), including the destination,持续保持相同或更高的丢包率与巨大的 StDev 抖动. This indicates genuine physical-interface congestion or fiber transmission errors in the physical interconnection or submarine-cable segment between hops 2 and 3, representing a serious actual backbone fault.
Five. Backbone Characteristics of China's Three Major Carriers and Key Autonomous Systems#
In routing diagnostic output, you must be able to identify the actual quality of the provider's advertised network accurately from IP ranges and AS numbers:
┌── AS4809 (CN2 GIA / 59.43.*.*) ───── 全程独立专网,极低丢包与抖动
中国电信 (CT) ─┤
└── AS4134 (163 骨干网 / 202.97.*.*) ── 容量大,晚高峰国际出口拥堵
┌── AS9929 (CUII / 218.105.*.*) ────── 原网通精品专网,负载低
中国联通 (CU) ─┤
└── AS4837 (169 骨干网 / 219.158.*.*) ── 骨干直连主力,性价比高
┌── AS58807 (CMIN2 / 223.120.142.*) ── 对标电信 GIA 的新一代专网
中国移动 (CM) ─┤
└── AS9808 (CMI / 223.120.*.*) ─────── 国际主流直连,跨洋高峰易抖1. Quick-Reference Matrix of Key IP Ranges and Autonomous Systems (AS)#
| Carrier | Network Name | Autonomous System Number (ASN) | Key Backbone IP Range Characteristics | Routing Architecture, Positioning, and Performance |
|---|---|---|---|---|
| China Telecom | CN2 GIA | AS4809 | 59.43.*.*(省级/跨洋全程命中) | Top-tier optimization. Both inbound and outbound traffic bypass standard 163 nodes, with the highest QoS queue priority and strong resistance to evening peak packet loss. |
| China Telecom | Traditional 163 Backbone | AS4134 | 202.97.*.* | An ordinary consumer network. It has substantial total international bandwidth, but severe evening-peak congestion on transoceanic egress links significantly reduces single-thread download performance. |
| China Unicom | CUII (Network A) | AS9929 (Often Uses AS10099 Overseas) | 218.105.*.*210.51.*.* | The former China Netcom premium backbone, now China Unicom's dedicated network for government, enterprise, and industrial internet services. Backbone utilization is extremely low, with exceptionally stable transoceanic latency and jitter. |
| China Unicom | 169 Backbone | AS4837 | 219.158.*.* | Direct connectivity over the consumer backbone. With ample upstream interconnection capacity on the North American West Coast, it offers very high direct throughput for China Unicom broadband and excellent value. |
| China Mobile | CMIN2 | AS58807 | 223.120.142.*223.120.162.* | China Mobile's high-end premium network, positioned to compete with China Telecom CN2 GIA. Independent international egress and transoceanic routes completely resolve evening-peak connection interruptions for China Mobile users. |
| China Mobile | Standard CMI | AS9808 | 223.120.*.*(常规国际段) | 移动常规出海通道。在亚太 Location (如 Hong Kong 、 Japan )互联极为通畅,但跨太平洋长距离链路 Networks 负载较高。 |
2. Beware of Partially Direct Routes and Misleading Routing Claims#
- The Fundamental Difference Between CN2 GT and CN2 GIA:
- CN2 GT(Global Transfer): uses only a short section of AS4809 during the outbound stage within mainland China (
59.43), traffic is handed back to the standard 163 backbone when it crosses the ocean (202.97), so return traffic does not receive end-to-end dedicated-network protection. - Genuine CN2 GIA: On both outbound and return routes, traffic switches at the aggregation layer in municipalities or coastal provinces to
59.43, with the international submarine-cable segment also marked AS4809 and never mixed along the way with202.97node.
- CN2 GT(Global Transfer): uses only a short section of AS4809 during the outbound stage within mainland China (
- The Return-Route Downgrade Tactic: Some low-quality providers advertise “premium routes” but only optimize the outbound path from the client to the VPS at low cost. For the return path from the VPS to the client, they send traffic through inexpensive international Transit providers such as Cogent, Telia (Arelion), or Lumen, causing data to detour through Europe or South America before entering China over congested standard backbones.
Six. Practical Two-Way Routing Analysis: An Automated Testing Workflow#
A complete network acceptance test should include both local forward testing and reverse testing from inside the server.
1. Tool Preparation: Deploy the Modern Open-Source Tracing Tool NextTrace on the VPS#
Compared with traditional tools, NextTrace accurately shows an IP's actual location, the carrier's AS number, and specific backbone route identifiers, including CN2 GIA, AS9929, and CMIN2:
# 登录目标 VPS (Linux 环境)
# 安装 NextTrace 诊断工具
curl -sL https://git.io/NextTrace | bash2. 执行回程权威测试#
Run reverse traceroutes to representative backbone networks of all three major Chinese carriers in different locations (Beijing, Shanghai, and Guangzhou), and record each carrier's return path:
# 1. 验证中国电信回程 (以上海电信核心网测试点为例)
nexttrace --table 202.96.209.133
# 2. 验证中国联通回程 (以联通 169/9929 关键接入点为例)
nexttrace --table 210.22.84.3
# 3. 验证中国移动回程 (以广东移动国际互联汇聚点为例)
nexttrace --table 120.196.165.73. Comprehensive Data Comparison Checklist#
When analyzing return-route trace output in the console, check the following four key conditions in order:
- Verify the First Hop and International Egress: whether the first external routing hop after packets leave the overseas data center's internal gateway goes directly to the promised optimized network, such as an overseas CN2 GIA PoP, rather than first transiting a cheap third-party public network.
- Entry Points into China and Transoceanic Hop Counts: Check whether the transoceanic route is direct, such as from the US West Coast to Shanghai/Guangzhou. If China–US RTT suddenly exceeds 300ms and the route includes European nodes such as London or Frankfurt, it indicates a major detour across the Atlantic or Eurasia.
- Balance Across the Three Carriers: Some products provide CN2 GIA only for China Telecom, while China Mobile return traffic uses ordinary CMI and China Unicom uses 4837. Top-tier multi-carrier optimized products, such as certain BandwagonHost GIA-E nodes or DMIT's Premium lineup, assign each carrier an appropriate high-priority return route: China Telecom CN2 GIA, China Unicom 9929/GIA, and China Mobile CMIN2/GIA.
- Retest and Compare During Evening Peak Hours: Record baseline RTT and StDev during a quiet weekday daytime period, such as 10:00, then repeat the full 100-probe test at 20:30~22:30 Beijing time during evening congestion. If average latency rises by less than 10% and final packet loss is 0%, the provider's backbone bandwidth has genuine spare capacity and top-priority QoS protection.
Seven. Emergency Network Troubleshooting and Operations Guidelines#
If link quality suddenly deteriorates during routine testing or production use, follow a systematic process to locate the cause rather than blindly reinstalling the operating system:
[网络突发恶化 / 无法连通]
│
┌─────────────┴─────────────┐
▼ ▼
【公网可达,仅延迟/丢包飙升】 【公网完全断连 / SSH 超时】
│ │
运行双向 MTR 探测 接入底层带外控制台
定位突发拥塞的精确 AS 节点 (KiwiVM Console / DMIT Console)
│ │
排查海缆割接或 DDoS 调度 核查网卡配置、防火墙与安全组- Distinguish Local Routing Problems from Cross-Border Failures: Passed MTR 审查本地局域网 Gateway (第 1 跳)以及省级宽带汇聚节点(第 2~3 跳)。若本地到省网跳数即出现大幅丢包与延迟上浮,问题根源在本地接入网或光猫/WiFi 干扰,与境外 VPS 链路无关。
- Use the Out-of-Band Console to Recover from Lost Network Access:
If SSH becomes unavailable after adjusting the system's MTU, accidentally deleting routing tables, or misconfiguring security rules, do not act rashly:
- On BandwagonHost, log into KiwiVM and click Interactive Console, access the instance's TTY login prompt directly, correct the configuration, and reset the network interface;
- In a DMIT environment, if you suspect a root authentication issue is preventing login, first use the panel's Access menu to verify or update the SSH key pair, then perform software and hardware reboots of the instance as instructed. If service is still not restored, immediately open the web Console to check the internal network daemon (
sshd、systemd-networkd) status.
- Identify Traffic Diversion to a Scrubbing Center: During an external network attack or an attack on the data center's upstream network, BGP may temporarily withdraw direct-route announcements and divert traffic to a blackhole or an off-site scrubbing center such as Voxility, Cloudflare Magic Transit, or Path. MTR will then show packets being redirected partway through the route, with substantial additional latency from the detour. Monitor provider announcements or network status updates in the support system, and conduct final acceptance tests only after the attack subsides or scrubbing restrictions are lifted.