Ping from the r-no.fr server

serverPart of this tool runs on the r-no.fr server: that part cannot be checked from your browser. Why, and what it does.

Examples:

Pinging your own address shows whether your connection answers when seen from outside, not from inside your network.

Transparency

A browser cannot send a ping. And the point of this tool is to test another network path than yours: so the r-no.fr server sends the ping, not your browser. Your browser sends it the address, and shows the result.

Why this tool is tagged [server]
The code that pings runs on the server. Its source, ping.py, is shown below with its fingerprint, and the server is built from that very file, at the same version as this page. But nothing lets you check from here that it is what actually runs: for that part, you have to trust r-no.fr. Everything that runs in your browser can be checked, as on the other tools.
What the server receives
The address to ping, in the body of a request, and, like any website, your IP address and browser name.
What the server keeps
Your IP address and the address you pinged, in memory only, for the limits below: ten minutes at most, never on disk, and erased when the service restarts. The ping service writes no log line for a request. Like for any page of the site, the server's access logs note the request (IP address, date and time, address requested, browser name), but not its content: the pinged address is not in them.
What the pinged address sees
Four ICMP echo requests of 64 bytes, one second apart, coming from the address of the r-no.fr server, never from yours. Their content says where they come from (r-no.fr/ip/ping), so that the administrator of that machine knows whom to ask.
Guardrails

They keep the server from being used against anyone, and its address from ending up on blocklists:

  • IPv4 addresses written in digits only, never a name: the server resolves no name for you.
  • Never a private, local or reserved address (10.0.0.0/8, 192.168.0.0/16, 127.0.0.0/8…), nor the server's own. They are refused in your browser, and again by the server.
  • Always four packets of 64 bytes, one second apart: neither the count, nor the size, nor the pace can be chosen.
  • No continuous ping: never more than four packets per request, and a compulsory 30-second pause between two pings from the same visitor, enforced by the server. Even a looping script gets no more.
  • At most 10 pings per visitor, 10 per pinged address (all visitors together), 20 per /24 network (against the scanning of a range) and 120 for the whole service, over 10 minutes. One ping at a time per visitor, four at a time in all.
  • Only this page's requests are answered (Sec-Fetch-Site and Origin headers, set by your browser). A script can forge them: it is a brake, and the limits above remain the real guardrail.
  • An address whose holder asks not to be pinged from here is excluded. The service can also be paused at once.
Enforced by your browser
This page's Content Security Policy allows this site itself (connect-src 'self'), for the ping and for the “My address” button, which asks ip/my-ip. No form submission (form-action 'none'). One more destination is allowed, as on every page of the site: https://stats.r-no.fr, the audience measurement (see below).
Audience measurement
Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.
  • /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
    SHA-256 225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716
  • https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
What is stored in your browser
No cookie, and nothing in the address of this page. Your language is given by the address itself (/en/ or /fr/): nothing is stored to remember it.
Code

In your browser, checkable

  • app.js: checks the address, asks the server, and computes and shows the result (losses, minimum, average…). Written for R-no Toolbox, not minified, no third-party library. 14.3 kB
    SHA-256 611623500e74d71ecc1f32fa8ae10dca8caa0cd9bed7ac1f8b20187104f7ee7d
  • textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 11.0 kB
    SHA-256 f23f7a1c84d41450b8f2778fd04fd1bb105e5066bd89463def5add6a2b2196c1
  • /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
    SHA-256 80f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631

On the server, to be trusted

  • ping.py: the ping service: the checks, the limits and the sending of the packets. Python, standard library only, no privilege needed on the server. The service runs this file, built from the same commit. 17.9 kB
    SHA-256 058c171b34be416bee83fd21163d969355cdba1e5c4d20710192da0c21e4623a
Tested
The checks of addresses, the limits, the packets and the answers of the service are covered by automated tests, run on every deployment, as is the reading and display of results in your browser.
Check it yourself
Download a file and compare its fingerprint with the one above:
curl -s https://r-no.fr/ip/ping/app.js | shasum -a 256
curl -s https://r-no.fr/ip/ping/ping.py | shasum -a 256
Limits
  • No answer does not mean down: many firewalls and routers drop pings. And an answer says nothing about the ports (web, mail…): ping is ICMP, not TCP or UDP.
  • The times are those between the r-no.fr server and the address, not between you and it.
  • An answer that takes more than one second counts as lost.
  • IPv4 only for now: the server has no IPv6 connection.