O traceroute Linux / Unix usa o UDP para solicitações padrão. Seu grupo de segurança não permite pacotes de entrada UDP.
Da página do manual do traceroute:
In the modern network environment the traditional traceroute methods can not be always applicable, because of widespread use of firewalls. Such firewalls filter the "unlikely" UDP ports, or even ICMP echoes. To solve this, some additional tracerouting methods are implemented (including tcp), see LIST OF AVAILABLE METHODS below. Such methods try to use particular protocol and source/destination port, in order to bypass firewalls (to be seen by firewalls just as a start of allowed type of a network session)
Veja a opção -I
do tracerout que alterna o modo traceroute para rastreamento baseado em ICMP.