• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1694
  • Last Modified:

tracert being blocked asa 5505

hi i get a request timed out when i try tracert under my cisco asa 5505,
here is the log that appears when i try the trace route

Deny icmp src outside:IPdst inside:MY IP(type 11, code 0) by access-group "outside_access_in" [0x0, 0x0]
0
Dan560
Asked:
Dan560
  • 2
1 Solution
 
TNL_EngrCommented:
Have you tried enabling ICMP on the outside interface?
From the CLI, it looks like this:
icmp permit any Outside
0
 
JFrederick29Commented:
Add this:

conf t
access-list outside_access_in extended permit icmp any any echo-reply
access-list outside_access_in extended permit icmp any any time-exceeded
access-list outside_access_in extended permit icmp any any unreachable
0
 
TNL_EngrCommented:
Sorry, I forgot to add:  If you are using the GUI (ASDM), this is found under:
Configuration: Device Management: ICMP
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Get your problem seen by more experts

Be seen. Boost your question’s priority for more expert views and faster solutions

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now