Solved

tracert being blocked asa 5505

Posted on 2008-10-09
3
1,676 Views
Last Modified: 2008-10-09
hi i get a request timed out when i try tracert under my cisco asa 5505,
here is the log that appears when i try the trace route

Deny icmp src outside:IPdst inside:MY IP(type 11, code 0) by access-group "outside_access_in" [0x0, 0x0]
0
Comment
Question by:Dan560
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 4

Expert Comment

by:TNL_Engr
ID: 22681578
Have you tried enabling ICMP on the outside interface?
From the CLI, it looks like this:
icmp permit any Outside
0
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 500 total points
ID: 22681593
Add this:

conf t
access-list outside_access_in extended permit icmp any any echo-reply
access-list outside_access_in extended permit icmp any any time-exceeded
access-list outside_access_in extended permit icmp any any unreachable
0
 
LVL 4

Expert Comment

by:TNL_Engr
ID: 22681598
Sorry, I forgot to add:  If you are using the GUI (ASDM), this is found under:
Configuration: Device Management: ICMP
0

Featured Post

Save the day with this special offer from ATEN!

Save 30% on the CV211 using promo code EXPERTS30 now through April 30th. The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

It happens many times that access list (ACL) have to be applied to outgoing router interface in order to limit some traffic.This article is about how to test ACL from the router which is not very intuitive for everyone. Below scenario shows simple s…
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question