Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Enable ping and tracert through sonicwall

Posted on 2009-05-13
6
Medium Priority
?
5,244 Views
Last Modified: 2013-11-29
I would like to know what rules I need to create to allow a tracert through a sonicwall tz170.
There is a default service for ping but not for tracert.
0
Comment
Question by:kallatech
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3
6 Comments
 
LVL 2

Expert Comment

by:JMorganRead
ID: 24377910
You have to allow outgoing UDP messages to ports 33434 through 33534 as well as allow outgoing ICMP echo requests.  I'm not sure what the exact syntax is for your sonicwall, but that's the gist of what you need to do.  That will let Windows and *nix tracerts through the firewall.  Hope this helps :)
0
 

Author Comment

by:kallatech
ID: 24378680
There is a service in the sonicwall called echo is that what you are talking about?
I created a service using udp and put in the port range you suggested.
I then did the astrerik to asterik allow when setting up the rule.
Are you saying I also need to do this for icmp and the echo service?
0
 
LVL 2

Accepted Solution

by:
JMorganRead earned 500 total points
ID: 24381229
Right.  We don't have the exact setup - - I have a different model of SonicWall, but you need to set up an access rule which allows incoming or outgoing (as appropriate to which way you want to trace) echo service on ports 33434 to 33534.
0
2017 Webroot Threat Report

MSPs: Get the facts you need to protect your clients.
The 2017 Webroot Threat Report provides a uniquely insightful global view into the analysis and discoveries made by the Webroot® Threat Intelligence Platform to provide insights on key trends and risks as seen by our users.

 

Author Comment

by:kallatech
ID: 24383717
I also created a rule that allows any service in and any service out would that not do that same thing or does the sonicwall require a specfic rule?

Here is my understand of what you are telling me I create a rule using the echo service that runs on the port range you gave me using icmp and that should allow tracert in and out?
0
 

Author Comment

by:kallatech
ID: 24383761
I created a rule that uses the echo service and did the asterisk to asterik allow.
I also created a rule that allows icmp 1 through the port range you gave me with the asterisk to asterik allow.

Is this all I need?
0
 
LVL 2

Expert Comment

by:JMorganRead
ID: 24386550
Yes, should be.
0

Featured Post

NFR key for Veeam Agent for Linux

Veeam is happy to provide a free NFR license for one year.  It allows for the non‑production use and valid for five workstations and two servers. Veeam Agent for Linux is a simple backup tool for your Linux installations, both on‑premises and in the public cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
In this article, WatchGuard's Director of Security Strategy and Research Teri Radichel, takes a look at insider threats, the risk they can pose to your organization, and the best ways to defend against them.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

722 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question