Link to home
Start Free TrialLog in
Avatar of nobs
nobs

asked on

Trace Route and Cisco asa 5505

When am inside the network ( 10.0.1.10) and i want to traceroute to the internet, my first hop is 196.24.5.6 our internet router. Why is it not the CISCO ASA 5505 Am confused here isnt traffic it suppose to go pass the firewall , meaning the first hop has to be ASA. Am ii missing something. Someone please help or explain. Do i need to add something on my asa.

Basically i would expect my first hop to be firewall.


Avatar of Les Moore
Les Moore
Flag of United States of America image

The ASA simply processes/nat's the packet, sends to its next hop. It does not decrement the ttl and send back to the traceroute host. But, really, it IS the first hop, but it is a firewall, not a router. Routers behave a certain way and so do firewalls. Routers process the icmp packet, decrement the TTL and send time-exceeded messages back to the host. The ASA just doesn't.
ASKER CERTIFIED SOLUTION
Avatar of JFrederick29
JFrederick29
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of nobs
nobs

ASKER

was very helpful
Hi nobs,

A point split was probably in order as lrmoore pretty much conveyed the same information.  I can open the question back up if you agree.  Thanks.