Solved

asa icmp for traceroute

Posted on 2012-12-24
2
868 Views
Last Modified: 2012-12-26
Experts,

suppose I have an ASA 5505 and want to allow it to answer traceroutes that come inbound from the outside interface. The ACL will be called outside_access_inbound

What ACL will allow the traceroute? Note, please don't say "ICMP". I need to only permit enough for traceroute rather than all ICMP.
0
Comment
Question by:trojan81
2 Comments
 
LVL 29

Assisted Solution

by:Sudeep Sharma
Sudeep Sharma earned 250 total points
ID: 38720345
Linux and Cisco traceroute uses UDP and Windows used ICMP echo request (type 8). So you would need to make rules for both to make it work. Please refer to the link below for the details description:

http://www.packetu.com/2009/10/09/traceroute-through-the-asa/

Sudeep
0
 
LVL 12

Accepted Solution

by:
Henk van Achterberg earned 250 total points
ID: 38721184
Please keep the following in mind if you want the ASA to show up in the traceroute:

ciscoasa(config-pmap-c)#set connection decrement-ttl


!--- Decrement the IP TTL field for packets traversing the firewall.
!--- By default, the TTL is not decrement hiding (somewhat) the firewall.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cisco ASA Restarted Suddenly 11 71
Cisco 1830 AP behaving wierdly 7 27
Order of preference for routing protocol 1 34
Cisco NBAR 6 21
How to configure Site to Site VPN on a Cisco ASA.     (version: 1.1 - updated August 6, 2009) Index          [Preface]   1.    [Introduction]   2.    [The situation]   3.    [Getting started]   4.    [Interesting traffic]   5.    [NAT0]   6.…
This article assumes you have at least one Cisco ASA or PIX configured with working internet and a non-dynamic, public, address on the outside interface. If you need instructions on how to enable your device for internet, or basic configuration info…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now