• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 901
  • Last Modified:

asa icmp for traceroute

Experts,

suppose I have an ASA 5505 and want to allow it to answer traceroutes that come inbound from the outside interface. The ACL will be called outside_access_inbound

What ACL will allow the traceroute? Note, please don't say "ICMP". I need to only permit enough for traceroute rather than all ICMP.
0
trojan81
Asked:
trojan81
2 Solutions
 
Sudeep SharmaTechnical DesignerCommented:
Linux and Cisco traceroute uses UDP and Windows used ICMP echo request (type 8). So you would need to make rules for both to make it work. Please refer to the link below for the details description:

http://www.packetu.com/2009/10/09/traceroute-through-the-asa/

Sudeep
0
 
Henk van AchterbergCommented:
Please keep the following in mind if you want the ASA to show up in the traceroute:

ciscoasa(config-pmap-c)#set connection decrement-ttl


!--- Decrement the IP TTL field for packets traversing the firewall.
!--- By default, the TTL is not decrement hiding (somewhat) the firewall.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now