• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 904
  • Last Modified:

asa icmp for traceroute


suppose I have an ASA 5505 and want to allow it to answer traceroutes that come inbound from the outside interface. The ACL will be called outside_access_inbound

What ACL will allow the traceroute? Note, please don't say "ICMP". I need to only permit enough for traceroute rather than all ICMP.
2 Solutions
Sudeep SharmaTechnical DesignerCommented:
Linux and Cisco traceroute uses UDP and Windows used ICMP echo request (type 8). So you would need to make rules for both to make it work. Please refer to the link below for the details description:


Henk van AchterbergSr. Technical ConsultantCommented:
Please keep the following in mind if you want the ASA to show up in the traceroute:

ciscoasa(config-pmap-c)#set connection decrement-ttl

!--- Decrement the IP TTL field for packets traversing the firewall.
!--- By default, the TTL is not decrement hiding (somewhat) the firewall.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Get expert help—faster!

Need expert help—fast? Use the Help Bell for personalized assistance getting answers to your important questions.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now