<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICMP Through a Source Group in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363898#M6201</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the ICMP issue, can you take a sniffer trace on the server and client side of the CSS?  If possible, a copy of your configuration would be helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zach&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Mar 2005 23:37:19 GMT</pubDate>
    <dc:creator>Zach Seils</dc:creator>
    <dc:date>2005-03-09T23:37:19Z</dc:date>
    <item>
      <title>ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363893#M6196</link>
      <description>&lt;P&gt;I'm attempting to get Windows traceroute to work through a Source Group.  I believe that ICMP traffic is not NAT'd by default, but I've specified with an ACL and I think it may be getting translated now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I still cannot trace all the way to my destination and can only get to 1 intermediate hop.  Interestingly, ping seems to work fine, which is also ICMP on Windows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, a question about source groups in general: if a flow is initiated internally with a Source Group, will any traffic with the correct source/destination pair be allowed in, even if it does not match a configured Content Rule??  If so, I presume that once the flow times out, further traffic would be subject to active Rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone shed any light on the situation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;~Dan&lt;/P&gt;</description>
      <pubDate>Mon, 28 Feb 2005 18:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363893#M6196</guid>
      <dc:creator>dan.shalinsky</dc:creator>
      <dc:date>2005-02-28T18:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363894#M6197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What version of WebNS are you running?  A co-worker found bug id CSCdx90237 when researching a similar problem -- so this should be fixed in the latest 7.40 code.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer your second question -- responses to source group initiated traffic will be allowed in.  In fact, the CSS doesn't drop traffic that isn't destined for a content rule, it just passes it through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Zach&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2005 20:18:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363894#M6197</guid>
      <dc:creator>Zach Seils</dc:creator>
      <dc:date>2005-03-05T20:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363895#M6198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zach:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply and the info on source groups.  I was thinking about the whole thing wrong.  I gather that, basically, traffic replies to source group traffic completely bypasses all content rules, *but* only as long as the TCP flow hasn't timed out.  Once it times out, traffic is denied, right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're actually running 6.10.405 on a 11800 if that makes any difference.  It's the lastest and greatest for the 11800 series.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2005 22:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363895#M6198</guid>
      <dc:creator>dan.shalinsky</dc:creator>
      <dc:date>2005-03-09T22:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363896#M6199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right -- because the CSS creates both flows (in &amp;lt;-&amp;gt; out, out &amp;lt;-&amp;gt; in) at the same time, return traffic is handled by the flow system and is not evaluated against content rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once the flow(s) have been removed, traffic that doesn't match a content rule will just be routed through the CSS, not denied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Zach&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2005 23:07:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363896#M6199</guid>
      <dc:creator>Zach Seils</dc:creator>
      <dc:date>2005-03-09T23:07:51Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363897#M6200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Zach:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for the clarification.  &lt;/P&gt;&lt;P&gt;Any ideas on the traceroute issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2005 23:29:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363897#M6200</guid>
      <dc:creator>dan.shalinsky</dc:creator>
      <dc:date>2005-03-09T23:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363898#M6201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the ICMP issue, can you take a sniffer trace on the server and client side of the CSS?  If possible, a copy of your configuration would be helpful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Zach&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Mar 2005 23:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363898#M6201</guid>
      <dc:creator>Zach Seils</dc:creator>
      <dc:date>2005-03-09T23:37:19Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363899#M6202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is a bug.&lt;/P&gt;&lt;P&gt;We jsut fixed it.&lt;/P&gt;&lt;P&gt;The problem is that the nating info is saved on 1 module and the TTL expired message arrives on another module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We fixed the problem by looking into the icmp message to find the correct source/destination and assign the packet to the correct module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tested the fix yesterday and it works.&lt;/P&gt;&lt;P&gt;We now have to integrate it in the next software release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bug id is CSCeh29793.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 10:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363899#M6202</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-03-10T10:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363900#M6203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for letting me know.  Out of curiosity, was this something that has worked in the past on older images?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;~Dan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 15:27:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363900#M6203</guid>
      <dc:creator>dan.shalinsky</dc:creator>
      <dc:date>2005-03-10T15:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: ICMP Through a Source Group</title>
      <link>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363901#M6204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;it works with 11000.&lt;/P&gt;&lt;P&gt;It works with non-windows platform.&lt;/P&gt;&lt;P&gt;It works if you have only 1 module in the CSS.&lt;/P&gt;&lt;P&gt;It works if the router ip address is hashed to the same value as the destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All versions of the 11500 would show the problem out of the working conditions descrived above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 Mar 2005 15:43:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/icmp-through-a-source-group/m-p/363901#M6204</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-03-10T15:43:31Z</dc:date>
    </item>
  </channel>
</rss>

