<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic traceroute from the switch directly connected via inside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3318445#M1064493</link>
    <description>&lt;P&gt;i can traceroute 8.8.8.8 from fw&lt;/P&gt;
&lt;P&gt;fw/pri/act# traceroute 8.8.8.8&lt;/P&gt;
&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to 8.8.8.8&lt;/P&gt;
&lt;P&gt;1 x.x.x.x0 msec 0 msec 0 msec&lt;BR /&gt; 2 * *&lt;BR /&gt;x.14.214.71 0 msec&lt;BR /&gt; 3 x.14.214.70 0 msec 10 msec 0 msec&lt;BR /&gt; 4 x.170.246.225 0 msec * 0 msec&lt;BR /&gt; 5 x.170.233.223 0 msec&lt;BR /&gt;x.14.237.179 0 msec&lt;BR /&gt;x.14.234.157 0 msec&lt;BR /&gt;6 google-public-dns-a.google.com (8.8.8.8) 0 msec 0 msec 10 msec&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;but when i do source of inside it does not work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fw/pri/act# traceroute 8.8.8.8 source inside&lt;/P&gt;
&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to 8.8.8.8&lt;/P&gt;
&lt;P&gt;1 * * *&lt;BR /&gt; 2 * * *&lt;BR /&gt; 3 * * *&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any advise&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 15:12:35 GMT</pubDate>
    <dc:creator>M Mohammed</dc:creator>
    <dc:date>2020-02-21T15:12:35Z</dc:date>
    <item>
      <title>traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3318445#M1064493</link>
      <description>&lt;P&gt;i can traceroute 8.8.8.8 from fw&lt;/P&gt;
&lt;P&gt;fw/pri/act# traceroute 8.8.8.8&lt;/P&gt;
&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to 8.8.8.8&lt;/P&gt;
&lt;P&gt;1 x.x.x.x0 msec 0 msec 0 msec&lt;BR /&gt; 2 * *&lt;BR /&gt;x.14.214.71 0 msec&lt;BR /&gt; 3 x.14.214.70 0 msec 10 msec 0 msec&lt;BR /&gt; 4 x.170.246.225 0 msec * 0 msec&lt;BR /&gt; 5 x.170.233.223 0 msec&lt;BR /&gt;x.14.237.179 0 msec&lt;BR /&gt;x.14.234.157 0 msec&lt;BR /&gt;6 google-public-dns-a.google.com (8.8.8.8) 0 msec 0 msec 10 msec&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;but when i do source of inside it does not work&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;fw/pri/act# traceroute 8.8.8.8 source inside&lt;/P&gt;
&lt;P&gt;Type escape sequence to abort.&lt;BR /&gt;Tracing the route to 8.8.8.8&lt;/P&gt;
&lt;P&gt;1 * * *&lt;BR /&gt; 2 * * *&lt;BR /&gt; 3 * * *&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;any advise&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3318445#M1064493</guid>
      <dc:creator>M Mohammed</dc:creator>
      <dc:date>2020-02-21T15:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3320205#M1064494</link>
      <description>&lt;P&gt;You cannot generally source traffic from one ASA interface to exit another one.&lt;/P&gt;</description>
      <pubDate>Sat, 27 Jan 2018 14:47:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3320205#M1064494</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-01-27T14:47:42Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3348416#M1064495</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you detail your answer here please?&lt;/P&gt;
&lt;P&gt;I need to run traceroute to IP_dst using as &lt;STRONG&gt;source&amp;nbsp;&lt;/STRONG&gt;another ASA interface, let's call it inside.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Isn't this possible? If not why does &lt;STRONG&gt;traceroute&lt;/STRONG&gt; command on ASA have &lt;STRONG&gt;source&lt;/STRONG&gt; option?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I am not clear:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- ASA 9.6.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- ASA interfaces: &lt;EM&gt;lan_data, lan_voice, outside&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- show route | 1.2.3.4&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;S*&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1.2.3.4 255.255.255.255 [1/0] via outside_interconnect_IP,&amp;nbsp;outside&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I need to run:&amp;nbsp;&lt;EM&gt;traceroute 1.2.3.4 source lan_data&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 13:33:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3348416#M1064495</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-14T13:33:48Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3348424#M1064496</link>
      <description>&lt;P&gt;&lt;EM&gt;As far as I know&lt;/EM&gt;, traceroute on an ASA will always be sourced from the interface that has the best route to the destination.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRIKE&gt;That's why there's no way to specify the source address.&lt;/STRIKE&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 04:52:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3348424#M1064496</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-17T04:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3348437#M1064497</link>
      <description>&lt;P&gt;Ok now I am really puzzled.&amp;nbsp;First of all thanks for the lighting fast reply!&lt;BR /&gt;Now on ASA I have this menu:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;traceroute 1.2.3.4 ?&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; numeric display numeric address&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; port specify port number&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; probe specify number of probes per hop&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; source specify source address or interface&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; timeout specify time out&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; ttl specify minimum and maximum ttl/hop-limit&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; use-icmp use ICMP probe packets&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; &amp;lt;cr&amp;gt;&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;traceroute 1.2.3.4 source ?&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; A.B.C.D Source address&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt;Current available interface(s):&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; lan_data Name of interface GigabitEthernet0/0&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; lan_voice Name of interface GigabitEthernet0/1&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;&lt;EM&gt; outside Name of interface GigabitEthernet0/2&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;What do you make of it?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 13:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3348437#M1064497</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-14T13:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3349760#M1064498</link>
      <description>Marvin, did you manage to read my previous reply here? &lt;BR /&gt;I am still stuck to create a TAC case for couple weeks so if you have any idea - thanks in advance!</description>
      <pubDate>Fri, 16 Mar 2018 11:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3349760#M1064498</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-16T11:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3350164#M1064499</link>
      <description>&lt;P&gt;I'm not sure at this point. I amended my earlier reply to reflect my doubt and take into account the option you pointed out.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Why not just use an actual traceroute from the next hop inside? Or, failing that, a packet-tracer on the ASA?&lt;/P&gt;</description>
      <pubDate>Sat, 17 Mar 2018 04:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3350164#M1064499</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-17T04:54:08Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3350725#M1064500</link>
      <description>Packet tracer indicates that packet is allowed.&lt;BR /&gt;Now since this is an ongoing issue and involves customer connectivity I was asked to provide a traceroute so everyone involved can see the hops "before the issue".&lt;BR /&gt;&lt;BR /&gt;Since this is happening on lan_voice (only phones sit there) I am left with:&lt;BR /&gt;1. Using ASA for traceroute dst_IP source lan_voice&lt;BR /&gt;2. Cable a PC on lan_voice Vlan and run "tracert -d dst_IP"&lt;BR /&gt;&lt;BR /&gt;I had to use the latter but as you might guess this is time consuming hence this entire discussion: traceroute using ASA source IP from one connected interface.</description>
      <pubDate>Mon, 19 Mar 2018 10:17:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3350725#M1064500</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-19T10:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3350824#M1064501</link>
      <description>&lt;P&gt;You could create an SVI on one of the switches that includes the lan_voice VLAN and traceroute from the switch using that as a source address.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also capture traffic from one of the devices having issues to demonstrate that the ASA is correctly handling the traffic.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Mar 2018 12:49:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3350824#M1064501</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-03-19T12:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3350855#M1064502</link>
      <description>SVI on the switch might help. As we speak we are passed this, still my need to tshoot the FW at demand is still on.&lt;BR /&gt;&lt;BR /&gt;As I said I will open a TAC case the moment I ll receive access to the service contracts.</description>
      <pubDate>Mon, 19 Mar 2018 13:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3350855#M1064502</guid>
      <dc:creator>Florin Barhala</dc:creator>
      <dc:date>2018-03-19T13:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute from the switch directly connected via inside</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3352356#M1064503</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/315231"&gt;@Florin Barhala&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;Please share the end result once you log the case with TAC&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;
&lt;P&gt;MM&lt;/P&gt;</description>
      <pubDate>Wed, 21 Mar 2018 13:07:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-from-the-switch-directly-connected-via-inside/m-p/3352356#M1064503</guid>
      <dc:creator>M Mohammed</dc:creator>
      <dc:date>2018-03-21T13:07:16Z</dc:date>
    </item>
  </channel>
</rss>

