<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cannot mtr through Fire Power Firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746639#M1096350</link>
    <description>&lt;P&gt;Hey all,&lt;BR /&gt;We use mtr (my traceroute) to troubleshoot issues and provide reports to ISPs during outages. My company recently installed some new FirePower 4115 firewalls running FXOS 2.10 and FDM 7.0.1 to replace our old pfsense firewalls.&lt;BR /&gt;&lt;BR /&gt;However, since they were installed, we've been unable to run my traceroutes through the new firewalls (inside to outside). We get a response from the target but the hops in between show up as (waiting for reply), as you can imagine this is unhelpful. I've tried adding rules to allow ICMP traffic and setting the default policy to allow. This issue persisted despite these changes. I also confirmed it's not out network by sending mtr through our old pfsense firewalls.&lt;BR /&gt;&lt;BR /&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;server-a) (172.31.11.14)                       2022-12-29T16:22:35+0000
Keys:  Help   Display mode   Restart statistics   Order of fields   quit
                                       Packets               Pings
 Host                                Loss%   Snt   Last   Avg  Best  Wrst StDev
 1. 172.31.11.1                        0.0%   584    0.4   0.3   0.3   1.4   0.1
 2. 172.31.11.1                        0.0%   584    0.3   0.3   0.2   5.6   0.2
 3. (waiting for reply)
 4. (waiting for reply)
 5. (waiting for reply)
 6. (waiting for reply)
 7. (waiting for reply)
 8. (waiting for reply)
 9. (waiting for reply)
10. 1.1.1.1                           0.0%   583    1.2   1.2   1.1   4.9   0.2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;It seem to delete your message but I caught it before it disappeared. I followed the guide you provided with no success sadly.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://integratingit.wordpress.com/2019/10/12/ftd-allow-traceroute/" target="_blank"&gt;https://integratingit.wordpress.com/2019/10/12/ftd-allow-traceroute/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Dec 2022 16:49:39 GMT</pubDate>
    <dc:creator>TheNetRunner</dc:creator>
    <dc:date>2022-12-29T16:49:39Z</dc:date>
    <item>
      <title>Cannot mtr through Fire Power Firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746639#M1096350</link>
      <description>&lt;P&gt;Hey all,&lt;BR /&gt;We use mtr (my traceroute) to troubleshoot issues and provide reports to ISPs during outages. My company recently installed some new FirePower 4115 firewalls running FXOS 2.10 and FDM 7.0.1 to replace our old pfsense firewalls.&lt;BR /&gt;&lt;BR /&gt;However, since they were installed, we've been unable to run my traceroutes through the new firewalls (inside to outside). We get a response from the target but the hops in between show up as (waiting for reply), as you can imagine this is unhelpful. I've tried adding rules to allow ICMP traffic and setting the default policy to allow. This issue persisted despite these changes. I also confirmed it's not out network by sending mtr through our old pfsense firewalls.&lt;BR /&gt;&lt;BR /&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;server-a) (172.31.11.14)                       2022-12-29T16:22:35+0000
Keys:  Help   Display mode   Restart statistics   Order of fields   quit
                                       Packets               Pings
 Host                                Loss%   Snt   Last   Avg  Best  Wrst StDev
 1. 172.31.11.1                        0.0%   584    0.4   0.3   0.3   1.4   0.1
 2. 172.31.11.1                        0.0%   584    0.3   0.3   0.2   5.6   0.2
 3. (waiting for reply)
 4. (waiting for reply)
 5. (waiting for reply)
 6. (waiting for reply)
 7. (waiting for reply)
 8. (waiting for reply)
 9. (waiting for reply)
10. 1.1.1.1                           0.0%   583    1.2   1.2   1.1   4.9   0.2&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;It seem to delete your message but I caught it before it disappeared. I followed the guide you provided with no success sadly.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://integratingit.wordpress.com/2019/10/12/ftd-allow-traceroute/" target="_blank"&gt;https://integratingit.wordpress.com/2019/10/12/ftd-allow-traceroute/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 16:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746639#M1096350</guid>
      <dc:creator>TheNetRunner</dc:creator>
      <dc:date>2022-12-29T16:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot mtr through Fire Power Firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746642#M1096351</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1075026"&gt;@TheNetRunner&lt;/a&gt; refer to this post to enable traceroute through the FTD &lt;A href="https://integratingit.wordpress.com/2019/10/12/ftd-allow-traceroute/" target="_blank"&gt;https://integratingit.wordpress.com/2019/10/12/ftd-allow-traceroute/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 16:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746642#M1096351</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-29T16:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot mtr through Fire Power Firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746677#M1096352</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1075026"&gt;@TheNetRunner&lt;/a&gt; I saw the message disappear....it's back now. &lt;/P&gt;
&lt;P&gt;Please provide a screenshot of your ACP rules relating to the traceroute rules.&lt;/P&gt;
&lt;P&gt;From the CLI of the FTD run the command "system support firewall-engine-debug" filter on the IP address of the client running the traceroute, capture the output and upload here.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 19:00:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746677#M1096352</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-29T19:00:48Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot mtr through Fire Power Firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746953#M1096370</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;thank you for the support&lt;BR /&gt;Below is a copy of the requested info&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-12-30 at 14.46.37.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172283iABEA3CFE77B201D6/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-12-30 at 14.46.37.png" alt="Screenshot 2022-12-30 at 14.46.37.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-12-30 at 14.46.05.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/172282i1D060E1B50F305C7/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-12-30 at 14.46.05.png" alt="Screenshot 2022-12-30 at 14.46.05.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;Please specify an IP protocol: icmp
Please specify a client IP address: 172.16.0.14
Please specify a server IP address: 1.1.1.1
Monitoring firewall engine debug messages

172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=6 GR=4-1 New firewall session
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=6 GR=4-1 app event with app id changed, url no change, tls host no change, bits 0x25
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=6 GR=4-1 MidRecovery data sent for rule id: 268435499, rule_action:2, rev id:1008270430, rule_match flag:0x0
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=6 GR=4-1 using HW or preset rule order 2, 'some_vn', action Allow and prefilter rule 0
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=6 GR=4-1 allow action
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 New firewall session
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 app event with app id changed, url no change, tls host no change, bits 0x25
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 MidRecovery data sent for rule id: 268435499, rule_action:2, rev id:1008270430, rule_match flag:0x0
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 using HW or preset rule order 2, 'some_vn', action Allow and prefilter rule 0
172.31.11.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 allow action&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 14:55:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746953#M1096370</guid>
      <dc:creator>TheNetRunner</dc:creator>
      <dc:date>2022-12-30T14:55:03Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot mtr through Fire Power Firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746962#M1096371</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1075026"&gt;@TheNetRunner&lt;/a&gt; don't specify the server address (1.1.1.1) otherwise you won't see the other addresses (of each hop) responding - this might provide a clue to why its not matching rule action 2.&lt;/P&gt;
&lt;P&gt;I appear to have the same rules set up on my FTD (using FDM) and it is working.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 15:30:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746962#M1096371</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-30T15:30:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot mtr through Fire Power Firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746967#M1096372</link>
      <description>&lt;P&gt;Apologies, I am new to FTD. I assumed, incorrectly, that it was required lol.&lt;BR /&gt;&lt;BR /&gt;Interesting that it is working for you. Which versions of FXOS and FDM are you running?&lt;BR /&gt;&lt;BR /&gt;2nd times the charm...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;&amp;gt; system support firewall-engine-debug

Please specify an IP protocol: icmp
Please specify a client IP address: 172.16.0.14
Please specify a server IP address:
Monitoring firewall engine debug messages

172.16.0.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 Deleting Firewall session
172.16.0.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 New firewall session
172.16.0.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 app event with app id changed, url no change, tls host no change, bits 0x25
172.16.0.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 MidRecovery data sent for rule id: 268435486, rule_action:2, rev id:3675751523, rule_match flag:0x0
172.16.0.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 using HW or preset rule order 1, 'ICMP Outbound', action Allow and prefilter rule 0
172.16.0.14 8 -&amp;gt; 1.1.1.1 0 1 AS=0 ID=26 GR=4-1 allow action&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 15:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746967#M1096372</guid>
      <dc:creator>TheNetRunner</dc:creator>
      <dc:date>2022-12-30T15:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot mtr through Fire Power Firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746974#M1096373</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1075026"&gt;@TheNetRunner&lt;/a&gt; is that it? I'd expect to see some time exceeded events from each hop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 15:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746974#M1096373</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2022-12-30T15:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot mtr through Fire Power Firewall</title>
      <link>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746991#M1096375</link>
      <description>&lt;P&gt;Yep, nothing else appears, which I also took as odd as well. I've raised a TAC with Cisco since I believe this might be a complex one. If I fix it then I shall update this thread with the fix.&lt;BR /&gt;&lt;BR /&gt;Thank you again &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt; and happy new year.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Dec 2022 16:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-mtr-through-fire-power-firewall/m-p/4746991#M1096375</guid>
      <dc:creator>TheNetRunner</dc:creator>
      <dc:date>2022-12-30T16:24:54Z</dc:date>
    </item>
  </channel>
</rss>

