<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello, it's not. 10.0.0.1 is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496211#M235385</link>
    <description>&lt;P&gt;Hello, it's not. 10.0.0.1 is my default gateway, a local router.&lt;/P&gt;&lt;P&gt;Something that is worth mentioning is, traceroute works for other ASA interfaces (DMZ). It only fails for the external interface.&lt;/P&gt;&lt;P&gt;Look:&lt;/P&gt;&lt;P&gt;c:\&amp;gt;&amp;nbsp;tracert 10.0.100.50&lt;/P&gt;&lt;P&gt;Tracing route to webserver.corp.mycompany.com [10.0.100.50]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1 &amp;nbsp; &amp;nbsp; 3 ms &amp;nbsp; &amp;nbsp; 3 ms &amp;nbsp; &amp;nbsp; 2 ms &amp;nbsp;10.0.0.1&lt;BR /&gt;&amp;nbsp; 2 &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp;10.0.0.2 &amp;lt;- This is the ASA&lt;BR /&gt;&amp;nbsp; 3 &amp;nbsp; &amp;nbsp; 1 ms &amp;nbsp; &amp;nbsp; 1 ms &amp;nbsp; &amp;nbsp; 1 ms &amp;nbsp;webserver.corp.mycompany.com [10.0.100.50]&lt;/P&gt;&lt;P&gt;Trace complete.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Oct 2014 22:46:20 GMT</pubDate>
    <dc:creator>adrianopinaffo1</dc:creator>
    <dc:date>2014-10-30T22:46:20Z</dc:date>
    <item>
      <title>Traceroute issue in ASA (not solved by other threads)</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496209#M235382</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I know this has been going on for&amp;nbsp;a long time, but I'm facing the traceroute issue in the ASA. Weirdly enough, I can reach the destination using traceroute with no problem, but I can't see the path to it. I pasted the result below.&lt;/P&gt;&lt;P&gt;I also checked my ASA configuration and the only setting that is not present is the "match any " for the "class-map class_default", because when I enter "class-map class_default" I get the following warning:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ASA(config)# class-map class-default&lt;BR /&gt;ERROR: % class-default is a well-known class and is not configurable under class-map&lt;/P&gt;&lt;P&gt;Can you guys help me? I posted below the tracert output and the concerned configuration. I can't find the misfit and I already checked most of the configuration forums.&lt;/P&gt;&lt;P&gt;C:\&amp;gt;tracert &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Tracing route to &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; [173.194.79.104]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1 &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp;10.0.0.1&lt;BR /&gt;&amp;nbsp; 2 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 3 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 4 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 5 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 6 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 7 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 8 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp; 9 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;10 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;11 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;12 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;13 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;14 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;15 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;16 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;17 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;18 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;19 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;20 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;21 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;22 &amp;nbsp; &amp;nbsp; * &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;* &amp;nbsp; &amp;nbsp; Request timed out.&lt;BR /&gt;&amp;nbsp;23 &amp;nbsp; 212 ms &amp;nbsp; 212 ms &amp;nbsp; 212 ms &amp;nbsp;pb-in-f104.1e100.net [173.194.79.104]&lt;/P&gt;&lt;P&gt;Trace complete.&lt;/P&gt;&lt;P&gt;---Router configuration&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 10 burst-size 5&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;object-group service ICMP_Return&lt;BR /&gt;&amp;nbsp;service-object icmp echo-reply&lt;BR /&gt;&amp;nbsp;service-object icmp time-exceeded&lt;BR /&gt;&amp;nbsp;service-object icmp traceroute&lt;BR /&gt;&amp;nbsp;service-object icmp unreachable&lt;BR /&gt;&amp;nbsp;service-object icmp6 echo-reply&lt;BR /&gt;&amp;nbsp;service-object icmp6 time-exceeded&lt;BR /&gt;&amp;nbsp;service-object icmp6 unreachable&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;access-list IF_outside_access_in remark ICMP Return&lt;BR /&gt;access-list IF_outside_access_in extended permit object-group ICMP_Return any any&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;access-group IF_outside_access_in in interface IF_outside&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map class_default&lt;BR /&gt;!--- This does not exit -&amp;gt; match any&amp;nbsp;&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;class-map inspection_default&lt;BR /&gt;&amp;nbsp;match default-inspection-traffic&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp;class class-default&lt;BR /&gt;&amp;nbsp; set connection decrement-ttl&lt;BR /&gt;service-policy global_policy global&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496209#M235382</guid>
      <dc:creator>adrianopinaffo1</dc:creator>
      <dc:date>2019-03-12T04:39:52Z</dc:date>
    </item>
    <item>
      <title>I am assuming that 10.0.0.1</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496210#M235383</link>
      <description>&lt;P&gt;I am assuming that&amp;nbsp;&lt;SPAN style="font-size: 14.545454025268555px;"&gt;10.0.0.1 is the ip address on ASA? &amp;nbsp;if that is true you communication is not breaking on ASA since you see first hope in your trace route.... what is the next hop in path after ASA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2014 13:29:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496210#M235383</guid>
      <dc:creator>Saqib Raza</dc:creator>
      <dc:date>2014-08-22T13:29:37Z</dc:date>
    </item>
    <item>
      <title>Hello, it's not. 10.0.0.1 is</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496211#M235385</link>
      <description>&lt;P&gt;Hello, it's not. 10.0.0.1 is my default gateway, a local router.&lt;/P&gt;&lt;P&gt;Something that is worth mentioning is, traceroute works for other ASA interfaces (DMZ). It only fails for the external interface.&lt;/P&gt;&lt;P&gt;Look:&lt;/P&gt;&lt;P&gt;c:\&amp;gt;&amp;nbsp;tracert 10.0.100.50&lt;/P&gt;&lt;P&gt;Tracing route to webserver.corp.mycompany.com [10.0.100.50]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1 &amp;nbsp; &amp;nbsp; 3 ms &amp;nbsp; &amp;nbsp; 3 ms &amp;nbsp; &amp;nbsp; 2 ms &amp;nbsp;10.0.0.1&lt;BR /&gt;&amp;nbsp; 2 &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp; &amp;nbsp;&amp;lt;1 ms &amp;nbsp;10.0.0.2 &amp;lt;- This is the ASA&lt;BR /&gt;&amp;nbsp; 3 &amp;nbsp; &amp;nbsp; 1 ms &amp;nbsp; &amp;nbsp; 1 ms &amp;nbsp; &amp;nbsp; 1 ms &amp;nbsp;webserver.corp.mycompany.com [10.0.100.50]&lt;/P&gt;&lt;P&gt;Trace complete.&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 22:46:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496211#M235385</guid>
      <dc:creator>adrianopinaffo1</dc:creator>
      <dc:date>2014-10-30T22:46:20Z</dc:date>
    </item>
    <item>
      <title>Hi Adriano,I think you</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496212#M235386</link>
      <description>&lt;P&gt;Hi Adriano,&lt;/P&gt;&lt;P&gt;I think you applied the set connection decrement under the wrong class map, let's try to do it with a new one and see if it works:&lt;/P&gt;&lt;P&gt;class-map TRACE&lt;BR /&gt;&amp;nbsp; match any&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp; class TRACE&lt;BR /&gt;&amp;nbsp;&amp;nbsp; set connection decrement-ttl&lt;/P&gt;&lt;P&gt;You also need to reapply the default class map&amp;nbsp;under the global policy map:&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt;&amp;nbsp; class inspection_default&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Aref&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 23:25:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496212#M235386</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2014-10-30T23:25:53Z</dc:date>
    </item>
    <item>
      <title>Hi,Can you provide your</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496213#M235387</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Can you provide your configuration ?&lt;/P&gt;&lt;P&gt;Also , have you gone through this document to verify the configuration on the ASA device for the Trace route to run through the ASA device:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/15246-31.html&lt;/P&gt;&lt;P&gt;Please let me know from where are you trying the trace route ? Is is the Internal Host ?&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 31 Oct 2014 03:48:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issue-in-asa-not-solved-by-other-threads/m-p/2496213#M235387</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2014-10-31T03:48:05Z</dc:date>
    </item>
  </channel>
</rss>

