<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traceroute Same Destination Differing Hops in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822233#M28817</link>
    <description>&lt;P&gt;We are doing a tracert to our internet router.&lt;/P&gt;
&lt;P&gt;The first time it takes 3 hops&lt;/P&gt;
&lt;P&gt;The first hop is the Cisco L3 core switches&lt;/P&gt;
&lt;P&gt;The second hop the firewall&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The third hop the internet router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The second time i do a tracert from the same machine an few seconds later i get&lt;/P&gt;
&lt;P&gt;The first hop is the Cisco L3 core switches&lt;/P&gt;
&lt;P&gt;The second hop the internet router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just worried we have a direct connection to the internet router.&lt;/P&gt;
&lt;P&gt;I very sure this is not the case but i cant explain the differing results.&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2019 16:59:51 GMT</pubDate>
    <dc:creator>Patrick19</dc:creator>
    <dc:date>2019-03-19T16:59:51Z</dc:date>
    <item>
      <title>Traceroute Same Destination Differing Hops</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822233#M28817</link>
      <description>&lt;P&gt;We are doing a tracert to our internet router.&lt;/P&gt;
&lt;P&gt;The first time it takes 3 hops&lt;/P&gt;
&lt;P&gt;The first hop is the Cisco L3 core switches&lt;/P&gt;
&lt;P&gt;The second hop the firewall&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The third hop the internet router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The second time i do a tracert from the same machine an few seconds later i get&lt;/P&gt;
&lt;P&gt;The first hop is the Cisco L3 core switches&lt;/P&gt;
&lt;P&gt;The second hop the internet router.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just worried we have a direct connection to the internet router.&lt;/P&gt;
&lt;P&gt;I very sure this is not the case but i cant explain the differing results.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 16:59:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822233#M28817</guid>
      <dc:creator>Patrick19</dc:creator>
      <dc:date>2019-03-19T16:59:51Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute Same Destination Differing Hops</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822242#M28819</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/850651"&gt;@Patrick19&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe this discussion can help you:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/switching/traceroute-output-do-not-show-firewall-as-next-hop-while/td-p/2981682" target="_blank"&gt;https://community.cisco.com/t5/switching/traceroute-output-do-not-show-firewall-as-next-hop-while/td-p/2981682&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 17:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822242#M28819</guid>
      <dc:creator>luis_cordova</dc:creator>
      <dc:date>2019-03-19T17:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute Same Destination Differing Hops</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822243#M28821</link>
      <description>Hi,&lt;BR /&gt;The ASA would not normally appear as a hop in a traceroute. You can enable it by doing the following:-&lt;BR /&gt;&lt;BR /&gt;policy-map global_policy&lt;BR /&gt; class class-default&lt;BR /&gt; set connection decrement-ttl&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;</description>
      <pubDate>Tue, 19 Mar 2019 17:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822243#M28821</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-03-19T17:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute Same Destination Differing Hops</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822244#M28823</link>
      <description>&lt;P&gt;Can you please show the output and what are the devices like L3 Switch, FW , Internet and what model and what version of IOS it running.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show us your routing table to understand better, how your configuration done.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 17:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822244#M28823</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-03-19T17:15:24Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute Same Destination Differing Hops</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822278#M28824</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/850651"&gt;@Patrick19&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;In addition to other posts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a) a router is replying with ICMP "TTL expired" when received a packet with TTL=1 (no matter of destination address).&lt;/P&gt;&lt;P&gt;b) a reouter is decreasing TTL value before forwarding an IP packet&lt;/P&gt;&lt;P&gt;c) GRE encapsulation is copying the TTL value from the original packet which is then encapsulted (including the original header with the original TTL).&lt;/P&gt;&lt;P&gt;So the GRE packet has an (external) TTL field within the IP header plus another (internal) TTL value within the encapsulated packet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now the source device is sending traceroute packets.&lt;/P&gt;&lt;P&gt;Starts with a packet with TTL = 1, then packet with TTL = 2 followed, then TTL = 3, etc.&lt;/P&gt;&lt;P&gt;Which means:&lt;/P&gt;&lt;P&gt;In your tracerout output:&lt;/P&gt;&lt;P&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.30.3 - i.e., the router received a packet with TTL = 1 and replied with ICMP "TTL expired"&lt;/P&gt;&lt;P&gt;Next packet was received with TTL = 2 by your 10.10.3.3 router.&lt;/P&gt;&lt;P&gt;It decreases the TTL value to TTL = 1 before forwarding.&lt;/P&gt;&lt;P&gt;As there is a GRE tunnel used to forward it to the next hop, the router encapsulates the original packet to a GRE packet while copying TTL = 1 to the external TTL field.&lt;/P&gt;&lt;P&gt;When the next hop receives the GRE packet, it's seeing the external TTL = 1 and replies with ICMP "TTL expired".&lt;/P&gt;&lt;P&gt;And you see:&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.40.4&lt;/P&gt;&lt;P&gt;Next traceroute packet was recived with TTL = 3 by the 10.10.30.3 router.&lt;/P&gt;&lt;P&gt;And forwarded to the GRE tunnel with TTL = 2 within the external and internal TTL field.&lt;/P&gt;&lt;P&gt;As the external TTL is 2, the 10.10.40.4 router continues by decapsulating the packet.&lt;/P&gt;&lt;P&gt;When decapsulated, the extra step specified in the RFC follows: "The payload packet's TTL MUST be decremented when&lt;BR /&gt;&amp;nbsp;&amp;nbsp; the packet is decapsulated to insure that no packet lives forever."&lt;/P&gt;&lt;P&gt;So the TTL of the decapsulated packet is decreased from 2 to 1.&lt;/P&gt;&lt;P&gt;And the router handles the packet like just received, i.e., it is seeing a packet arrived with TTL = 1.&lt;/P&gt;&lt;P&gt;So replies with ICMP "TTL expired" again (using the tunel port as the source IP), and you see:&lt;/P&gt;&lt;P&gt;5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.40.4&lt;/P&gt;&lt;P&gt;The next packet comes with TTL=3 and is forwarded to the next hop with TTL=1, which has&lt;/P&gt;&lt;P&gt;6&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.50.5&lt;/P&gt;&lt;P&gt;as a result.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Original post here:&amp;nbsp;&lt;A href="https://community.cisco.com/t5/routing/tracert-show-same-hop-twice/td-p/1502358" target="_blank"&gt;https://community.cisco.com/t5/routing/tracert-show-same-hop-twice/td-p/1502358&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 18:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-same-destination-differing-hops/m-p/3822278#M28824</guid>
      <dc:creator>Jaderson Pessoa</dc:creator>
      <dc:date>2019-03-19T18:24:16Z</dc:date>
    </item>
  </channel>
</rss>

