<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enabling Traceroute in ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362443#M309424</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I was trying out that command but it gave me a different output as I described earlier.&lt;BR /&gt;&lt;BR /&gt;Thanks for the links! Will go over these. I had too much ASA for the day but it was a fun learning experience!&lt;BR /&gt;&lt;BR /&gt;So is it safe to say I could remove these:&lt;BR /&gt;&lt;BR /&gt; class class-default&lt;BR /&gt; set connection decrement-ttl&lt;BR /&gt;!&lt;BR /&gt;access-list OUTSIDE-IN extended permit icmp any any time-exceeded&lt;BR /&gt;access-list OUTSIDE-IN extended permit icmp any any unreachable&lt;BR /&gt;&lt;BR /&gt;Or they're needed for making traceroute work?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Nov 2013 18:42:56 GMT</pubDate>
    <dc:creator>johnlloyd_13</dc:creator>
    <dc:date>2013-11-06T18:42:56Z</dc:date>
    <item>
      <title>Enabling Traceroute in ASA</title>
      <link>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362439#M309416</link>
      <description>&lt;P&gt;hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i've enabled traceroute on my ASA 5505 and behind is another router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the problem is the two device's traceroute aren't the same. i want a similar output on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is this normal or was there something i've missed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1841#trace &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Translating "&lt;A href="http://www.google.com&amp;quot;...domain" target="_blank"&gt;www.google.com"...domain&lt;/A&gt; server (8.8.8.8) [OK]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Tracing the route to &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1 172.16.1.1 4 msec *&amp;nbsp; 0 msec&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; ASA GW&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 0 msec 0 msec 4 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 8 msec 8 msec 12 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 16 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 16 msec 16 msec 16 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 6 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 12 msec 12 msec 20 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 7 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 16 msec 12 msec 52 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) [MPLS: Label 16040 Exp 0] 12 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 9 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 12 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt; 10 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 12 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt; 11 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 12 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt; 12 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 16 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt; 13 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.50) 16 msec 12 msec 8 msec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5505# trace &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Tracing the route to 173.194.117.49&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 1&amp;nbsp; 192.168.1.1 0 msec 0 msec 0 msec&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; ANOTHER ROUTER CONNECTED TO CABLE MODEM&lt;/P&gt;&lt;P&gt; 2&amp;nbsp; cm1.delta104.maxonline.com.sg (59.x.x.1) 10 msec 10 msec 20 msec&lt;/P&gt;&lt;P&gt; 3&amp;nbsp; 172.20.43.1 10 msec 10 msec 10 msec&lt;/P&gt;&lt;P&gt; 4&amp;nbsp; 172.26.43.1 10 msec 30 msec 20 msec&lt;/P&gt;&lt;P&gt; 5&amp;nbsp; 172.20.7.106 20 msec 10 msec 10 msec&lt;/P&gt;&lt;P&gt; 6&amp;nbsp; 203.117.36.89 10 msec 10 msec 10 msec&lt;/P&gt;&lt;P&gt; 7&amp;nbsp; 203.117.36.25 30 msec 10 msec 10 msec&lt;/P&gt;&lt;P&gt; 8&amp;nbsp; 203.117.36.18 20 msec 10 msec 10 msec&lt;/P&gt;&lt;P&gt; 9&amp;nbsp; 72.14.196.189 20 msec 10 msec 10 msec&lt;/P&gt;&lt;P&gt; 10 66.249.95.122 10 msec 10 msec 20 msec&lt;/P&gt;&lt;P&gt; 11 209.85.244.115 10 msec 10 msec 10 msec&lt;/P&gt;&lt;P&gt; 12 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.49) 20 msec 10 msec 20 msec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5505# sh run policy-map&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp; set connection decrement-ttl&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ASA5505# sh run access-list&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit icmp any 172.16.0.0 255.255.0.0 echo&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit tcp any 172.16.0.0 255.255.0.0 eq ssh&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list OUTSIDE-IN extended permit icmp any any unreachable&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362439#M309416</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2019-03-12T03:01:16Z</dc:date>
    </item>
    <item>
      <title>Enabling Traceroute in ASA</title>
      <link>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362440#M309417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you start by trying to add the following and see if it helps&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp; inspect icmp error&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This to my understanding is meant for the ICMP related messages that the devices in between your actual trace/icmp target send.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 17:54:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362440#M309417</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-06T17:54:03Z</dc:date>
    </item>
    <item>
      <title>Enabling Traceroute in ASA</title>
      <link>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362441#M309419</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you're a genius! thanks a lot!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1841#trace www.google.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Translating "www.google.com"...domain server (8.8.8.8) [OK]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Tracing the route to &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.51)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 1 172.16.1.1 4 msec *&amp;nbsp; 0 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 192.168.1.1 0 msec 0 msec 0 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 cm1.delta104.maxonline.com.sg (59.x.x.1) 12 msec 56 msec 12 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4 172.20.43.1 8 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 172.26.43.1 16 msec 16 msec 16 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 6 172.20.7.114 16 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 7 203.117.36.89 12 msec 12 msec 16 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8 203.117.36.21 [MPLS: Label 16183 Exp 0] 12 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt;&amp;nbsp; 9 203.117.37.22 12 msec 12 msec 12 msec&lt;/P&gt;&lt;P&gt; 10 72.14.220.142 28 msec 20 msec 16 msec&lt;/P&gt;&lt;P&gt; 11 209.85.243.156 16 msec 16 msec 16 msec&lt;/P&gt;&lt;P&gt; 12 209.85.244.115 16 msec 16 msec 16 msec&lt;/P&gt;&lt;P&gt; 13 &lt;A href="https://community.cisco.com/www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt; (173.194.117.51) 16 msec 16 msec 16 msec&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 17:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362441#M309419</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2013-11-06T17:59:46Z</dc:date>
    </item>
    <item>
      <title>Enabling Traceroute in ASA</title>
      <link>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362442#M309421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to hear its working now. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I see that you originally used the configuration that decrements the TTL which essentially enabled the ASA to show in the traceroute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to check a better explanation of the &lt;STRONG&gt;"inspect icmp error"&lt;/STRONG&gt; configuration then you can check here in the Command Reference. The information is contained in the "Usage Guidelines" section there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/command-reference/i2.html#wp1760544"&gt;http://www.cisco.com/en/US/docs/security/asa/command-reference/i2.html#wp1760544&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also this is an old document that handles this subject&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is section for both getting the firewall to show up in the traceroute and also make the traceroute work through the firewall&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:05:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362442#M309421</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-06T18:05:20Z</dc:date>
    </item>
    <item>
      <title>Re: Enabling Traceroute in ASA</title>
      <link>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362443#M309424</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I was trying out that command but it gave me a different output as I described earlier.&lt;BR /&gt;&lt;BR /&gt;Thanks for the links! Will go over these. I had too much ASA for the day but it was a fun learning experience!&lt;BR /&gt;&lt;BR /&gt;So is it safe to say I could remove these:&lt;BR /&gt;&lt;BR /&gt; class class-default&lt;BR /&gt; set connection decrement-ttl&lt;BR /&gt;!&lt;BR /&gt;access-list OUTSIDE-IN extended permit icmp any any time-exceeded&lt;BR /&gt;access-list OUTSIDE-IN extended permit icmp any any unreachable&lt;BR /&gt;&lt;BR /&gt;Or they're needed for making traceroute work?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:42:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362443#M309424</guid>
      <dc:creator>johnlloyd_13</dc:creator>
      <dc:date>2013-11-06T18:42:56Z</dc:date>
    </item>
    <item>
      <title>Enabling Traceroute in ASA</title>
      <link>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362444#M309427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you need those still.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To my understanding the &lt;STRONG&gt;"inspect icmp error"&lt;/STRONG&gt; helps with the traceroute that is done from a host that uses Dynamic PAT translation towards the Internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should still need those ACL rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Nov 2013 18:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enabling-traceroute-in-asa/m-p/2362444#M309427</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-11-06T18:50:26Z</dc:date>
    </item>
  </channel>
</rss>

