<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Traceroute Between two ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048674#M402697</link>
    <description>&lt;P&gt;Hey Gents/ladies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a ASA 5505 and a 5510, that we are using site to site..&lt;/P&gt;&lt;P&gt;I need to traceroute from the 5505-5510.. From the outside interfaces.. Don't want to do this through the site-to-site.&lt;/P&gt;&lt;P&gt;If you know what i mean..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have temporarily added a few acl on the outside interfaces..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i traceroute it only goes one hop.. Maybe thats the way it suppose to be?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to know all the hops between the outside interfaces on the 5505 to the outside interface on the 5510..&lt;/P&gt;&lt;P&gt;Is it possible? &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:09:54 GMT</pubDate>
    <dc:creator>Shane Riley</dc:creator>
    <dc:date>2019-03-12T00:09:54Z</dc:date>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048674#M402697</link>
      <description>&lt;P&gt;Hey Gents/ladies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a ASA 5505 and a 5510, that we are using site to site..&lt;/P&gt;&lt;P&gt;I need to traceroute from the 5505-5510.. From the outside interfaces.. Don't want to do this through the site-to-site.&lt;/P&gt;&lt;P&gt;If you know what i mean..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have temporarily added a few acl on the outside interfaces..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;access-list outside_in extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i traceroute it only goes one hop.. Maybe thats the way it suppose to be?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to know all the hops between the outside interfaces on the 5505 to the outside interface on the 5510..&lt;/P&gt;&lt;P&gt;Is it possible? &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048674#M402697</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2019-03-12T00:09:54Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048675#M402698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are traceroute between the 2 outside interfaces of the ASA, then you don't need to configure any ACL on the ASA.&lt;/P&gt;&lt;P&gt;And yes, it is definitely possible unless your ISP is blocking traceroute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you try traceroute from both ends and both only goes up one hop?&lt;/P&gt;&lt;P&gt;Do you happen to use the same ISP on both ends?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 11:23:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048675#M402698</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-16T11:23:22Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048676#M402699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh right didn't know &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yeah did it from both ends, also from a server on one of the dmz IP..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But probably the problem is that its from the same ISP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 11:51:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048676#M402699</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2012-10-16T11:51:52Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048677#M402700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried to traceroute to something on the internet and see if that works? Just try to traceroute to 4.2.2.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 11:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048677#M402700</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-16T11:54:28Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048678#M402701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes i tried from the asa 5510 source (outside interface) and it works fine &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the trick is to find the route from the 5510 to the 5505.. &lt;SPAN __jive_emoticon_name="confused" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll try to connect my computer from a ip thats not connected to the firewall but's still located on the same ISP ip range...&lt;/P&gt;&lt;P&gt;Maybe i am on the wrong track...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;/Shane&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048678#M402701</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2012-10-16T12:04:39Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048679#M402702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh, try this: from ASA5510 can you traceroute to the ASA5505 default gateway, and vice versa?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048679#M402702</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-16T12:14:26Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048680#M402703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is from the 5505 traceroute to the default gateway of the 5510...same results when i trry tio traceroute to the 4.2.2.2 from the 5505&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;KAKORTGW01# traceroute x.x.x.x source outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Tracing the route to x.x.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 1&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 2&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 3&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 4&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 5&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 6&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 7&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 8&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 9&amp;nbsp;&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 10&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 11&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 12&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 13&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 14&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 15&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt; 16&amp;nbsp; *&amp;nbsp; *&amp;nbsp; *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know the default gateway of the 5505, the outside interface is configured to get the ip from dhcp..So i can't try from the 5510 to the default gateway of the 5505. &lt;SPAN __jive_emoticon_name="plain" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:49:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048680#M402703</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2012-10-16T12:49:19Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048681#M402704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you can traceroute to 4.2.2.2 from 5510, but not from 5505?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check the default gateway of 5505 by checking the route: show route&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:52:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048681#M402704</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-16T12:52:03Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048682#M402705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh damn i feel stupid,&amp;nbsp; forgot about that command.. that was easy &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; Thanks really appreciate your help..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes exactly i can traceroute to 4.2.2.2 form the 5510 but not from the 5505&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traceroute from the 5510 to the 5505s default gateway is 8 hops &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:57:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048682#M402705</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2012-10-16T12:57:52Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048683#M402706</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Something weird happening on the 5505 end. I would check with the ISP.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 13:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048683#M402706</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-16T13:17:50Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048684#M402707</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well maybe it has something to do with the 5505, it has easy vpn enabled, i just saw that now &lt;SPAN __jive_emoticon_name="sad" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/sad.gif"&gt;&lt;/SPAN&gt; vpnclient server is the ip address of the 5510.. Don't know how the easy vpn works exactly..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 13:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048684#M402707</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2012-10-16T13:53:47Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048685#M402708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ahh, no wonder.&lt;/P&gt;&lt;P&gt;Easy vpn, it really depends on which mode it's on and also if split tunneling is configured or not.&lt;/P&gt;&lt;P&gt;It most probably sends everything through the VPN tunnel towards the 5510.&lt;/P&gt;&lt;P&gt;You can temporarily disable the easy vpn, and perform the traceroute, and re-enable it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 14:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048685#M402708</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-10-16T14:04:30Z</dc:date>
    </item>
    <item>
      <title>Traceroute Between two ASA</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048686#M402709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alright i try to disable the easy vpn and perform the traceroute and see &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I'll get back to you in a bit..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Shane&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 14:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-between-two-asa/m-p/2048686#M402709</guid>
      <dc:creator>Shane Riley</dc:creator>
      <dc:date>2012-10-16T14:13:17Z</dc:date>
    </item>
  </channel>
</rss>

