<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to see tracert output on the command promt in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678116#M535009</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Abhijit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to enable traceroute on the ASA, kindly follow this doc for it:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#intro"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#intro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 26 Jul 2011 10:40:23 GMT</pubDate>
    <dc:creator>varrao</dc:creator>
    <dc:date>2011-07-26T10:40:23Z</dc:date>
    <item>
      <title>Unable to see tracert output on the command promt</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678115#M535007</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having two sets of firewall between two facilities, like HO and Branch office. We are able to see tracert output of any site from HO, however we are unable to see tracert output (hops) from Branch office. Please help on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abhijit Kasarekar&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:03:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678115#M535007</guid>
      <dc:creator>Abhijit Kasarekar</dc:creator>
      <dc:date>2019-03-11T21:03:37Z</dc:date>
    </item>
    <item>
      <title>Unable to see tracert output on the command promt</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678116#M535009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Abhijit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to enable traceroute on the ASA, kindly follow this doc for it:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#intro"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#intro&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 10:40:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678116#M535009</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-26T10:40:23Z</dc:date>
    </item>
    <item>
      <title>Unable to see tracert output on the command promt</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678117#M535011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for quick response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having all the necessary access on the firewall. but still i am unable to see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abhijit Kasarekar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 10:54:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678117#M535011</guid>
      <dc:creator>Abhijit Kasarekar</dc:creator>
      <dc:date>2011-07-26T10:54:13Z</dc:date>
    </item>
    <item>
      <title>Unable to see tracert output on the command promt</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678118#M535012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Abhijit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have already enabled the traceroute on ASA, then I would suggest&amp;nbsp; you also take logs on the firewall to chcek where the packets are being denied for tracert. Also could you paste the config that you have added for allowing traceroute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 11:05:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678118#M535012</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-26T11:05:24Z</dc:date>
    </item>
    <item>
      <title>Unable to see tracert output on the command promt</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678119#M535013</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Varun,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find below configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside extended permit icmp any any echo &lt;/P&gt;&lt;P&gt;access-list inside extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list inside extended permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list inside extended permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;access-list outside extended permit icmp any any echo &lt;/P&gt;&lt;P&gt;access-list outside extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list outside extended permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list outside extended permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any echo outside&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;icmp permit any echo inside&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply inside&lt;/P&gt;&lt;P&gt;access-group inside in interface inside&lt;/P&gt;&lt;P&gt;access-group outside in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abhijit Kasarekar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 11:19:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678119#M535013</guid>
      <dc:creator>Abhijit Kasarekar</dc:creator>
      <dc:date>2011-07-26T11:19:13Z</dc:date>
    </item>
    <item>
      <title>Unable to see tracert output on the command promt</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678120#M535014</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Abhijit,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the configuration below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;ciscoasa(config)#&lt;STRONG&gt;class-map class-default&lt;/STRONG&gt;
ciscoasa(config)#&lt;STRONG&gt;match any&lt;/STRONG&gt;

&lt;EM&gt;
&lt;SPAN style="color: #0000ff;"&gt;!--- This class-map exists by default.&lt;/SPAN&gt;
&lt;/EM&gt;

ciscoasa(config)#&lt;STRONG&gt;policy-map global_policy&lt;/STRONG&gt;

&lt;EM&gt;
&lt;SPAN style="color: #0000ff;"&gt;!--- This Policy-map exists by default.&lt;/SPAN&gt;
&lt;/EM&gt;

ciscoasa(config-pmap)#&lt;STRONG&gt;class class-default&lt;/STRONG&gt;

&lt;EM&gt;
&lt;SPAN style="color: #0000ff;"&gt;!--- Add another class-map to this policy.&lt;/SPAN&gt;
&lt;/EM&gt;

ciscoasa(config-pmap-c)#&lt;STRONG&gt;set connection decrement-ttl&lt;/STRONG&gt;

&lt;EM&gt;
&lt;SPAN style="color: #0000ff;"&gt;!--- Decrement the IP TTL field for packets traversing the firewall.
!--- By default, the TTL is not decrement hiding (somewhat) the firewall.&lt;/SPAN&gt;
&lt;/EM&gt;

ciscoasa(config-pmap-c)#&lt;STRONG&gt;exit&lt;/STRONG&gt;
ciscoasa(config-pmap)#&lt;STRONG&gt;exit&lt;/STRONG&gt;
ciscoasa(config)#&lt;STRONG&gt;service-policy global_policy global&lt;/STRONG&gt;

&lt;EM&gt;
&lt;SPAN style="color: #0000ff;"&gt;!--- This service-policy exists by default.&lt;/SPAN&gt;
&lt;/EM&gt;
WARNING: Policy map global_policy is already configured as a service policy

ciscoasa(config)#&lt;STRONG&gt;icmp unreachable rate-limit 10 burst-size 5&lt;/STRONG&gt;

&lt;EM&gt;
&lt;SPAN style="color: #0000ff;"&gt;!--- Adjust ICMP unreachable replies:
!--- The default is rate-limit 1 burst-size 1.
!--- The default will result in timeouts for the ASA hop:&lt;/SPAN&gt;
&lt;/EM&gt;

ciscoasa(config)#&lt;STRONG&gt;access-list outside-in-acl remark Allow ICMP Type 11 for Windows tracert&lt;/STRONG&gt;
ciscoasa(config)#&lt;STRONG&gt;access-list outside-in-acl extended permit icmp any any time-exceeded&lt;/STRONG&gt;

&lt;EM&gt;
&lt;SPAN style="color: #0000ff;"&gt;!--- The access-list is for the far end of the ICMP traffic (in this case
!---the outside interface) needs to be modified in order to allow ICMP type 11 replies
!--- time-exceeded):&lt;/SPAN&gt;
&lt;/EM&gt;
ciscoasa(config)#&lt;STRONG&gt;access-group outside-in-acl in interface outside&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly refer to the doc above fr complete details.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 11:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678120#M535014</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-07-26T11:31:28Z</dc:date>
    </item>
    <item>
      <title>Unable to see tracert output on the command promt</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678121#M535015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;done same settings on both the firewalls but still unable to tracert output.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 11:51:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678121#M535015</guid>
      <dc:creator>Abhijit Kasarekar</dc:creator>
      <dc:date>2011-08-22T11:51:03Z</dc:date>
    </item>
    <item>
      <title>Unable to see tracert output on the command promt</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678122#M535016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest if you could share a bit more information, could you share the configuration?? I wouls like to know, from which interface to which interface is the tracert being done. These details woudl make it a bit easy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically the outputs i need is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run class-map&lt;/P&gt;&lt;P&gt;show run policy-map&lt;/P&gt;&lt;P&gt;show run access-group&lt;/P&gt;&lt;P&gt;show run access-list &lt;NAME&gt;&lt;/NAME&gt;&lt;/P&gt;&lt;P&gt;show service-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This hsould be enough, if required i'll ask, also plz check what logs you get, if you are suspecting that the firewall is droping the traceroute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 12:16:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-see-tracert-output-on-the-command-promt/m-p/1678122#M535016</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2011-08-22T12:16:02Z</dc:date>
    </item>
  </channel>
</rss>

