<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 7.0 can no longer traceroute outside? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-7-0-can-no-longer-traceroute-outside/m-p/391850#M558839</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Binh, looks like it's fixed now. I indeed had to enable "inspect icmp error" to get traceroute's working again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 28 Apr 2005 15:31:57 GMT</pubDate>
    <dc:creator>rwhite</dc:creator>
    <dc:date>2005-04-28T15:31:57Z</dc:date>
    <item>
      <title>PIX 7.0 can no longer traceroute outside?</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-can-no-longer-traceroute-outside/m-p/391848#M558837</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a PIX 515E that we recently upgraded to 128mb RAM and PIX 7.0. At the very top of our inbound access list, we have the following lines to enable people on our LAN to be able to traceroute to the internet:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 1 remark Allow ICMP echo-replies&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 2 extended permit icmp any any echo-reply&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 3 remark Allow ICMP traceroute&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 4 extended permit icmp any any traceroute&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 5 remark Permit ICMP unreachables&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 6 extended permit icmp any any unreachable&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 7 remark Permit ICMP time-exceeded&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 8 extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This all worked fine before the upgrade, where we were previously running 6.3(3). Now after the upgrade, traceroutes and MTR's from *nix or Windows no longer work. I have another PIX running 6.3(3) in parallel that still works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a bug in the new 7.0 software? Or is there something new I need to enable to get this working with 7.0?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-ryan.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-can-no-longer-traceroute-outside/m-p/391848#M558837</guid>
      <dc:creator>rwhite</dc:creator>
      <dc:date>2020-02-21T08:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 can no longer traceroute outside?</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-can-no-longer-traceroute-outside/m-p/391849#M558838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ryan:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried enabling inspection for ICMP and see if that works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please also upload your 7.0 config for analysis.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See release notes for PIX 7.0 code below as regards to ICMP inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;Version 7.0(1) introduces an ICMP inspection engine. This engine enables secure usage of&lt;/P&gt;&lt;P&gt;ICMP, by providing stateful tracking for ICMP connections, matching echo requests with&lt;/P&gt;&lt;P&gt;replies. Additional controls are available for ICMP error messages, which are only&lt;/P&gt;&lt;P&gt;permitted for established connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use the inspect icmp and the inspect icmp error commands to configure the ICMP inspection&lt;/P&gt;&lt;P&gt;engine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For a complete description of the command syntax, see the Cisco PIX Security Appliance Command&lt;/P&gt;&lt;P&gt;Reference. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/prod_release_note09186" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/prod_release_note09186&lt;/A&gt;&lt;/P&gt;&lt;P&gt;a00803f0f4c.html&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_refer" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_refer&lt;/A&gt;&lt;/P&gt;&lt;P&gt;ence_chapter09186a00803dfa9b.html&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Binh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2005 06:10:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-can-no-longer-traceroute-outside/m-p/391849#M558838</guid>
      <dc:creator>bphan</dc:creator>
      <dc:date>2005-04-28T06:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 7.0 can no longer traceroute outside?</title>
      <link>https://community.cisco.com/t5/network-security/pix-7-0-can-no-longer-traceroute-outside/m-p/391850#M558839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Binh, looks like it's fixed now. I indeed had to enable "inspect icmp error" to get traceroute's working again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Apr 2005 15:31:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-7-0-can-no-longer-traceroute-outside/m-p/391850#M558839</guid>
      <dc:creator>rwhite</dc:creator>
      <dc:date>2005-04-28T15:31:57Z</dc:date>
    </item>
  </channel>
</rss>

