<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PIX decreasing TTL values in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-decreasing-ttl-values/m-p/193423#M605484</link>
    <description>&lt;P&gt;This sure does sound abnormal. Pinging PIX's external interface,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;$ ping 195.x.x.x &lt;/P&gt;&lt;P&gt;PING 195.x.x.x (195.x.x.x): 56 data bytes&lt;/P&gt;&lt;P&gt;64 bytes from 195.x.x.x: icmp_seq=0 ttl=246 time=7.393 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if I ping a box in the DMZ, things look a bit wierd,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;$ ping 195.x.x.x&lt;/P&gt;&lt;P&gt;PING 195.x.x.x (195.x.x.x): 56 data bytes&lt;/P&gt;&lt;P&gt;64 bytes from 195.x.x.x: icmp_seq=0 ttl=55 time=11.852 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running 6.3(1). I don't remember seeing this behaviour on earlier releases. Did something change in the latest version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any pointers are welcome.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 06:45:51 GMT</pubDate>
    <dc:creator>haver</dc:creator>
    <dc:date>2020-02-21T06:45:51Z</dc:date>
    <item>
      <title>PIX decreasing TTL values</title>
      <link>https://community.cisco.com/t5/network-security/pix-decreasing-ttl-values/m-p/193423#M605484</link>
      <description>&lt;P&gt;This sure does sound abnormal. Pinging PIX's external interface,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;$ ping 195.x.x.x &lt;/P&gt;&lt;P&gt;PING 195.x.x.x (195.x.x.x): 56 data bytes&lt;/P&gt;&lt;P&gt;64 bytes from 195.x.x.x: icmp_seq=0 ttl=246 time=7.393 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if I ping a box in the DMZ, things look a bit wierd,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;$ ping 195.x.x.x&lt;/P&gt;&lt;P&gt;PING 195.x.x.x (195.x.x.x): 56 data bytes&lt;/P&gt;&lt;P&gt;64 bytes from 195.x.x.x: icmp_seq=0 ttl=55 time=11.852 ms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm running 6.3(1). I don't remember seeing this behaviour on earlier releases. Did something change in the latest version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any pointers are welcome.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:45:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-decreasing-ttl-values/m-p/193423#M605484</guid>
      <dc:creator>haver</dc:creator>
      <dc:date>2020-02-21T06:45:51Z</dc:date>
    </item>
    <item>
      <title>Re: PIX decreasing TTL values</title>
      <link>https://community.cisco.com/t5/network-security/pix-decreasing-ttl-values/m-p/193424#M605485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't see why the PIX would decrement the values like you have seem when the ICMP packet traverses the PIX into the DMZ segment.  My first guess would be that perhaps the ICMP echo-reply packet that you see from 195.x.x.x in the DMZ network is not taking the same path as the packet that hits the PIX interface itself.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would verify routing information on the network and the DMZ host itself.  If that does not give you the answer, I would use the 'debug icmp trace' command on the PIX to verify that in fact both the echo and echo-reply are traversing the PIX.  You can also verify the ICMP packet information with this debug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;P&gt;Marcus&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 May 2003 17:56:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-decreasing-ttl-values/m-p/193424#M605485</guid>
      <dc:creator>msitzman</dc:creator>
      <dc:date>2003-05-29T17:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: PIX decreasing TTL values</title>
      <link>https://community.cisco.com/t5/network-security/pix-decreasing-ttl-values/m-p/193425#M605486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no asymetric routing problem. Packets can only traverse the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug icmp trace shows,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;411: Inbound  ICMP echo request (len 56 id 15034 seq 0) 195.24.x.x &amp;gt; 195.69.2xx.xx &amp;gt; 195.69.2xx.xx&lt;/P&gt;&lt;P&gt;412: Outbound ICMP echo reply (len 56 id 15034 seq 0) 195.69.2xx.xx &amp;gt; 195.69.2xx.xx &amp;gt; 195.24.x.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, it turns out, that the DMZ host sets TTL to 64, which explains why I see TTL=55 at the other end. Not only that, there are also 9 hops to the DMZ host (64 - 9 = 55).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I should've checked the default TTL values before posting here. Anyways, thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Jun 2003 10:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-decreasing-ttl-values/m-p/193425#M605486</guid>
      <dc:creator>haver</dc:creator>
      <dc:date>2003-06-01T10:08:13Z</dc:date>
    </item>
  </channel>
</rss>

