<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traceroute in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traceroute/m-p/1560928#M635634</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;The firewall will not respond how in traceroutes unless you have the decrement-ttl option.&lt;/P&gt;&lt;P&gt;The ASA can do that, but you can't fix it with the PIX/FWSM because they will not decrement the ttl and thus will "hide" from the traceroute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it is clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Oct 2010 17:53:09 GMT</pubDate>
    <dc:creator>Panos Kampanakis</dc:creator>
    <dc:date>2010-10-21T17:53:09Z</dc:date>
    <item>
      <title>Traceroute</title>
      <link>https://community.cisco.com/t5/network-security/traceroute/m-p/1560925#M635553</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to allow FWSMs and PIXs to appear in traceroutes.&amp;nbsp; It works on an ASA pair that I manage, but I have no luck with the FWSMs and the PIXs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only command that the ASAs have that the other firewalls don't is "set connection decrement-ttl".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All of the interface's ACLs have "icmp any any echo-reply", "icmp any any time-exceeded ", and "icmp any any unreachable".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also "icmp permit any &lt;EM&gt;interface name&lt;/EM&gt;" is configured for all interfaces.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only difference is there is no option for "set connection decrement-ttl" on the FWSM/PIXs in their global policy-maps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FWSM Firewall Version 4.0(12) and&amp;nbsp; Cisco PIX Security Appliance Software Version 7.0(7)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been using &lt;A href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#trace" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#trace&lt;/A&gt; as a guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute/m-p/1560925#M635553</guid>
      <dc:creator>stuartcox79</dc:creator>
      <dc:date>2019-03-11T18:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute</title>
      <link>https://community.cisco.com/t5/network-security/traceroute/m-p/1560926#M635580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Stuart,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you paste the config and tell me what is the model of the Pix firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 22:24:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute/m-p/1560926#M635580</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-20T22:24:02Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute</title>
      <link>https://community.cisco.com/t5/network-security/traceroute/m-p/1560927#M635619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't post the config, but I have all the relevant parts of the config in the previous post.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PIXs are 535s and the FWSMs are WS-SVC-FWM-1s.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 14:57:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute/m-p/1560927#M635619</guid>
      <dc:creator>stuartcox79</dc:creator>
      <dc:date>2010-10-21T14:57:48Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute</title>
      <link>https://community.cisco.com/t5/network-security/traceroute/m-p/1560928#M635634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;The firewall will not respond how in traceroutes unless you have the decrement-ttl option.&lt;/P&gt;&lt;P&gt;The ASA can do that, but you can't fix it with the PIX/FWSM because they will not decrement the ttl and thus will "hide" from the traceroute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it is clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Oct 2010 17:53:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute/m-p/1560928#M635634</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-10-21T17:53:09Z</dc:date>
    </item>
  </channel>
</rss>

