<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable Tracroute from DMZ Segment in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555423#M658266</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello my Dear&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct, a Cisco IOS box uses UDP for its traceroute, doesn't matter what its tracing to, it will use UDP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it depends on how far the hop is away, do you know?You might want to increase the range from 33434 to 33464&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Sep 2010 22:38:29 GMT</pubDate>
    <dc:creator>golly_wog</dc:creator>
    <dc:date>2010-09-07T22:38:29Z</dc:date>
    <item>
      <title>Enable Tracroute from DMZ Segment</title>
      <link>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555420#M658229</link>
      <description>&lt;P&gt;Hello Dear's,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m trying to traceroute internal server from DMZ segment which is connected to remote branches, i have enabled time-exceeded,and echo-reply,it doesn't work,also I tried by enabling unreacheable,and &lt;STRONG style="color: #ff0000; "&gt;Access-list DMZ extended permit icmp any any&lt;/STRONG&gt; but stil doesn't work,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traceroute from internal to DMZ server is working by &lt;STRONG style="color: #ff0000; "&gt;"time-exceeded"&lt;/STRONG&gt; but it can't be done from DMZ segment to internal server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i have enabled &lt;STRONG style="color: #ff0000; "&gt;Access-list DMZ extended permit UDP any any&lt;/STRONG&gt;&amp;nbsp; it works but it doesnt show the firewall hop.I m aware the firewall HOP is shown by the destination address but it is shows me the " * "&amp;nbsp; rather than the destination.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which UDP ports i have to enable to allow traceroute.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:35:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555420#M658229</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2019-03-11T18:35:59Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Tracroute from DMZ Segment</title>
      <link>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555421#M658248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it a linux/unix box in DMZ that you are using for traceroute ?, Linux/Unix uses UDP datagrams for traceroute with destination ports numbering from 33434 to 33534 (usually), so you may want to open relevant UDP ports, check in logs and captures which exact ports&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding why firewall not showing its interface as the hop, refer:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s1.html#wp1395966"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/s1.html#wp1395966&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 09:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555421#M658248</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2010-09-07T09:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Tracroute from DMZ Segment</title>
      <link>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555422#M658256</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dear's,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I m tracing from cisco router which is located in branch office that passess through DMZ interface of ASA. I m trying to do trace from branch router to internal windows Server, then why the UDP is neccessary here,i have read about UDP is necessary for Linux nd Unix Box but i m tracing to windows server.I have tried by enabling the same UDP ports as mentioned by you but still i m not able to trace but when i do UDP any any then the traceroute works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 20:50:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555422#M658256</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-09-07T20:50:59Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Tracroute from DMZ Segment</title>
      <link>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555423#M658266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello my Dear&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are correct, a Cisco IOS box uses UDP for its traceroute, doesn't matter what its tracing to, it will use UDP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But it depends on how far the hop is away, do you know?You might want to increase the range from 33434 to 33464&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 22:38:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555423#M658266</guid>
      <dc:creator>golly_wog</dc:creator>
      <dc:date>2010-09-07T22:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Tracroute from DMZ Segment</title>
      <link>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555424#M658282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;to find out exact port use packet capture command on DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list abc permit udp host &lt;ROUTER&gt; host &lt;SERVER on="" inside=""&gt;&lt;/SERVER&gt;&lt;/ROUTER&gt;&lt;/P&gt;&lt;P&gt;capture cpz access-l abc interface DMZ&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now traceroute and do show cap cpz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this will tell you what exact UDP ports you need&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 04:32:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555424#M658282</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2010-09-08T04:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Tracroute from DMZ Segment</title>
      <link>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555425#M658312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dear,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found the ports 33455,33456,33457,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank&amp;nbsp; u once more for ur kind reply&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 06:27:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555425#M658312</guid>
      <dc:creator>estelamathew</dc:creator>
      <dc:date>2010-09-08T06:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Enable Tracroute from DMZ Segment</title>
      <link>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555426#M658327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am glad I could help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Sep 2010 06:32:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-tracroute-from-dmz-segment/m-p/1555426#M658327</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2010-09-08T06:32:51Z</dc:date>
    </item>
  </channel>
</rss>

