<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic traceroute issues with CISCO ASA 5540 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235288#M875435</link>
    <description>&lt;P&gt;We have a Cisco ASA connected to the internet through a Cisco 3800 series router. On the inside of the ASA we have a server that is published onto the internet (Static NAT on the ASA to a public IP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason we require a sucessful traceroute to this server from anywhere in the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is the traceroute is sucessful from a few places, but times out at the ASA from most of the places.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; When i bypass the ASA and connect the server directly to the internet with a public IP, trace is sucessful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ICMP echo and any any is already applied on the ASA to allow tace ICMP packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea how to rectify this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server &amp;gt;&amp;gt;&amp;gt;ASA inside--ASA Outside &amp;gt;&amp;gt;&amp;gt; Router  &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;. Internet.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 14:59:56 GMT</pubDate>
    <dc:creator>victor_87</dc:creator>
    <dc:date>2019-03-11T14:59:56Z</dc:date>
    <item>
      <title>traceroute issues with CISCO ASA 5540</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235288#M875435</link>
      <description>&lt;P&gt;We have a Cisco ASA connected to the internet through a Cisco 3800 series router. On the inside of the ASA we have a server that is published onto the internet (Static NAT on the ASA to a public IP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For some reason we require a sucessful traceroute to this server from anywhere in the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is the traceroute is sucessful from a few places, but times out at the ASA from most of the places.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; When i bypass the ASA and connect the server directly to the internet with a public IP, trace is sucessful.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ICMP echo and any any is already applied on the ASA to allow tace ICMP packets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea how to rectify this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server &amp;gt;&amp;gt;&amp;gt;ASA inside--ASA Outside &amp;gt;&amp;gt;&amp;gt; Router  &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;. Internet.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235288#M875435</guid>
      <dc:creator>victor_87</dc:creator>
      <dc:date>2019-03-11T14:59:56Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute issues with CISCO ASA 5540</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235289#M875438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Read the below for the solution:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2009 15:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235289#M875438</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-03-03T15:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute issues with CISCO ASA 5540</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235290#M875439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Victor&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem you may be facing is that not all traceroutes use ICMP. Windows machines do but Linux for example uses UDP so if you are not allowing that in it won't respond. Have a look at the following document for more details - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/tech/tk364/technologies_tech_note09186a00801ae32a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/tech/tk364/technologies_tech_note09186a00801ae32a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2009 15:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235290#M875439</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-03-03T15:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: traceroute issues with CISCO ASA 5540</title>
      <link>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235291#M875440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thankyou , thankyou very much, i didn't know that. You have opened my eyes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder y Cisco TAC has this case open from morning, asking for sh tech etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway thankyou very much.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Mar 2009 16:18:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/traceroute-issues-with-cisco-asa-5540/m-p/1235291#M875440</guid>
      <dc:creator>victor_87</dc:creator>
      <dc:date>2009-03-03T16:18:54Z</dc:date>
    </item>
  </channel>
</rss>

