<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Tracert through firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082440#M895709</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am using the ASDM, but am happy to go into the CLI, which part do I need to add do tracert between interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just this?:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;    class inspection_default&lt;/P&gt;&lt;P&gt;     inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 30 Sep 2008 08:44:25 GMT</pubDate>
    <dc:creator>whiteford</dc:creator>
    <dc:date>2008-09-30T08:44:25Z</dc:date>
    <item>
      <title>Tracert through firewall</title>
      <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082438#M895707</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For me to get the tracert to work through my Cisco ASA and any DMZ/Sub Interfaces i had to create a rule on the inside and other interfaces:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a security risk or can I leave these on each interface?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082438#M895707</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2019-03-11T13:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert through firewall</title>
      <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082439#M895708</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello Whitford,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remove the ACLs and just add Inspect ICMP and Inspect ICMP error in the global policy global_poplicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see if it works...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 07:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082439#M895708</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-09-30T07:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert through firewall</title>
      <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082440#M895709</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am using the ASDM, but am happy to go into the CLI, which part do I need to add do tracert between interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just this?:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;    class inspection_default&lt;/P&gt;&lt;P&gt;     inspect icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 08:44:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082440#M895709</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-09-30T08:44:25Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert through firewall</title>
      <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082441#M895710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;    class inspection_default&lt;/P&gt;&lt;P&gt;     inspect icmp&lt;/P&gt;&lt;P&gt;     inspect icmp error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure there no ACL on inside interface/higher blocking ICMP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now try to tracert from higher security/LAN to a device in lower security Zone and it should work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 08:48:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082441#M895710</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-09-30T08:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert through firewall</title>
      <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082442#M895711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No luck I'm afraid, this is what I already have, but works when I add the permit icmp any any:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;  inspect dns migrated_dns_map_1&lt;/P&gt;&lt;P&gt;  inspect ftp&lt;/P&gt;&lt;P&gt;  inspect h323 h225&lt;/P&gt;&lt;P&gt;  inspect h323 ras&lt;/P&gt;&lt;P&gt;  inspect rsh&lt;/P&gt;&lt;P&gt;  inspect rtsp&lt;/P&gt;&lt;P&gt;  inspect esmtp&lt;/P&gt;&lt;P&gt;  inspect sqlnet&lt;/P&gt;&lt;P&gt;  inspect skinny&lt;/P&gt;&lt;P&gt;  inspect sunrpc&lt;/P&gt;&lt;P&gt;  inspect xdmcp&lt;/P&gt;&lt;P&gt;  inspect sip&lt;/P&gt;&lt;P&gt;  inspect netbios&lt;/P&gt;&lt;P&gt;  inspect tftp&lt;/P&gt;&lt;P&gt;  inspect http&lt;/P&gt;&lt;P&gt;  inspect ils&lt;/P&gt;&lt;P&gt;  inspect pptp&lt;/P&gt;&lt;P&gt;  inspect icmp&lt;/P&gt;&lt;P&gt;  inspect icmp error&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could it be an ACE?  I have the deny any any at the bottom of each ACL for the interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 09:07:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082442#M895711</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-09-30T09:07:42Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert through firewall</title>
      <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082443#M895712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if you have an ACL on LAN interface/higher security Interface then you must open icmp any any eq echo in it , the return reply will be taken care by Inspect&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 09:10:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082443#M895712</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2008-09-30T09:10:32Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert through firewall</title>
      <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082444#M895713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi, &lt;/P&gt;&lt;P&gt;in order to get tracert work through ASA do the following.&lt;/P&gt;&lt;P&gt;ciscoasa(config)#class-map class-default&lt;/P&gt;&lt;P&gt;ciscoasa(config)#match any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- This class-map exists by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)#policy-map global_policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- This Policy-map exists by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config-pmap)#class class-default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- Add another class-map to this policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config-pmap-c)#set connection decrement-ttl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- Decrement the IP TTL field for packets traversing the firewall.&lt;/P&gt;&lt;P&gt;!--- By default, the TTL is not decrement hiding (somewhat) the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config-pmap-c)#exit&lt;/P&gt;&lt;P&gt;ciscoasa(config-pmap)#exit&lt;/P&gt;&lt;P&gt;ciscoasa(config)#service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- This service-policy exists by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING: Policy map global_policy is already configured as a service policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)#icmp unreachable rate-limit 10 burst-size 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- Adjust ICMP unreachable replies:&lt;/P&gt;&lt;P&gt;!--- The default is rate-limit 1 burst-size 1.&lt;/P&gt;&lt;P&gt;!--- The default will result in timeouts for the ASA hop:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)#access-list outside-in-acl remark Allow ICMP Type 11 for Windows tracert&lt;/P&gt;&lt;P&gt;ciscoasa(config)#access-list outside-in-acl extended permit icmp any any time-exceeded&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!--- The access-list is for the far end of the ICMP traffic (in this case&lt;/P&gt;&lt;P&gt;!---the outside interface) needs to be modified in order to allow ICMP type 11 replies&lt;/P&gt;&lt;P&gt;!--- time-exceeded):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ciscoasa(config)#access-group outside-in-acl in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rate if helpful&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 09:19:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082444#M895713</guid>
      <dc:creator>itdsmartnet</dc:creator>
      <dc:date>2008-09-30T09:19:23Z</dc:date>
    </item>
    <item>
      <title>Re: Tracert through firewall</title>
      <link>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082445#M895714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It seems to work only if I have:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;an icmp any any in to my "inside" interface and on my "DMZ" interface.  So I need to rules to get it to work, does this sound right to you?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Security levels = &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMZ = 10&lt;/P&gt;&lt;P&gt;Outside = 0&lt;/P&gt;&lt;P&gt;Inside = 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My policy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy &lt;/P&gt;&lt;P&gt;class inspection_default &lt;/P&gt;&lt;P&gt;inspect dns migrated_dns_map_1 &lt;/P&gt;&lt;P&gt;inspect ftp &lt;/P&gt;&lt;P&gt;inspect h323 h225 &lt;/P&gt;&lt;P&gt;inspect h323 ras &lt;/P&gt;&lt;P&gt;inspect rsh &lt;/P&gt;&lt;P&gt;inspect rtsp &lt;/P&gt;&lt;P&gt;inspect esmtp &lt;/P&gt;&lt;P&gt;inspect sqlnet &lt;/P&gt;&lt;P&gt;inspect skinny &lt;/P&gt;&lt;P&gt;inspect sunrpc &lt;/P&gt;&lt;P&gt;inspect xdmcp &lt;/P&gt;&lt;P&gt;inspect sip &lt;/P&gt;&lt;P&gt;inspect netbios &lt;/P&gt;&lt;P&gt;inspect tftp &lt;/P&gt;&lt;P&gt;inspect http &lt;/P&gt;&lt;P&gt;inspect ils &lt;/P&gt;&lt;P&gt;inspect pptp &lt;/P&gt;&lt;P&gt;inspect icmp &lt;/P&gt;&lt;P&gt;inspect icmp error &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Sep 2008 11:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/tracert-through-firewall/m-p/1082445#M895714</guid>
      <dc:creator>whiteford</dc:creator>
      <dc:date>2008-09-30T11:14:25Z</dc:date>
    </item>
  </channel>
</rss>

