<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem with decrement-ttl traceroute in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939833#M925712</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I think you did not read my comment properly, you cannot configure this command using Flexconfig on newer versions of FTD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per the cisco guide &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/threat_defense_service_policies.html#id_71096" target="_self"&gt;here&lt;/A&gt;, you need to define an Extended ACL and modify the &lt;SPAN class="ph uicontrol"&gt;Threat Defense Service Policy to reference the ACL and then tick the box to "Enable Decrement TTL"&lt;/SPAN&gt;. See the screenshots I previously provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
    <pubDate>Sun, 13 Oct 2019 19:28:45 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2019-10-13T19:28:45Z</dc:date>
    <item>
      <title>problem with decrement-ttl traceroute</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939572#M925697</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ddd.jpg" style="width: 800px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/46749iD46362E6D8CE6F88/image-size/large?v=v2&amp;amp;px=999" role="button" title="ddd.jpg" alt="ddd.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;please help me . i can not do it&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:35:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939572#M925697</guid>
      <dc:creator>saber.sattari</dc:creator>
      <dc:date>2020-02-21T17:35:10Z</dc:date>
    </item>
    <item>
      <title>Re: problem with decrement-ttl traceroute</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939608#M925701</link>
      <description>&lt;P&gt;Try removing the "icmp..." line and putting that in a separate FlexConfig object.&lt;/P&gt;
&lt;P&gt;Also make sure you've typed in the line manually and not pasted it from an external text editor.&lt;/P&gt;
&lt;P&gt;It works fine on my FMC (currently running 6.5.0 but this config has been in place since 6.1.x):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TTL FlexConfig.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/46754iAC8E1AD3AB691457/image-size/large?v=v2&amp;amp;px=999" role="button" title="TTL FlexConfig.PNG" alt="TTL FlexConfig.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2019 11:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939608#M925701</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-12T11:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: problem with decrement-ttl traceroute</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939629#M925707</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;The flexconfig method certainly worked before on older versions of FTD, but I've recently deployed FTD 6.4 and I recieved the same error "error - unsupported CLI" as you do.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/threat_defense_service_policies.html#id_71096" target="_self"&gt;This&lt;/A&gt; cisco documentation provides provides the new method to configure. You will need to define and extended ACL, then define a "Threat Defense Service Rule" under the Access Control Policy &amp;gt; Advanced settings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ACL&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="acl.PNG" style="width: 724px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/46758i4B5BBCAB43896584/image-dimensions/724x184?v=v2" width="724" height="184" role="button" title="acl.PNG" alt="acl.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Threat Defense Service Policy&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="advanced settings.PNG" style="width: 547px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/46760i736218CA4BF58F14/image-dimensions/547x561?v=v2" width="547" height="561" role="button" title="advanced settings.PNG" alt="advanced settings.PNG" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="polc summary.PNG" style="width: 771px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/46759i3B56900920925471/image-dimensions/771x253?v=v2" width="771" height="253" role="button" title="polc summary.PNG" alt="polc summary.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Once configured the output on the CLI is the same syntax as before, I assume Cisco has just removed the ability to configure via Flexconfig in newer versions.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2019 12:54:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939629#M925707</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-10-12T12:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: problem with decrement-ttl traceroute</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939728#M925709</link>
      <description>&lt;P&gt;Good catch&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt;!&lt;/P&gt;
&lt;P&gt;It looks like upgraded FMC carries forward the old syntax but new installations require you to use the new method. That's confusing to say the least.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2019 02:51:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939728#M925709</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-13T02:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: problem with decrement-ttl traceroute</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939797#M925711</link>
      <description>&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;Thank you for your answer&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN class=""&gt;But the problem still exists&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;marvin , RJI&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;I did all that you said ,&amp;nbsp;But when I write the word (connection ), the problem is correct&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="tlid-translation translation"&gt;&lt;SPAN class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/46774i3CCB5BA046599B8F/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/46775i6F3CCDD0BF4F89A2/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2019 13:46:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939797#M925711</guid>
      <dc:creator>saber.sattari</dc:creator>
      <dc:date>2019-10-13T13:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: problem with decrement-ttl traceroute</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939833#M925712</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I think you did not read my comment properly, you cannot configure this command using Flexconfig on newer versions of FTD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As per the cisco guide &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/threat_defense_service_policies.html#id_71096" target="_self"&gt;here&lt;/A&gt;, you need to define an Extended ACL and modify the &lt;SPAN class="ph uicontrol"&gt;Threat Defense Service Policy to reference the ACL and then tick the box to "Enable Decrement TTL"&lt;/SPAN&gt;. See the screenshots I previously provided.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;</description>
      <pubDate>Sun, 13 Oct 2019 19:28:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-decrement-ttl-traceroute/m-p/3939833#M925712</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-10-13T19:28:45Z</dc:date>
    </item>
  </channel>
</rss>

