cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

Community Helping Community

5539
Views
25
Helpful
20
Replies
Beginner

Re: Fixed yet?

Hi,

 

I have FTD's in HA. Do I need to set/change the platform settings for FTD-HA and apply the commands shown in the screenshots? Would appreciate your help!

 

Thank you!

Hall of Fame Guru

Re: Fixed yet?

To make the icmp and traceroute work fully yes, you would apply the bits from the FMC screenshots.

Re: Fixed yet?

Anyone still have this issue?  I have an HA pair of Firepower 2110 running 6.2.2.2 in my lab and I flat-out cannot get traceroute to work through them, even after configuring the ICMP and FlexConfig settings recommended by Marvin.  I have the same symptom that Alexandre described - all the traceroute hops fail except for the final one, which does come through.

Beginner

Re: Fixed yet?

Finally got an answer from TAC on a 2+ month old SR of them, and it works, no fancy settings required:

 

Add ICMP (either v4 or v6) Destination Unknown and Time Exceeded to the list of allowed ICMP traffic.

 

And that's it, plain and simple. Not what I was expecting but hey, the theory behind it makes sense if you think about it. If anyone feels brave enough digging into all the small sub-options, feel free to do so and let us know so we can tight even further our controls :)

 

 

allow_traceroute.png

 

Cheers.

Beginner

OK, thanks for the guidance

OK, thanks for the guidance so far. Can someone expand or post a link on how to "use Flex config to add inspects"?.  

I tried adding the System Defined, Default_Inspection_Protocol_Enable, to a new Flexconfig policy, however it seemed to do nothing. 

Hall of Fame Guru

@itsupport@protectorfire.com

[@itsupport@protectorfire.com.au]  

Answered in your related post:

https://supportforums.cisco.com/discussion/13338721/configuring-block-ips-isp-5508-fmc

CreatePlease to create content
Content for Community-Ad
FusionCharts will render here