cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
896
Views
0
Helpful
1
Replies

Allowing Trace Route on ASA version - 9.6(3)8

Hi Friends..

We have configured our ASA firewall to allow Trace Route to reach outside destinations (over internet), as per configuration attached. 

But, we are unable to get information of hops in ISP path during Tracing Route to reach destination, from host allowed in LAN Network (attached the problem symptoms).

Please let me know, if any correction required on attached configuration to achieve my requirement.

 

 

1 Accepted Solution

Accepted Solutions

Bogdan Nita
VIP Alumni
VIP Alumni

It looks like the icmp unreachable packets are being dropped on the outside interface.

I noticed you have 2 ISPs and use one of them for the traceroute destination. If you also have verify reverse-path it could explain the behavior. 

View solution in original post

1 Reply 1

Bogdan Nita
VIP Alumni
VIP Alumni

It looks like the icmp unreachable packets are being dropped on the outside interface.

I noticed you have 2 ISPs and use one of them for the traceroute destination. If you also have verify reverse-path it could explain the behavior. 

Review Cisco Networking for a $25 gift card