cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
585
Views
5
Helpful
7
Replies

ASA not allowing trace

mohammedrafiq
Level 1
Level 1

Hi,

We have ASA5550 firwalling our LAN from internet,ICMP is open any any both way for test, but when we do trace to a public address on internet , ASA is not showing all the hops along the line. any idea ?

Regards,

7 Replies 7

andrew.prince
Level 10
Level 10

You need to configure the ASA to decrement the TTL in the traceroute - however there is a security advisory about this, the vulnerability is fixed in software version 7.2(3)6 or 8.0(3) and later.

HTH>

Thanks Andy,

Can you send me an example.

Regards,

Sure - try:-

!

policy-map global_policy

class class-default

set connection decrement-ttl

!

HTH>

Andy,

We are not doing any Qos on ASA,is this the only way?

We are running verison 8.04 IOS.

Regards,

That is not QoS configuration - it is amending the default policy that exists in the ASA.

There is no other way to configure the ASA to show itself as a hop in a trace route - the ASA will NOT decrement the TTL unless told to.

Thanks Andy,

Can you send me an example.

Regards,

see my previous post.

Review Cisco Networking for a $25 gift card