04-21-2009 01:07 AM - edited 03-11-2019 08:20 AM
Hi,
We have ASA5550 firwalling our LAN from internet,ICMP is open any any both way for test, but when we do trace to a public address on internet , ASA is not showing all the hops along the line. any idea ?
Regards,
04-21-2009 01:26 AM
You need to configure the ASA to decrement the TTL in the traceroute - however there is a security advisory about this, the vulnerability is fixed in software version 7.2(3)6 or 8.0(3) and later.
HTH>
04-21-2009 01:43 AM
Thanks Andy,
Can you send me an example.
Regards,
04-21-2009 01:51 AM
Sure - try:-
!
policy-map global_policy
class class-default
set connection decrement-ttl
!
HTH>
04-21-2009 01:59 AM
Andy,
We are not doing any Qos on ASA,is this the only way?
We are running verison 8.04 IOS.
Regards,
04-21-2009 02:01 AM
That is not QoS configuration - it is amending the default policy that exists in the ASA.
There is no other way to configure the ASA to show itself as a hop in a trace route - the ASA will NOT decrement the TTL unless told to.
04-21-2009 01:55 AM
Thanks Andy,
Can you send me an example.
Regards,
04-21-2009 01:57 AM
see my previous post.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide