06-17-2011 10:56 AM - edited 03-11-2019 01:46 PM
we need to be able to traceroute to the internet through the asa, but when the traffic hits the asa i then get requst time out.
i can ping but not traceroute, is there an easy fix?
06-17-2011 11:00 AM
Hi,
ciscoasa#config t ciscoasa(config)#access-list internal-out permit icmp any any echo-reply ciscoasa(config)#access-list internal-out permit icmp any any time-exceeded ciscoasa(config)#access-list internal-out permit icmp any any unreachable ciscoasa(config)#policy-map global_policy ciscoasa(config-pmap)#class inspection_default ciscoasa(config-pmap-c)# inspect icmp ciscoasa(config-pmap-c)# inspect icmp error ciscoasa(config-pmap-c)#end ciscoasa(config)#service-policy global_policy global ciscoasa(config)#access-group internal-out in interface outside
Accomodate the access list name to the one that you have on the outside.
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml
Mike
06-17-2011 11:03 AM
You will one extra line to what Mike said :-
ciscoasa(config)#access-list internal-out permit icmp any any traceroute
Manish
01-09-2017 06:31 PM
this will not bring down the network?
internal-out ACL has deny any any at the end.
So, would it block all the traffics except icmp?
01-09-2017 06:38 PM
The instruction "Accomodate the access list name to the one that you have on the outside." menas you would add those lines to an existing ACL that is already applied on the outside interface.
06-17-2011 11:03 AM
Hi,
Did you strictly follow the following document:
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#trace
The following might help:
https://supportforums.cisco.com/docs/DOC-1636
Also, make sure you have inspect icmp and inspect icmp error turned on.
Regards,
Anu
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide