cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
92
Views
0
Helpful
0
Replies

Cisco Firepower 7.4.2 rules enable outbound traceroute

tryingtofixit
Level 1
Level 1

ouch, posted in wrong forum.

I have tried using the platform settings ICMP options to let windows traceroute out to the internet, failed.

Another fp admin shared me these rules below. They work, but what else do I need to do to make them secure? These are the absolute bare minimum ports that allow windows to traceroute out to the internet.

rule01: inside to outside allowing only these ports:

icmp-eq-req
icmp-time exceeded
icmp-unreachable
udp-traceroute udp-33434-33464

rule02: outside to inside allowing only these ports:
icmp-eq-req
icmp-time exceeded
icmp-unreachable
udp-traceroute udp-33434-33464
any suggestions?

0 Replies 0
Review Cisco Networking for a $25 gift card