05-16-2025 07:07 PM
ouch, posted in wrong forum.
I have tried using the platform settings ICMP options to let windows traceroute out to the internet, failed.
Another fp admin shared me these rules below. They work, but what else do I need to do to make them secure? These are the absolute bare minimum ports that allow windows to traceroute out to the internet.
rule01: inside to outside allowing only these ports:
icmp-eq-req
icmp-time exceeded
icmp-unreachable
udp-traceroute udp-33434-33464
rule02: outside to inside allowing only these ports:
icmp-eq-req
icmp-time exceeded
icmp-unreachable
udp-traceroute udp-33434-33464
any suggestions?
05-19-2025 05:59 AM
Why do you want to allow traceroute?
05-19-2025 06:03 AM
useful in troubleshooting inside to outside issues with Isp's and vendors. We have some external services that won't even start a tech support ticket unless a tracert to their external site is placed inside a support ticket.
05-19-2025 06:11 AM
That's wild. What exactly does a trace route tell them?
05-19-2025 07:12 AM
its getting out of our firewall over the internet to their site. this helps them "know" you are not being blocked internally, or you don't have internet connectivity (fails outbound) would be my guess. something to use real quickly "Not ME, its YOU!"
05-19-2025 07:16 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide