cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
410
Views
0
Helpful
5
Replies

Cisco Firepower 7.4.2 rules enable outbound traceroute

tryingtofixit
Level 1
Level 1

ouch, posted in wrong forum.

I have tried using the platform settings ICMP options to let windows traceroute out to the internet, failed.

Another fp admin shared me these rules below. They work, but what else do I need to do to make them secure? These are the absolute bare minimum ports that allow windows to traceroute out to the internet.

rule01: inside to outside allowing only these ports:

icmp-eq-req
icmp-time exceeded
icmp-unreachable
udp-traceroute udp-33434-33464

rule02: outside to inside allowing only these ports:
icmp-eq-req
icmp-time exceeded
icmp-unreachable
udp-traceroute udp-33434-33464
any suggestions?

5 Replies 5

Why do you want to allow traceroute?

useful in troubleshooting inside to outside issues with Isp's and vendors. We have some external services that won't even start a tech support ticket unless a tracert to their external site is placed inside a support ticket.  

That's wild. What exactly does a trace route tell them?

its getting out of our firewall over the internet to their site.  this helps them "know" you are not being blocked internally, or you don't have internet connectivity (fails outbound)  would be my guess.  something to use real quickly "Not ME, its YOU!"  

yeah but just because icmp works outbound doesn't mean their app does
Review Cisco Networking for a $25 gift card