06-28-2003 04:21 PM - edited 02-20-2020 10:49 PM
Anybody know why you can't telnet or traceroute from a PIX?
What's up with that?
Solved! Go to Solution.
07-03-2003 09:36 PM
I have submitted an enhancement request to add the telnet and traceroute commands for the PIX Developers to consider.
Let's see what happens in the upcoming major releases.
peter
06-29-2003 09:43 AM
It is a security feature of the Pix.
The Pix is a secure firewall with a closed OS.
peter
06-29-2003 05:49 PM
How does preventing telnet or traceroute make the firewall more secure?
Is this part of Cisco's claim that the PIX doesn't have a full TCP/IP stack for some reason? I'm not trying to pick a fight here, just wish I could friggin traceroute or telnet to other machines while working on the PIX.
06-29-2003 06:25 PM
Sure - I understand your points. Let's hope a DE will respond to give their viewpoint.
One feature introduced in 6.3 was a management interface command. This command permits pinging or telneting to the inside interface on the pix over a vpn tunnel.
I was told by DEs that this was not permitted by design. Enough people asked for the command to modify this default behavior if they understood and accepted the risks.
Maybe the same can be done for traceroute and telnet.
How do others feel? I can submit an enhancement request for the next Pix version and we can see where it goes.
peter
06-29-2003 06:39 PM
Please do submit an enhancement request. I like how the default on PIX is always "No" (keeps me from shooting myself in the foot), but I'd like to be able to choose to enable other features at my own risk- for example, I like how you can't telnet to the outside interface by default, but I'd like to be able to choose to enable this feature if I want. I'm a big boy, I know the risks.
If I could turn on telnet or traceroute for testing and troubleshooting, I can always turn it back off when I'm done.
07-03-2003 09:36 PM
I have submitted an enhancement request to add the telnet and traceroute commands for the PIX Developers to consider.
Let's see what happens in the upcoming major releases.
peter
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide