cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8144
Views
0
Helpful
17
Replies

Still can't traceroute through FTD (6.2.3.2)

peter0023
Level 1
Level 1

Hi all

 

I have FTD 2130 version 6.2.3.2 , I'm facing that server trace e.g. 8.8.8.8 always show *

I had read many articles , I had  tried

 

1. set policy from outside to inside allow icmp all

2. add flexconfig with

     policy-map global_policy
       class class-default
        set connection decrement-ttl 

 

 

still not working , someone can help me to fix it? thanks a lot

 

 

 

=============update======================

I fixed this issue , thanks.....

17 Replies 17

It seems from device limit , kindly refer to
https://quickview.cloudapps.cisco.com/quickview/bug/CSCuy04691

ben360
Level 1
Level 1

Can you expand on the fix?

Along with enabling ICMP inspection on the global policy map, you need to allow the ICMP unreachable and time exceeded in inbound direction on the ACL applied on the outside interface.

You can enable ICMP inspection from Firepower CLISH mode using the following command:

> configure inspection icmp enable

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card