cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8669
Views
0
Helpful
17
Replies

Still can't traceroute through FTD (6.2.3.2)

peter0023
Level 1
Level 1

Hi all

 

I have FTD 2130 version 6.2.3.2 , I'm facing that server trace e.g. 8.8.8.8 always show *

I had read many articles , I had  tried

 

1. set policy from outside to inside allow icmp all

2. add flexconfig with

     policy-map global_policy
       class class-default
        set connection decrement-ttl 

 

 

still not working , someone can help me to fix it? thanks a lot

 

 

 

=============update======================

I fixed this issue , thanks.....

17 Replies 17

It seems from device limit , kindly refer to
https://quickview.cloudapps.cisco.com/quickview/bug/CSCuy04691

ben360
Level 1
Level 1

Can you expand on the fix?

Along with enabling ICMP inspection on the global policy map, you need to allow the ICMP unreachable and time exceeded in inbound direction on the ACL applied on the outside interface.

You can enable ICMP inspection from Firepower CLISH mode using the following command:

> configure inspection icmp enable

Review Cisco Networking for a $25 gift card