Hi All,
Say I have a setup as below
Host1--(inside)ASA(Outside)----R1(192.168.1.1)---R2(172.16.1.1)---R3(Host2)
We do a tcpping to the destination say to port 80.
We will know whether the host is alive as it will send an syn-ack to us.
Noe say I have done a tcptraceroute from Host1
So at the first hop after ASA, the router(R1) will still send an ICMP unreachable message, souced from Host1
But since firewall did not have the session initiated from host1 to R1, the icmp unreachable packet will be dropped?
Other than allwoing icmp unreachable through firewall, is there any other way? Kindly advise.
Thanks in advance.