cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1101
Views
0
Helpful
1
Replies

Traceroute + Antispoofing on not default route

Hi all,

I've enabled antispoof on all interfaces on asa 5510

If you start a traceroute to a network on the default route, everything works, since replies comes to an interface with route 0.0.0.0/0 defined.

If you start a tracer route to a network that is NOT on the default route (let's assume coporate MPLS), you only get response from first carrier router, the other are discarded because of anti spoof violation.

I have ICMP inspection and icmp-error inspection enabled.

is there any way to solve this?

1 Reply 1

Humm...

Do you really think it's a good idea to add other default route in other interface????

I'm afraid that would completely break conectivity.

I'd say youre saying there's no fix.

Review Cisco Networking products for a $25 gift card