09-05-2015 03:39 PM - edited 03-11-2019 11:33 PM
Hello Experts,
My question is how to enable traceroute on cisco ASA. I have seen alot of examples which allow traceroute through the ASA. However i am looking to enable traceroute on ASA itself. Like if i have an outside interface with IP 1.1.1.1 i could do traceroute to that IP 1.1.1.1. From windows i am able to do so as it uses icmp protocol. But what about linux/IOS which uses udp for traceroute.
Thanks in advance.
09-05-2015 05:18 PM
I am not 100% sure what you are trying to accomplish. Can you perhaps elaborate a bit more? The traceroute command is supported valid command and you can trace issue is from the ASA directly.
Thank you for rating helpful posts!
09-06-2015 05:40 AM
Hi.
I want to trace route Cisco asa outside interface from another source. We have two different data centres. I want dc B edge Router to be able to trace route dc A edge firewall outside interface. When I do so. It denies any udp packet.
09-07-2015 11:50 AM
Take a look at the following link:
http://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/15246-31.html
Thank you for rating helpful posts!
09-07-2015 04:30 PM
change the the access-list for your outside interface at dcA, to allow icmp from your dc B on the outside interface.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide