cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
19065
Views
10
Helpful
16
Replies

Traceroute through FTD

Colin Higgins
Level 2
Level 2

I am trying to get traceroute to work from my internal network to the Internet through a FTD2110 managed by FMC running 6.2.3 code

 

I created an access policy allowing ICMP type 3 and 11 from the outside to the inside. I added ICMP permit statements in the Platform Settings for the device (3 and 11 on the outside interface to any-ipv4).

 

I also added the Flex config statement to decrement the TTL

 

But this still isn't working. Is this a bug? Unsupported? 

16 Replies 16

icmp permit any time-exceeded <your outside interface name>
icmp permit any unreachable <your outside interface name>

 How did you enabled this in FDM can't find?

This can be done in FDM using a Flexconfig object and policy:

MarvinRhoads_0-1717170970780.png

 

Review Cisco Networking for a $25 gift card