12-10-2010 06:31 AM - edited 03-06-2019 02:28 PM
I am having an issue if I do a traceroute from our remote sites it stops at the vlan the fwsm is directly connected. So more detail... it hits the remote site's router then 3 next hops but once it gets to our 6513 which vlan2 is the firewall's connection, the trace stops, it still has to go the the 6509 which the servers are connected, but the traces do not make it there.
12-10-2010 08:13 AM
It is likely the firewall has no route back to the source address you are using.
Try to run the command with a different source address.
regards,
Leo
12-10-2010 08:34 AM
When you are performing your traceroute all routed hops along the path need to respond independently. If those
hops do not have routes, translations or access lists applied to the FWSM, they are going to fail. Very simple way to check. Run a syslog on
your FWSM, filter out the log and then perform your trace route again. You will receive messages in your
syslog that will detail why the FWSM is blocking the traffic.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide