02-14-2014 10:58 AM
The issue is that we can trace between networking equipment on tunnels involving the ISR routers using Firewall feature set, but we cannot trace to hosts. For example from (US)AS1, I can trace to (UK)CS1's 192.168.1.2 ip address, but not to host that I find in the arp table for that vlan. I have added ICMP TTL exceeded and TTL time-outs to the ACL's, but it still does not work. Any helf would be greatly appreciated
Solved! Go to Solution.
02-18-2014 10:44 AM
Elijay, You stated that you are using ISR's. Are you perhaps running inspection? If so, you may want to check your ICMP rules for router-traffic and timeouts. You may want to increase the timeout setting.
02-18-2014 10:44 AM
Elijay, You stated that you are using ISR's. Are you perhaps running inspection? If so, you may want to check your ICMP rules for router-traffic and timeouts. You may want to increase the timeout setting.
02-18-2014 11:07 AM
We were able to fix the traceroute problem by increasing the inspection timeout value to 20:
ip inspect name insp-outbound icmp timeout 20
thanks hunt-j
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide