cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2434
Views
5
Helpful
9
Replies

Allow tracert/pathping through firewall?

whiteford
Level 1
Level 1

Hi,

I have an ASA 5520, I am using sub-interfaces to a VLAN switch (Cisco 3750). I'm based on the "inside" and I need to use pathping and tracert from my PC to these remote networks that are on the VLANs.

I think the firewall might be blocking this, but am not sure. As soon as my trace gets to the firewall I get the * * * appear as if it's getting blocked.

Any Ideas?

9 Replies 9

Hi,

I just want the DMZ1 servers to tracert to my inside PC, do you know how I can do through the ASDM?

Did you read the url?

It outlines the procedure quite well I thought.

It also depends on the version of IOS you are using, the document covers it:-

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml#topic0

HTH>

Thing is I can ping fine, it's just the tracert and pathpings

Have you actually configured:-

policy-map global_policy

class inspection_default

inspect icmp

As the document instructs you to or:-

class-map class-default

match any

policy-map global_policy

class class-default

set connection decrement-ttl

HTH>

policy-map global_policy

class inspection_default

inspect icmp

has been added, is that a NAT I have to add?

The url you linked is now broken and I am having the same issues as the original poster. I figured since your are an Advocate, you would be able to point me in the right direction to find another one that read like your original link?

 

Thanks in advance.

@gpadmin The posts you are replying to are 13 years old.

For more current advice (and non-broken links as of June 2021), please check out these articles:

For ASA (old post but still 100% accurate):

https://packetu.com/2009/10/09/traceroute-through-the-asa/

For FTD:

https://packetu.com/2018/08/12/traceroute-through-firepower-threat-defense/

Thanks Marvin. I didn't realize the date-timestamp of those posts. Just found them having issues trying to get pathping results which I believe might be due to our ASA5508 firewall. I'll check out the ASA link. Your help is very much appreciated, thanks again!

Review Cisco Networking products for a $25 gift card