Can't traceroute through interfaces on ASA - possible

Unanswered Question
Sep 23rd, 2008
User Badges:

Hi,


From a windows PC I can't tracert or pathping though different interfaces on the ASA 5520 or to the internet, is this something that can be achieved?

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Loading.
satish_zanjurne Tue, 09/23/2008 - 06:40
User Badges:
  • Silver, 250 points or more


Yes !!!! it can be achieved.


For ASA/PIX 7.X


Use following access-list


access-list 101 permit icmp any any echo-reply

access-list 101 permit icmp any any source-quench

access-list 101 permit icmp any any unreachable

access-list 101 permit icmp any any time-exceeded

access-group 101 in interface outside


Or

Add following policy statement to global policy.


policy-map global_policy

class inspection_default

inspect icmp


HTH...rate if helpfull....

jamesgonzo Tue, 09/23/2008 - 07:57
User Badges:

Thanks, I have added:


policy-map global_policy

class inspection_default

inspect icmp


But no change. I'm trying from a subinterface off the ASA (VLAN in a 3750). Do I need to do something else?


Thanks

Actions

This Discussion