I am trying to disable PING and Tracerout but leave it enable for internal hosts.
After done below configuraion, I can ping any outside hosts but can't do traceroute.
Can anyone tell me what configuration is missing? Thank you.
ip access-list extended ICMP
permit icmp any any echo-reply
permit icmp any any traceroute
deny icmp any any
permit ip any any
ip access-group ICMP in