11-26-2009 07:14 PM - edited 03-04-2019 06:48 AM
In a lab enviroment I was experimenting with acl's and inspections. I could ping a destination with no problem but when trying to use traceroute to the same destination it would fail. Access list I was using was access-list 101 permit icmp any any echo-reply log
access-list 101 permit tcp any any www established log
Inspect rules were ip inspect name myrules tcp audit-trail on
ip inspect name myrules udp audit-trail on
ip inspect name myrules icmp audit-trail on
ip inspect name myrules http audit-trail on
ip inspect name myrules ftp audit-trail on
Trying figure out why ping would work and not traceroute. I am pinging accross a vpn tunnel to another router. Access list and inspection rules applied to the inbound port between tunnel router and destination router.
I am a CCNP student at local college.
Thaks, Doug
11-27-2009 01:49 AM
Please have a look at the following URL about how traceroute works:
If I understand your setup correctly, then I think you need at least the following ACEs included in the ACL:
access-list 101 permit icmp any any time-exceeded
access-list 101 permit icmp any any unreachable
11-30-2009 06:20 PM
Hi
I used you acl's and was able to successfully use the traceroute command.
Thanks, Doug
12-01-2009 03:10 AM
Hi Doug,
That's good news! Thanks for taking the time to provide feedback about the outcome.
Kind Regards,
Maria
12-02-2009 12:16 AM
Hi,
also note Cisco devices are sending UDP packets when running tracert command:
http://www.cisco.com/en/US/tech/tk364/technologies_tech_note09186a00801ae32a.shtml
BR,
Milan
12-02-2009 06:33 AM
Hi Milan,
You are right. In this case there was a single ACL reported to exist, it would permit echo-reply (so ping worked), and it was applied to some inbound port. For that reason I thought the problem was probably in the return path and suggested only the minimum required additional configuration for traceroute to work as well. What needs to be included in the ACLs depends on the direction the ACL is applied (in/out of interface).
Kind Regards,
Maria
Edit: I forgot to mention that the direction of the traceroute is also part of the game.
11-27-2009 06:04 PM
Thanks, I will give it a try Monday.
Doug
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: