cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
517
Views
5
Helpful
7
Replies

ASA not allowing trace

mohammedrafiq
Level 1
Level 1

Hi,

We have ASA5550 firwalling our LAN from internet,ICMP is open any any both way for test, but when we do trace to a public address on internet , ASA is not showing all the hops along the line. any idea ?

Regards,

7 Replies 7

andrew.prince
Level 10
Level 10

You need to configure the ASA to decrement the TTL in the traceroute - however there is a security advisory about this, the vulnerability is fixed in software version 7.2(3)6 or 8.0(3) and later.

HTH>

Thanks Andy,

Can you send me an example.

Regards,

Sure - try:-

!

policy-map global_policy

class class-default

set connection decrement-ttl

!

HTH>

Andy,

We are not doing any Qos on ASA,is this the only way?

We are running verison 8.04 IOS.

Regards,

That is not QoS configuration - it is amending the default policy that exists in the ASA.

There is no other way to configure the ASA to show itself as a hop in a trace route - the ASA will NOT decrement the TTL unless told to.

Thanks Andy,

Can you send me an example.

Regards,

see my previous post.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card