Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

CAnnot Tracert to external IP's

I am trying to tracert to any external ip / website, and it times out.

I have a PIX515 and a Cisco 2611 router...where can I find out how to make this work?

  • Other Security Subjects
1 REPLY
Cisco Employee

Re: CAnnot Tracert to external IP's

If you're running 6.3 code on the PIX then enable the following command:

fixup protocol icmp-error

If you don't have this command then you have to allow the return ICMP packets back through the PIX, as th ePIX does not open holes for return ICMP traffic. Add the following line to your existing outside access-list:

access-list permit icmp any any

105
Views
0
Helpful
1
Replies
This widget could not be displayed.