Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Controlling types of ICMP Unreachable generated by filtering routers

As subject:

I want to be able to controll by ICMP code the types of ICMP Unreachable (Type 3) messages generated by a filtering router.

Scenario: BGP Peering routers to a web hosting infrastructure on the Internet, that want visibility of the path used via traceroute, however I dont want to advertise the fact that filtering is occuring by generating ICMP unreachable admin prohibtited or filtering prohibited.

I would also like to stay away from implementing outbound ACLs on the external interfaces just to control ICMP message generation.

Any other thoughts?

1 REPLY
VIP Purple

Re: Controlling types of ICMP Unreachable generated by filtering

Access lists would make it easier.

How about this for a compromise:

interface x/x

no ip unreachables

116
Views
0
Helpful
1
Replies