I cannot do outbound traceroutes from clients on the inside network to the Internet. I have allowed icmp outbound on the inside interface and allowed icmp echo-reply,unreachable and time-exceeded inbound on the outside interface. I still time outs on each hop till the destination.
Inbound UDP connections need to be allowed only if you want to perform inbound traceroutes thru the ASA, Am I right?
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
[toc:faq]Introduction:This document describes details on how NAT-T
works.Background:ESP encrypts all critical information, encapsulating
the entire inner TCP/UDP datagram within an ESP header. ESP is an IP
protocol in the same sense that TCP and UDP are I...