Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Community Member

no reply from Trace route across PIX vpn tunnel

I have the following setup:

site a -> sessionWall--routera--vpn tunnel--routerb---PIX--->routerc--siteb

there is a VPN tunnel between the sessionWall firewall and the PIX firewall, traffic is encypted within the tunnel, after the firewalls, traffic is clear.

when i do a trace route from site A to site B, I cannot see any reply from the routers(e.g. routerc) after the 2 firewalls, which is in the clear, I can only see reply from the end node. why is it so?

Thanks much for the advise,

Paul

2 REPLIES
Community Member

Re: no reply from Trace route across PIX vpn tunnel

Hi

My best guess would be that the source address that routerc replies to icmp with. may not necessarily be the address it is configured with on the siteb LAN, and therefore may not be allowed through the VPN tunnel.

Can you ping all of routerc's interface addresses?

HTH

Kev

Community Member

Re: no reply from Trace route across PIX vpn tunnel

Thank you Kev,

actually I can ping all the interfaces on routerc.

say if i am not worry about people mapping out my network. how do I actually allow trace route across my vpn tunnel, that is to allow all routers to reply, what is needed for trace route to work? I have actually enable ICMP type 11 on the PIX but it doesn't seems to work.

any advise appreciated.

164
Views
0
Helpful
2
Replies
CreatePlease to create content