|
Question : Traceroute problem
|
|
I am unable to traceroute to anything outside my PIX Firewall. It works fine on campus between networks. I can ping anything inside and outside of the PIX. I have verified ICMP permit any inside. I have also removed my outgoing access-list and it made no difference. We currently use an Enterasys SSR 8000 as our layer 3 switch. I'm not blocking UDP 33434. All of the traceroutes I try hit the gateway and die when tracing to off campus. What else can I try?
|
Answer : Traceroute problem
|
|
Are you sure your traceroute is using ICMP? Linux traceroute and others use UDP packets by default. In any case, if your traceroute does not return results beyond your firewall, then obviously your firewall (or to whatever external device your firewall is connected) is filtering the kind of packets necessary for your traceroute to work.
If you control the firewall, can you post the config here (feel free to change sensitive info - but please do it consistently)?
-Jon
|
|
|