Allowing TraceRoute through an access-list

From: Lee Donald (Lee.Donald@t-systems.co.uk)
Date: Wed Apr 06 2005 - 11:04:19 GMT-3


I know this is a rather easy thing but I'm having a mental block with
TraceRoute.

 

I thought you just allow port-unreachable and ttl-exceeded for Cisco trace?
But it's not working, I've tried some of the others but no go.

 

Exactly which icmp type is it?

 

My access-list

 

Any help greatly appreciated.

 

 

 

 

Extended IP access list INBOUND

    10 permit icmp any any ttl-exceeded

    20 permit icmp any any port-unreachable

    30 permit icmp any any net-unreachable

    40 permit icmp any any time-exceeded

Extended IP access list OUTBOUND

    10 permit icmp any any ttl-exceeded

    20 permit icmp any any port-unreachable

    30 permit icmp any any net-unreachable

    40 permit icmp any any time-exceeded

 

 

 

 

Regards

 

Lee Donald.



This archive was generated by hypermail 2.1.4 : Tue May 03 2005 - 07:54:53 GMT-3