<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPv6 Traceroute not returning hops before the destination in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ipv6-traceroute-not-returning-hops-before-the-destination/m-p/560308#M4461</link>
    <description>&lt;P&gt;I have two GlobalProtect installations each configured differently. I can ping and connect to IPv6 destinations just fine. If I run a traceroute to the IPv6 destinations using UDP or ICMP, I do not get the hops before the destination. For example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tracing route to google.com [2607:f8b0:4005:80d::200e]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;
&lt;P&gt;1 * * * Request timed out.&lt;BR /&gt;2 * * * Request timed out.&lt;BR /&gt;3 * * * Request timed out.&lt;BR /&gt;4 * * * Request timed out.&lt;BR /&gt;5 * * * Request timed out.&lt;BR /&gt;6 15 ms 14 ms 14 ms 2607:f8b0:4005:80d::200e&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I use a system that is on-prem, not using GlobalProtect, the traceroutes work fine. We have two WANs, and an Internet connection, and it doesn't matter what path I traceroute across. The same thing happens.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can get the traceroute to show every hop from the GlobalProtect connected machine if I do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.) Traceroute using an on-prem system&lt;/P&gt;
&lt;P&gt;2.) Record each hop I learned from the on-prem machine&lt;/P&gt;
&lt;P&gt;3.) Ping each hop from the GlobalProtect machine&lt;/P&gt;
&lt;P&gt;4.) Traceroute from the GlobalProtect Machine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then the traceroute works! I can't always do this though, especially if there are a lot of router choices and the packets choose a different path. Very weird that pinging each hop in the path gets the traceroute to work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone every experienced issues not getting the hops in the path when tracerouting to IPv6 destinations from GlobalProtect? I am trying to figure out what could be blocking it. The Security Policies we have are wide open outbound.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 03 Oct 2023 04:13:36 GMT</pubDate>
    <dc:creator>jonathanhunt</dc:creator>
    <dc:date>2023-10-03T04:13:36Z</dc:date>
    <item>
      <title>IPv6 Traceroute not returning hops before the destination</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ipv6-traceroute-not-returning-hops-before-the-destination/m-p/560308#M4461</link>
      <description>&lt;P&gt;I have two GlobalProtect installations each configured differently. I can ping and connect to IPv6 destinations just fine. If I run a traceroute to the IPv6 destinations using UDP or ICMP, I do not get the hops before the destination. For example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tracing route to google.com [2607:f8b0:4005:80d::200e]&lt;BR /&gt;over a maximum of 30 hops:&lt;/P&gt;
&lt;P&gt;1 * * * Request timed out.&lt;BR /&gt;2 * * * Request timed out.&lt;BR /&gt;3 * * * Request timed out.&lt;BR /&gt;4 * * * Request timed out.&lt;BR /&gt;5 * * * Request timed out.&lt;BR /&gt;6 15 ms 14 ms 14 ms 2607:f8b0:4005:80d::200e&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If I use a system that is on-prem, not using GlobalProtect, the traceroutes work fine. We have two WANs, and an Internet connection, and it doesn't matter what path I traceroute across. The same thing happens.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can get the traceroute to show every hop from the GlobalProtect connected machine if I do the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1.) Traceroute using an on-prem system&lt;/P&gt;
&lt;P&gt;2.) Record each hop I learned from the on-prem machine&lt;/P&gt;
&lt;P&gt;3.) Ping each hop from the GlobalProtect machine&lt;/P&gt;
&lt;P&gt;4.) Traceroute from the GlobalProtect Machine&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then the traceroute works! I can't always do this though, especially if there are a lot of router choices and the packets choose a different path. Very weird that pinging each hop in the path gets the traceroute to work.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone every experienced issues not getting the hops in the path when tracerouting to IPv6 destinations from GlobalProtect? I am trying to figure out what could be blocking it. The Security Policies we have are wide open outbound.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Oct 2023 04:13:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/ipv6-traceroute-not-returning-hops-before-the-destination/m-p/560308#M4461</guid>
      <dc:creator>jonathanhunt</dc:creator>
      <dc:date>2023-10-03T04:13:36Z</dc:date>
    </item>
  </channel>
</rss>

