<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Support on PA for UNIX-Syle tracerouts in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10485#M7718</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As the last response to this was in Dec 2010, are there any plans to support traceroute on unix with an App-ID anytime soon?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 20 Oct 2011 20:13:28 GMT</pubDate>
    <dc:creator>msnazel</dc:creator>
    <dc:date>2011-10-20T20:13:28Z</dc:date>
    <item>
      <title>Support on PA for UNIX-Syle tracerouts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10483#M7716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 12pt; font-family: Calibri; "&gt;Does PA support unix-style tracerouts. I have enabled ICMP and PING, but tracerouts from unix hosts through palo alto are still being denied. Looking at this a little bit further, we noticed that windows-style tracerouts use ICPMP echo requests and rely on ICMP destination unreachables ,messages, but unix-style tracerouts send UDP packets with higher end ports, and rely on ICMP port unreachanbel messages.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2010 15:04:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10483#M7716</guid>
      <dc:creator>bbivolaku</dc:creator>
      <dc:date>2010-12-17T15:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Support on PA for UNIX-Syle tracerouts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10484#M7717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The firewall can allow both ICMP and UDP traceroutes through.&amp;nbsp; For Windows traceroute you would need to allow the 'ping' application.&amp;nbsp; For Unix traceroute your outbound policy will need to be a bit more relaxed since there is no specific traceroute App-ID yet.&amp;nbsp; When I allow all traffic through the firewall, Unix UDP traceroutes show up as "insufficient-data" in the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could manually allow Unix traceroute by configuring a Security Policy to allow UDP ports 33434 to 33534.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default, the firewall will respond with the ICMP TTL Expired message for traceroute.&amp;nbsp; You can suppress these messages with a Zone Protection profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kelly&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Dec 2010 17:09:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10484#M7717</guid>
      <dc:creator>kbrazil</dc:creator>
      <dc:date>2010-12-17T17:09:46Z</dc:date>
    </item>
    <item>
      <title>Re: Support on PA for UNIX-Syle tracerouts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10485#M7718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As the last response to this was in Dec 2010, are there any plans to support traceroute on unix with an App-ID anytime soon?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 20:13:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10485#M7718</guid>
      <dc:creator>msnazel</dc:creator>
      <dc:date>2011-10-20T20:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Support on PA for UNIX-Syle tracerouts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10486#M7719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe there will be a separate App-ID for traceroute including UDP. Please defer to your Sales SE to determine ETA/Roadmap.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Renato&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 22 Oct 2011 05:47:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/support-on-pa-for-unix-syle-tracerouts/m-p/10486#M7719</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-10-22T05:47:30Z</dc:date>
    </item>
  </channel>
</rss>

