- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-17-2010 07:04 AM
Does PA support unix-style tracerouts. I have enabled ICMP and PING, but tracerouts from unix hosts through palo alto are still being denied. Looking at this a little bit further, we noticed that windows-style tracerouts use ICPMP echo requests and rely on ICMP destination unreachables ,messages, but unix-style tracerouts send UDP packets with higher end ports, and rely on ICMP port unreachanbel messages.
12-17-2010 09:09 AM
Hi there,
The firewall can allow both ICMP and UDP traceroutes through. For Windows traceroute you would need to allow the 'ping' application. For Unix traceroute your outbound policy will need to be a bit more relaxed since there is no specific traceroute App-ID yet. When I allow all traffic through the firewall, Unix UDP traceroutes show up as "insufficient-data" in the logs.
You could manually allow Unix traceroute by configuring a Security Policy to allow UDP ports 33434 to 33534.
By default, the firewall will respond with the ICMP TTL Expired message for traceroute. You can suppress these messages with a Zone Protection profile.
Cheers,
Kelly
12-17-2010 09:09 AM
Hi there,
The firewall can allow both ICMP and UDP traceroutes through. For Windows traceroute you would need to allow the 'ping' application. For Unix traceroute your outbound policy will need to be a bit more relaxed since there is no specific traceroute App-ID yet. When I allow all traffic through the firewall, Unix UDP traceroutes show up as "insufficient-data" in the logs.
You could manually allow Unix traceroute by configuring a Security Policy to allow UDP ports 33434 to 33534.
By default, the firewall will respond with the ICMP TTL Expired message for traceroute. You can suppress these messages with a Zone Protection profile.
Cheers,
Kelly
10-20-2011 01:13 PM
As the last response to this was in Dec 2010, are there any plans to support traceroute on unix with an App-ID anytime soon?
10-21-2011 10:47 PM
Hi,
I believe there will be a separate App-ID for traceroute including UDP. Please defer to your Sales SE to determine ETA/Roadmap.
Regards,
Renato
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!