Hi there, The firewall can allow both ICMP and UDP traceroutes through. For Windows traceroute you would need to allow the 'ping' application. For Unix traceroute your outbound policy will need to be a bit more relaxed since there is no specific traceroute App-ID yet. When I allow all traffic through the firewall, Unix UDP traceroutes show up as "insufficient-data" in the logs. You could manually allow Unix traceroute by configuring a Security Policy to allow UDP ports 33434 to 33534. By default, the firewall will respond with the ICMP TTL Expired message for traceroute. You can suppress these messages with a Zone Protection profile. Cheers, Kelly
... View more