Got it

How to show the concealed routes when you are doing tracert to USG5500

Latest reply: Mar 24, 2016 18:54:31 1349 1 0 0 0

When doing the tracert and the packets travel though the firewall ,we cannot see the detailed hops and it shows as "stars" instead,

here is the topology ,when we ping from Client 1 to Client 2 ,it shows like this :

 

PC>tracert 192.168.20.10

traceroute to 192.168.20.10, 8 hops max

(ICMP), press Ctrl+C to stop

1  192.168.10.1   16 ms  62 ms  47 ms

2    *  *  *                   (this hop stands for  firewall )

3  20.20.20.2   156 ms  78 ms  94 ms

4  192.168.20.10   109 ms  47 ms  62 ms

How to show the concealed routes when you are doing tracert to USG5500-1079245-1

After adding the following commands and we can see the detailed hops:
[SRG]ip ttl-expires enable
[SRG]ip unreachables enable
[SRG]undo  firewall defend tracert enable

Test result shown here :
PC>tracert 192.168.20.10
traceroute to 192.168.20.10, 8 hops max
(ICMP), press Ctrl+C to stop
1  192.168.10.1   62 ms  31 ms  32 ms
2  10.10.10.1   62 ms  47 ms  47 ms
3  20.20.20.2   78 ms  78 ms  63 ms
4  192.168.20.10   31 ms  47 ms  62 ms
By default an interface doesn't reply with an ICMP Time Exceeded message after it receives a message with TTL 1 , we need enable the sending of ICMP destination unreachable packets and  the ICMP timeout packets  with both commands.

View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.