Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Tracerouting through PIX

Status
Not open for further replies.

Ricter

ISP
Jan 18, 2003
1
US
Hi All,
When I traceroute from a switch on the DMZ through the pix to an inside network address I get an odd response:

dmz-switch> (enable) traceroute 161.112.113.232
traceroute to 161.112.113.232(161.112.113.232), 30 hops max, 40 byte packets
1 161.112.113.232(161.112.113.232) 7 ms 7 ms 8 ms
2 161.112.113.232(161.112.113.232) 8 ms 7 ms 7 ms
3 161.112.113.232(161.112.113.232) 7 ms 7 ms 8 ms

All the ips are the same. Is this because the request is coming from a lower security to a higher security interface?
It as if the pix is disguising the internal network ip's

Switch-PIX-INSIDE

Any help is appreciated
Thanks
 
That is the normal behaviour of the PIX. It is protecting your internal network by hiding the internal details from non trusted users. Otherwise your internal network could be scaned and compromised. Hope this helps!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top