I just moved off of a managed firewall to an in-house firewall. All seems to be working fine except for route tracing. When I perform a tracert (ip address) my first hop is my core switch and the second is my internal interface of my firewall. I then get asterisks, Request timed out, from hop 3 to 30 and at the end it says Trace Complete even though it didn't actually complete. In the Logviewer I see one entry at about hop 20 where the icmp is accepted to the resolved IP address. The rule is 9 which allows any internal source to use icmp-proto and icmp-requests along with other services to go out the firewall. Any ideas what is wrong?
Nokia IP530\Check Point NG FP2\ NT40 Management Station
Nokia IP530\Check Point NG FP2\ NT40 Management Station