Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Tracert Not Working 2

Status
Not open for further replies.

gslee

Technical User
Dec 19, 2003
2
US
I just moved off of a managed firewall to an in-house firewall. All seems to be working fine except for route tracing. When I perform a tracert (ip address) my first hop is my core switch and the second is my internal interface of my firewall. I then get asterisks, Request timed out, from hop 3 to 30 and at the end it says Trace Complete even though it didn't actually complete. In the Logviewer I see one entry at about hop 20 where the icmp is accepted to the resolved IP address. The rule is 9 which allows any internal source to use icmp-proto and icmp-requests along with other services to go out the firewall. Any ideas what is wrong?
Nokia IP530\Check Point NG FP2\ NT40 Management Station
 
This is a quirk of FP2
it is solved by later fixes
 
Have you tried looking at the CP firewall logs to see what protocols/ports are getting denied. Do a tracert and then grab the log excerpt. You probably need to define some rules to allow ICMP packets out of the internal interface. By default ICMP outbound is denied as far as I can tell.

 
Nevermind, I re-read your post and realize you _have_ already checked the logs and rule...must be as Piloria says...;)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top