JasmineCorp Blogs
Updated Blogs
Fighting Obesity in Children
Computer Remote Support Software
IE9 Windows Server 2008 R2 Terminal Server RDS Server
Disable IE Enhanced Security on 2008 Server
More .....


JCBid.com online auction Pollenex-sbb8-teak-spa-bench
Pollenex sbb8 teak spa bench
JCBid.com online auction Madcatz-triga611-tritton-axpro-dolbyr-51-console-gaming-headset
Madcatz triga611 tritton axpro dolby(r)
JCBid.com online auction 80mm-dark-blue-globe-paper-wt
80mm dark blue globe paper wt
JCBid.com online auction 11-square-ss-griddle
11" square ss griddle
JCBid.com online auction Rca-rts635-low-profile-soundbar
Rca rts635 low-profile soundbar
Blog by JasmineCorp | Create your own Blog

Bookmark and Share RSS Feed | Login           

PC Tech Support


Tech support - post experiences and reviews on tech products worked with while on the job providing support to her customers and end-users.
 

Permit Trace Route on Cisco ASA


By PC Tech Support at 2009-11-29 07:51:36
The Cisco ASA not only blocks outbound pings out of the box as most firewwalls and security appliances do but also doesn't permit the trace route command from working. Traceroute is a command that is not used too often but is a tool used for trouble-shooting network issues. Traceroute is one of the built-in commands on desktops, laptops, and routers, this command gets used to find internet or internal internet connectivity problems. On the Cisco ASA, three lines of code need to be added to the access list for inside to outside traffic.

Configure ASA to allow traceroute responses.


To allow pings and trace route responce traffic from internal to the outside, add the following statements:

access-list pmt_out2IN extended permit icmp any any echo-reply
access-list pmt_out2IN extended permit icmp any any unreachable
access-list pmt_out2IN extended permit icmp any any time-exceeded

To allow RDP or terminal server traffic through an ASA: Open TCP 3689 inbound to that server whose public NAT is 230.198.191.25 , add this line:

access-list pmt_out2IN extended permit tcp any host 230.44.191.25 eq 3689










Share/Save/Bookmark












Permalink | Comments (1)

Comments



To add a comment please login by clicking here

JC Store | JasmineCorp | JCBid |Software Development | Domain Registration | Hosting | Web Designing | Buy Books | Advertise with JCSearch | Whois | IP Locator | Add Search | Shopping | Store | Free Blogs | Free GuestBook | Free E-Cards | Free Games | Free Tutorials | Set as Home | Add to Favorite | Suggest a Site | Directory Our Portfolio | Terms of service | Free quote | Tell a Friend | Special Offer | Job Opportunities | games | Usenet Groups  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Register a Domain Name:
.com .us .info
.org .in .name
.net .biz .asia