AFAIK, traceroute operates by sending UDP packet destined for
random port. So you can't really enable traceroute past packet filter.
Maybe you can try looking at exact format of UDP packet traceroute sends
and allow packets with just that combination of bytes.
But I bet someone smart can hack this setup.
______________________________ Reply Separator _________________________________
Author: "James Rippas (Technology)" <jrippas @
com> at Internet
Date: 9/6/96 11:03 AM
I'd like to know what ports/protocol I need to permit through a packet filter
for traceroute to work. I've tried just ICMP/traceroute, but that doesn't
work. I suspect I need to let a UDP port through, but I'm not sure.