Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: traceroute
From: Steve Conner <sconner @ cycon . com>
Date: Fri, 6 Sep 1996 10:38:52 -0400 (EDT)
To: "James Rippas (Technology)" <jrippas @ fcmc . com>
Cc: firewalls @ GreatCircle . COM
In-reply-to: <9609060853 . ZM4508 @ alanis>

Hi James,

You are correct in assuming that the traceroute requires a UDP port.  The
problem is that traceroute sends out the UDP packets on a random upper
level port (>1023) and then listens for an ICMP reply.

My suggestion is try opening outbound UDP for a single host and see if the
ICMP packets can come back through.  Some firewalls have problems handling
the traceroute ICMP replies, but there are a couple of firewalls that I
know of that can handle these replies properly.

Steve

---------------------------------------------------------------
Steve Conner				Cypress Consulting, Inc.
sconner @
 cycon .
 com			703-256-1279
Manager, Research & Development		http://www.cycon.com
CYCON Labyrinth, Firewall and Network Address Translator	
---------------------------------------------------------------

On Fri, 6 Sep 1996, James Rippas (Technology) wrote:

> Hi,
> 
> I'd like to know what ports/protocol I need to permit through a packet filter
> for traceroute to work.  I've tried just ICMP/traceroute, but that doesn't
> work. I suspect I need to let a UDP port through, but I'm not sure.
> 
> Thanks,
> 
> -jim
> 



References:
  • traceroute
    From: "James Rippas (Technology)" <jrippas @ fcmc . com>
Indexed By Date Previous: Re: Firewalls-Digest V5 #347
From: Donna Jones <donna @ jarhead . msfc . nasa . gov>
Next: Re: C2 certified OS that can run a firewall
From: Rick Smith <smith @ sctc . com>
Indexed By Thread Previous: traceroute
From: "James Rippas (Technology)" <jrippas @ fcmc . com>
Next: Re: traceroute
From: Adrian Setton <asetton @ lightech . com . ar>

Google
 
Search Internet Search www.greatcircle.com