<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Traceroute is not working on VSX firewalls in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traceroute-is-not-working-on-VSX-firewalls/m-p/94793#M8935</link>
    <description>&lt;P&gt;Add the traceroute service to the services column, this will allow both the ping version and the UDP 33xxx version.&lt;/P&gt;</description>
    <pubDate>Thu, 20 Aug 2020 21:10:02 GMT</pubDate>
    <dc:creator>Maarten_Sjouw</dc:creator>
    <dc:date>2020-08-20T21:10:02Z</dc:date>
    <item>
      <title>Traceroute is not working on VSX firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traceroute-is-not-working-on-VSX-firewalls/m-p/94788#M8934</link>
      <description>&lt;P&gt;ping is working&lt;/P&gt;&lt;P&gt;[Expert@fwg-pedc--a:2]# ping 10.116.25.9&lt;BR /&gt;PING 10.116.25.9 (10.116.25.9) 56(84) bytes of data.&lt;BR /&gt;64 bytes from 10.116.25.9: icmp_seq=1 ttl=128 time=0.819 ms&lt;BR /&gt;64 bytes from 10.116.25.9: icmp_seq=2 ttl=128 time=0.300 ms&lt;/P&gt;&lt;P&gt;--- 10.116.25.9 ping statistics ---&lt;BR /&gt;2 packets transmitted, 2 received, 0% packet loss, time 1001ms&lt;BR /&gt;rtt min/avg/max/mdev = 0.300/0.559/0.819/0.260 ms&lt;BR /&gt;[Expert@fwg--a:2]# traceroute 10.116.25.9&lt;BR /&gt;traceroute to 10.116.25.9 (10.116.25.9), 30 hops max, 40 byte packets&lt;BR /&gt;1 * * *&lt;BR /&gt;2 * * *&lt;BR /&gt;3 * * *&lt;BR /&gt;4 * * *&lt;BR /&gt;5 * * *&lt;BR /&gt;6 *&lt;/P&gt;&lt;P&gt;For ping firewall log shows service icmp and passing&lt;/P&gt;&lt;P&gt;But for traceroute service shows gtp_path_mgmt (UDP/33501) and drop on default deny policy&lt;/P&gt;&lt;P&gt;How can we do traceroute?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 19:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traceroute-is-not-working-on-VSX-firewalls/m-p/94788#M8934</guid>
      <dc:creator>CPRQ</dc:creator>
      <dc:date>2020-08-20T19:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute is not working on VSX firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traceroute-is-not-working-on-VSX-firewalls/m-p/94793#M8935</link>
      <description>&lt;P&gt;Add the traceroute service to the services column, this will allow both the ping version and the UDP 33xxx version.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 21:10:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traceroute-is-not-working-on-VSX-firewalls/m-p/94793#M8935</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-08-20T21:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Traceroute is not working on VSX firewalls</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traceroute-is-not-working-on-VSX-firewalls/m-p/94805#M8936</link>
      <description>&lt;P&gt;Linux traceroute uses udp by default, unlike windows which relies on icmp.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Aug 2020 23:11:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Traceroute-is-not-working-on-VSX-firewalls/m-p/94805#M8936</guid>
      <dc:creator>Daniel_Schlifka</dc:creator>
      <dc:date>2020-08-20T23:11:32Z</dc:date>
    </item>
  </channel>
</rss>

