<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: asg_tracert in Hyperscale Firewall (Maestro)</title>
    <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266954#M3897</link>
    <description>&lt;P&gt;The 82 Maestro admin guide still shows below comment so it is still a relevant command to use.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The native Linux "&lt;/SPAN&gt;&lt;CODE&gt;tracert&lt;/CODE&gt;&lt;SPAN&gt;" utility cannot handle the "&lt;/SPAN&gt;&lt;CODE&gt;tracert&lt;/CODE&gt;&lt;SPAN&gt;" pings correctly because of the stickiness mechanism used in the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sg variable"&gt;Security Group&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_fwcap variable"&gt;Firewall&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 10 Jan 2026 16:45:55 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2026-01-10T16:45:55Z</dc:date>
    <item>
      <title>asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266953#M3896</link>
      <description>&lt;P&gt;At one point, it was recommended on Scalable Platforms to always use &lt;STRONG&gt;asg_tracert&lt;/STRONG&gt; instead of the native tracert/traceroute tools to ensure accurate results.&amp;nbsp; Is this still the case in Maestro?&amp;nbsp; Are the native traceroute/tracert tools just links to &lt;STRONG&gt;asg_tracert&lt;/STRONG&gt; on those platforms?&amp;nbsp; I don't have an active Maestro system readily available to check this.&amp;nbsp; Thanks!&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jan 2026 15:39:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266953#M3896</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-01-10T15:39:43Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266954#M3897</link>
      <description>&lt;P&gt;The 82 Maestro admin guide still shows below comment so it is still a relevant command to use.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The native Linux "&lt;/SPAN&gt;&lt;CODE&gt;tracert&lt;/CODE&gt;&lt;SPAN&gt;" utility cannot handle the "&lt;/SPAN&gt;&lt;CODE&gt;tracert&lt;/CODE&gt;&lt;SPAN&gt;" pings correctly because of the stickiness mechanism used in the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sg variable"&gt;Security Group&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_fwcap variable"&gt;Firewall&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jan 2026 16:45:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266954#M3897</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-01-10T16:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266961#M3898</link>
      <description>&lt;P&gt;Does this apply to the &lt;STRONG&gt;traceroute&lt;/STRONG&gt; command as well, which uses UDP datagrams instead of &lt;STRONG&gt;tracert&lt;/STRONG&gt;, which uses ICMP echo requests for probes?&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jan 2026 15:01:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266961#M3898</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-01-11T15:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266972#M3899</link>
      <description>&lt;P&gt;Seems like it. From the guide:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;Traceroute (asg_tracert)&lt;/H1&gt;
&lt;P class="Procedure_Heading"&gt;Description&lt;/P&gt;
&lt;P&gt;Use the "&lt;CODE&gt;asg_tracert&lt;/CODE&gt;" command in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_ScalablePlatforms.tp_ggcli variable"&gt;Gaia gClish&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;or the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_expert_mode variable"&gt;Expert mode&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to show correct&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;tracert&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;results on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sg variable"&gt;Security Group&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;The native "&lt;CODE&gt;tracert&lt;/CODE&gt;" cannot handle the "&lt;CODE&gt;tracert&lt;/CODE&gt;" pings correctly because of the stickiness mechanism used in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sg variable"&gt;Security Group&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_fwcap variable"&gt;Firewall&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;The "&lt;CODE&gt;asg_tracert&lt;/CODE&gt;" command supports all native options and parameters of the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;CODE&gt;tracert&lt;/CODE&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;command.&lt;/P&gt;</description>
      <pubDate>Sun, 11 Jan 2026 22:02:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/266972#M3899</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-11T22:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/267233#M3917</link>
      <description>&lt;P&gt;If you want i can run some commands for you on Maestro just PM me what you want me to test&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 18:19:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/267233#M3917</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-01-13T18:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/267242#M3918</link>
      <description>&lt;P&gt;asg_tracert is a lot slower, but seems to produce more consistent output:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;[Expert@DallasticXL-s01-02:0]# time traceroute -n 1.1.1.1
traceroute to 1.1.1.1 (1.1.1.1), 30 hops max, 40 byte packets
 1  10.0.1.1  2.704 ms  2.580 ms  2.504 ms
 2  w.x.y.z  33.097 ms  32.992 ms  33.100 ms
 3  184.19.247.176  33.266 ms 184.19.247.178  33.143 ms 184.19.247.176  33.269 ms
 4  74.40.10.208  34.011 ms  34.291 ms  34.590 ms
 5  74.40.10.110  34.145 ms  33.834 ms  33.989 ms
 6  45.52.201.127  37.234 ms  34.560 ms  34.311 ms
 7  * 141.101.74.63  34.983 ms 141.101.74.207  35.792 ms
 8  141.101.74.53  35.982 ms 1.1.1.1  35.249 ms 141.101.74.195  35.816 ms

real	0m5.010s
user	0m0.000s
sys	0m0.004s
[Expert@DallasticXL-s01-02:0]# time asg_tracert -n 1.1.1.1
traceroute to 1.1.1.1 (1.1.1.1), 30 hops max, 40 byte packets
 1  10.0.1.1  1.482 ms  0.679 ms  0.623 ms
 2  w.x.y.z  3.919 ms  1.782 ms  2.858 ms
 3  184.19.247.176  2.829 ms  2.158 ms  2.412 ms
 4  74.40.10.208  3.598 ms  3.267 ms  2.967 ms
 5  45.52.201.125  29.442 ms  3.317 ms  3.996 ms
 6  * 74.43.94.161  17.415 ms  10.169 ms
 7  141.101.74.65  3.674 ms  49.604 ms  3.658 ms
 8  1.1.1.1  3.394 ms  3.312 ms  3.433 ms

real	0m12.507s
user	0m0.003s
sys	0m0.008s&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jan 2026 22:01:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/267242#M3918</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2026-01-13T22:01:04Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/267261#M3919</link>
      <description>&lt;P&gt;Good day!&lt;/P&gt;&lt;P&gt;Out of curiosity I decided to check what asg_tracert is. "whereis asg_tracert" returns "/opt/CPsmo-R81.20/bin/asg_tracert"&lt;/P&gt;&lt;P&gt;"less&amp;nbsp;/opt/CPsmo-R81.20/bin/asg_tracert" reviels that the asg script contains only one command call:&amp;nbsp;"tracert -z 500 $@"&lt;/P&gt;&lt;P&gt;Then we can compare md5sum for @"/usr/bin/traceroute" and "/usr/bin/tracert" and result is the same!&lt;/P&gt;&lt;P&gt;-z is "sendwait" which explains why asg_tracert works slower&lt;/P&gt;&lt;P&gt;.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2026-01-14 102311.png" style="width: 298px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32694iD401966F892A2830/image-size/large?v=v2&amp;amp;px=999" role="button" title="2026-01-14 102311.png" alt="2026-01-14 102311.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2026-01-14 102355.png" style="width: 384px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32695i54CEEFCB45AAB5F8/image-size/large?v=v2&amp;amp;px=999" role="button" title="2026-01-14 102355.png" alt="2026-01-14 102355.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 07:26:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/267261#M3919</guid>
      <dc:creator>Gennady</dc:creator>
      <dc:date>2026-01-14T07:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269325#M3927</link>
      <description>&lt;P&gt;Hi Tim,&lt;BR /&gt;Honestly, I have never used asg_tracert command. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 31 Jan 2026 06:25:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269325#M3927</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-01-31T06:25:17Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269329#M3928</link>
      <description>&lt;P&gt;Thanks Lari, I was trying to figure out if asg_tracert was just a relic left over from the Scalable Platform Chassis days or if it still applied in Maestro.&lt;/P&gt;</description>
      <pubDate>Sat, 31 Jan 2026 14:03:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269329#M3928</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-01-31T14:03:55Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269497#M3929</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;I made some investigations. Here is what I found.&lt;BR /&gt;&lt;BR /&gt;Maestro has three tools for traceroute.&lt;/P&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;CODE&gt;traceroute&lt;/CODE&gt;&lt;/STRONG&gt; – Standard Linux traceroute using &lt;STRONG&gt;UDP&lt;/STRONG&gt;. Runs on the &lt;STRONG&gt;local SGM&lt;/STRONG&gt; where you execute it.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;CODE&gt;tracert&lt;/CODE&gt;&lt;/STRONG&gt; – Windows‑style traceroute using &lt;STRONG&gt;ICMP&lt;/STRONG&gt;. Also runs &lt;STRONG&gt;locally&lt;/STRONG&gt; on the SGM.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;CODE&gt;asg_tracert&lt;/CODE&gt;&lt;/STRONG&gt; – Uses &lt;STRONG&gt;ICMP&lt;/STRONG&gt;, but runs on the &lt;STRONG&gt;Flow Owner (FO)&lt;/STRONG&gt; for the destination, not necessarily the SGM you’re logged into. You can confirm the FO with dxl calc.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tracert.png" style="width: 556px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33018i1F470FEEECB2DEBF/image-size/large?v=v2&amp;amp;px=999" role="button" title="tracert.png" alt="tracert.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 22:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269497#M3929</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-02-02T22:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269499#M3930</link>
      <description>&lt;P&gt;See how asg_tracert and tracert have different results? If I go to the flow owner (SGM 2 in my case() and run tracert, the result is the same as for asg_tracert from SGM1.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tracert2.png" style="width: 505px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33019iEBF60431CDC33589/image-size/large?v=v2&amp;amp;px=999" role="button" title="tracert2.png" alt="tracert2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_3ae5a1626a198Lari_Luoma_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 22:39:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269499#M3930</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-02-02T22:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269507#M3931</link>
      <description>&lt;P&gt;Good evening, Tim. I have a lab environment set up here at NTSEC’s SKO with a Maestro cluster. I’m going to run some tests and analyze the behavior, and then I’ll get back to you with my findings and perspective on the topic.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 00:59:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269507#M3931</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-02-03T00:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269611#M3932</link>
      <description>&lt;P&gt;Got it, thanks Lari.&amp;nbsp; So, if I am not using asg_tracert, will the return traffic actually come back to the flow owner, and then be corrected to the SGM I actually ran the tracert/traceroute from?&amp;nbsp; I assume the correction does not touch the TTL and thus would not be shown in the tracert/traceroute output?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 23:49:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269611#M3932</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-02-03T23:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269612#M3933</link>
      <description>&lt;P&gt;That would be great, thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Feb 2026 23:49:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269612#M3933</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2026-02-03T23:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: asg_tracert</title>
      <link>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269757#M3936</link>
      <description>&lt;P&gt;Yes, that's my understanding. How the correction shows is that some responses are missing in &lt;STRONG&gt;tracert&lt;/STRONG&gt; and &lt;STRONG&gt;traceroute&lt;/STRONG&gt; outputs when run from the SMO. It's expected that there are more packets missing with ICMP. If I run &lt;STRONG&gt;tracert&lt;/STRONG&gt; from the flow owner, there won't be any drops and it looks the same as &lt;STRONG&gt;asg_tracert&lt;/STRONG&gt;. UDP and ICMP also behave differently as &lt;STRONG&gt;traceroute&lt;/STRONG&gt; only lost one packet.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Feb 2026 04:04:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Hyperscale-Firewall-Maestro/asg-tracert/m-p/269757#M3936</guid>
      <dc:creator>Lari_Luoma</dc:creator>
      <dc:date>2026-02-05T04:04:38Z</dc:date>
    </item>
  </channel>
</rss>

