Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
junior_kakou
Contributor
Jump to solution

Linux traceroute packets blocked, but not window packets

Hello everyone;
i have set up a site to site vpn between our site A and site B with two mikrotik routers. the vpn works well. both sites can see each other. behind site A is a 3600 firewall and the pc's of both sites can see each other.
when i ping back and forth from a windows pc as well as a linux pc, the pings go through. a traceroute back and forth from a windows pc, we can reach the pc behind the firewall. But a traceroute from a linux PC can't reach the PC behind the firewall at site A. The packets don't get through the router.
To sum up:
a tracert from Site B on Windows reaches the PC behind Site A's firewall;
a traceroute from Site B on linux can't reach the pc behind Site A's firewall.

what could be the problem???
Thanks

 

0 Kudos
1 Solution

Accepted Solutions
Timothy_Hall
Legend Legend
Legend

Windows tracert sends ICMP requests, while Unix/Linux traceroute sends UDP packets bound for UDP high ports.  Use the tracert command from Gaia/Linux and it will work, you must be blocking UDP high ports somewhere in the path but not ICMP echo requests.

Edit: Windows tracert expects to get ICMP echo replies as responses, while Unix traceroute expects to receive Destination/Port unreachable responses.  So those latter types of responses could be getting blocked.

Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones

View solution in original post

(1)
1 Reply
Timothy_Hall
Legend Legend
Legend

Windows tracert sends ICMP requests, while Unix/Linux traceroute sends UDP packets bound for UDP high ports.  Use the tracert command from Gaia/Linux and it will work, you must be blocking UDP high ports somewhere in the path but not ICMP echo requests.

Edit: Windows tracert expects to get ICMP echo replies as responses, while Unix traceroute expects to receive Destination/Port unreachable responses.  So those latter types of responses could be getting blocked.

Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events