Hi Christoph,
Binh Hoang of Cisco Systems stated,
"Have you tried enabling inspection for ICMP and see if that works?
See release notes for PIX 7.0 code below as regards to ICMP inspection.
Version 7.0(1) introduces an ICMP inspection engine. This engine enables secure usage of ICMP, by providing stateful tracking for ICMP connections, matching echo requests with replies. Additional controls are available for ICMP error messages, which are only permitted for established connections.
Use the inspect icmp and the inspect icmp error commands to configure the ICMP inspection engine."
Command reference:
formatting link
Thanks Binh, looks like it's fixed now. I indeed had to enable "inspect icmp error" to get traceroute's working again.
----------------------------------------------
Hope this helps.
BradReese.Com Cisco Repair Worldwide
1293 Hendersonville Road, Suite 17 Asheville, North Carolina USA 28803 Toll Free: 877-549-2680 International: 828-277-7272 Website:
formatting link