
241
Defining your security environment
Controlling full application inspection of traffic
Enabling support for traceroute
Traceroute has an option to specify a source route or to record the route taken. By default, the security
gateway has these features turned off for security reasons, since they could compromise information
about your inside networks. A ping request using one of these features is dropped and logged. Support
for this is re-enabled by adding the variable ping.preserve.ttl to the Advanced Services tab. Adding this
variable lets the security gateway respond properly to the traceroute command.
Prerequisites
Complete the following task before beginning this procedure:
■
“Configuring access for ICMP traffic”
To enable support for traceroute
1
In the SGMI, in the left pane, under Policy, click
Firewall
.
2
In the right pane, on the Rules tab, highlight the rule you created to pass ICMP traffic, and then
click
Properties
.
3
In the Rule Properties dialog box, on the Advanced Services tab, in the Parameter text box, type:
ping.preserve.ttl
4
Click
Add
.
5
Click
OK
.
6
Optionally, do one of the following:
■
To save your configuration now and activate later, on the toolbar, click
Save
.
■
To activate your configuration now, on the toolbar, click
Activate
.
When prompted to save your changes, click
Yes
.
Related information
For further information related to this topic, see the following:
■
Содержание Security 5600 Series, Security 5400 Series,Clientless VPN 4400 Series
Страница 76: ...76 Managing administrative access Enabling SSH for command line access to the appliance...
Страница 242: ...242 Defining your security environment Controlling full application inspection of traffic...
Страница 243: ...243 Defining your security environment Controlling full application inspection of traffic...
Страница 269: ...268 Limiting user access Authenticating using Out Of Band Authentication OOBA...
Страница 319: ...318 Controlling traffic at the security gateway Blocking inappropriate content with content filtering...
Страница 373: ...372 Preventing attacks Enabling protection for logical network interfaces...
Страница 409: ...408 Providing remote access using VPN tunnels Multicast traffic through gateway to gateway IPsec tunnels...
Страница 509: ...508 Generating reports Upgrade reports...
Страница 553: ...552 Advanced system settings Configuring advanced options...
Страница 557: ...556 SSL server certificate management Installing a signed certificate...
Страница 861: ...860 Index...