[c-nsp] PIX and FWSM not decreasing TTL (was RE: Weird traceroutes through Firewall Services Module (FWSM))

Christian Zeng christian at zengl.net
Sat May 20 04:54:12 EDT 2006


Hi,

* Sam Stickland <sam_mailinglists at spacething.org> wrote:
>A PIX or FWSM does not decrease the TTL of traffic passing through it, even
>though it is a Layer3 device. Therefore, they NEVER show up in traceroutes.

>I need these devices to show up in traceroutes. Is this configuration
>possible? Google turns up surprisingly little on this.

Recently we discussed this behavior with the TAC. The TAC stated that this is
intended and they do not want to implement TTL decreasing in the (near) future.



Christian


More information about the cisco-nsp mailing list