Forum Discussion
Hello_World_146
Nimbostratus
Jun 02, 2014ICMP Filter
Hi Team,
I would like to set an ICMP filter in a CGNAT so that pings coming from internal clients to the internet (e.g. google.com) can go through normally, but trace routes do not show the inte...
Cory_50405
Noctilucent
Jun 02, 2014I would think in order to not show the CGNAT hops, you would want to block ICMP from your CGNATs back to the internal client network. Traceroute depends on network devices to send back ICMP time exceeded messages to the client once the TTL reaches zero. So if you prevent the ICMP messages (type 11) from your CGNAT back to your internal network, then that should achieve what you wish.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
