Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Disable visibility in traceroute

As I know there is no chance to hide Fortigate in unix traceroute (just only disable pings). Maybe it' s good idea to implement it. Lumir
5 REPLIES 5
Not applicable

Putting the box in transparent mode should do the trick.
Not applicable

But you lost all the L3 functionality. Just disable responses to traceroute requests should be enough (like to ping requests)... Lumir
Not applicable

When you ping something you' re sending an ICMP echo packet to the target, which responds. When you use trace route, you' re also sending an ICMP echo packet except this time you' re using varying TTLs until you finally reach the target. Both methods use ICMP echo packets. There is no special " traceroute request" that can be dropped. If you' ve disabled ICMP Echo (PING) to the FGT, then you are dropping the traceroute requests. When you run tracert again, you will find that the FGT will not answer. It will appear as " *" . But, tracert is still going to list the box as being there because the box is still routing traffic. It won' t be invisible in the way you' re talking about unless you put the box into Transparent mode. Then yes, you will loose some services since the box will be essentially a very feature-rich switching device versus being a gateway device. Check here for a Microsoft description of tracert: http://support.microsoft.com/default.aspx?scid=kb;en-us;217014
Not applicable

JBult, I definitively don’t agree. The unix traceroute sends udp datagrams as the standard option. What I only need from my firewall is to discard and does not respond to - request which are sent to firewall’s IP (this is implemented in FG) - request which are sent to firewalled subnets behind the firewall and allow only defined communication (I hope this is implemented in FG :) but FG sends back icmp time exceeded ) So the recommendation is an option which can disable icmp at all or allow disabling particual icmp - like disabling of icmp time exceeded on Internet iface. Lumir
Not applicable

Hmmm... UDP, eh? Ok... I was able to dig up a " man" page on traceroute from somewhere. It does seem to use a UDP datagram versus an ICMP Echo like Windows uses. I didn' t know that. My explanation above was for the Windows tracert command. The only way I can think of doing what you want is to take a look under the IPS Signatures, specifically under ICMP. You can also try setting up a custom service to block this UDP packet explicitly or an ICMP service to block the response. Other than that, I' m not sure. It' s too bad that the FGT responds at all. There should be an option for the FGT to simply drop those. Good luck!
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors