Allowing ICMP isnt enough for traceroute to work, traceroute uses
messages on successive UDP ports to get the route that is used
Allow UDP
33434 -> ( 33434 + MAX HOPS )
(33434 -> 33599, is the rule I use)
~Mat
Robert Staph wrote:
> no matter what rules about icmp I try I can't traceroute past my
> m0n0wall in the latest beta.
>
> -Rob
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: m0n0wall dash unsubscribe at lists dot m0n0 dot ch
> For additional commands, e-mail: m0n0wall dash help at lists dot m0n0 dot ch
>
|