Sanfor IAM - Traceroute showing * in first HOP

syedjahanzaib Lv1Posted 20 Jun 2023 16:48

Last edited by syedjahanzaib 20 Jun 2023 16:49.

User default gateway is pointed towards Sangfor IAM. All protocols are allowed for test purposes. Ping ICMP response of internet sites is working fine. upon perfomring traceroute from client PC to any internet site, first HOP (IAM internal IP) is always showing *
How can I allow sangfor IP in trceroute instead of * ?


  1. PS C:\> tracert -d 8.8.8.8

  2. Tracing route to 8.8.8.8 over a maximum of 30 hops

  3.   1     *        *        *     Request timed out.   <(<<< This should show SANGFOR Intenral LAN IP, instead its hiding and showing *)
  4.   2    <1 ms    <1 ms    <1 ms  ISP.WAN.ROUTER.IP
  5.   3     1 ms     1 ms     1 ms  X.X.X.X
  6. ....
Copy Code

By solving this question, you may help 517 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Zonger Lv4Posted 27 Jun 2023 19:34
  
If you are seeing "*" for the first hop in the traceroute output when tracing from a client PC to an internet site, it indicates that the device at that hop is not responding to the ICMP Time Exceeded message, which is used by traceroute to identify the intermediate hops.

To allow the Sangfor IAM internal IP to be visible in the traceroute output instead of "*", you need to enable ICMP Time Exceeded messages on the Sangfor IAM device. Here are the general steps to do so:

Access the management interface of the Sangfor IAM device.
Look for a configuration setting related to ICMP or traceroute.
Enable the ICMP Time Exceeded message response or traceroute support.
Save the configuration changes and apply them.
The specific steps and configuration options may vary depending on the version and model of the Sangfor IAM device. It is recommended to consult the documentation or contact Sangfor support for detailed instructions on how to enable ICMP Time Exceeded messages or traceroute support on your specific device.

Keep in mind that enabling ICMP Time Exceeded messages or traceroute support may have security implications, so it is important to consider the potential risks and ensure that appropriate security measures are in place.
Newbie814512 Lv2Posted 27 Jun 2023 13:39
  
To allow the Sangfor IAM internal IP to appear in traceroute instead of showing "", you need to configure the Sangfor IAM device to respond to ICMP Time Exceeded messages generated by the intermediate hops. By default, many network devices are configured to not respond to these messages, which is why you see "" in the traceroute output.


Here are the general steps to configure the Sangfor IAM device to allow ICMP Time Exceeded responses:


  • Access the Sangfor IAM device's administration interface or command-line interface (CLI).


  • Locate the settings related to ICMP or firewall configurations. The exact location of these settings may vary depending on the version and specific configuration of your Sangfor IAM device.


  • Look for an option to enable or allow ICMP Time Exceeded messages. This setting may be called "ICMP Redirect," "ICMP Time Exceeded," or something similar.


  • Enable the ICMP Time Exceeded response for the Sangfor IAM device. This allows it to respond to Time Exceeded messages generated by the intermediate hops during traceroute.


  • Save the configuration changes and restart the Sangfor IAM device or apply the changes as required.



After making these configuration changes, repeat the traceroute from the client PC to any internet site. You should now see the Sangfor IAM internal IP appearing as the first hop instead of showing "*". Keep in mind that the specific steps and options may vary based on your Sangfor IAM device's configuration interface, so consult the device's documentation or reach out to Sangfor support for detailed guidance.
Faisal P Posted 27 Jun 2023 12:22
  
Configure an application control policy. Choose Access Control > Application Control Page 40 SANGFOR Policy and enable all services
Kalem Lv3Posted 26 Jun 2023 19:54
  
Check if there are security measures that blocks the PC's connection.
Bebe_Bote Lv3Posted 26 Jun 2023 19:43
  
check if the antivirus is blocking its connectivity.
jetjetd Lv5Posted 26 Jun 2023 19:26
  
Please check the PC's firewall if it was turned on.
Farina Ahmed Posted 26 Jun 2023 14:54
  
In order to allow the Sangfor IAM internal IP to be displayed in the traceroute instead of "*", you need to configure the Sangfor IAM device to respond to ICMP Time Exceeded messages. By default, many network devices, including firewalls and security devices, are configured to not respond to these messages for security reasons.

To allow the Sangfor IAM internal IP to appear in the traceroute output, you'll need to follow these steps:

1) Log in to the Sangfor IAM management interface.
2) Navigate to the configuration settings related to ICMP.
3) Look for settings related to "ICMP Time Exceeded" or "ICMP Unreachable" messages.
4) Enable the option to respond to ICMP Time Exceeded messages. This will allow the device to send back the necessary information for traceroute.
5) Save the configuration changes and apply them.

After making these changes, perform a traceroute from the client PC to an internet site again. You should now see the Sangfor IAM internal IP instead of "*".
Alizaan Lv2Posted 26 Jun 2023 13:22
  
This is the normal behavior of how the Address Resolution Protocol functions.
Tatam Lv2Posted 26 Jun 2023 13:13
  
The * * is the indication of unsuccessful ping.
PrincesDivad Lv2Posted 26 Jun 2023 13:09
  
What do you need to accomplished? The result is normal for me.

I Can Help:

Change

Moderator on This Board

15
21
3

Started Topics

Followers

Follow

Board Leaders