Kalem Lv3Posted 26 Jun 2023 19:54
  
Check if there are security measures that blocks the PC's connection.
Faisal P Posted 27 Jun 2023 12:22
  
Configure an application control policy. Choose Access Control > Application Control Page 40 SANGFOR Policy and enable all services
Newbie814512 Lv2Posted 27 Jun 2023 13:39
  
To allow the Sangfor IAM internal IP to appear in traceroute instead of showing "", you need to configure the Sangfor IAM device to respond to ICMP Time Exceeded messages generated by the intermediate hops. By default, many network devices are configured to not respond to these messages, which is why you see "" in the traceroute output.


Here are the general steps to configure the Sangfor IAM device to allow ICMP Time Exceeded responses:


  • Access the Sangfor IAM device's administration interface or command-line interface (CLI).


  • Locate the settings related to ICMP or firewall configurations. The exact location of these settings may vary depending on the version and specific configuration of your Sangfor IAM device.


  • Look for an option to enable or allow ICMP Time Exceeded messages. This setting may be called "ICMP Redirect," "ICMP Time Exceeded," or something similar.


  • Enable the ICMP Time Exceeded response for the Sangfor IAM device. This allows it to respond to Time Exceeded messages generated by the intermediate hops during traceroute.


  • Save the configuration changes and restart the Sangfor IAM device or apply the changes as required.



After making these configuration changes, repeat the traceroute from the client PC to any internet site. You should now see the Sangfor IAM internal IP appearing as the first hop instead of showing "*". Keep in mind that the specific steps and options may vary based on your Sangfor IAM device's configuration interface, so consult the device's documentation or reach out to Sangfor support for detailed guidance.
Zonger Lv4Posted 27 Jun 2023 19:34
  
If you are seeing "*" for the first hop in the traceroute output when tracing from a client PC to an internet site, it indicates that the device at that hop is not responding to the ICMP Time Exceeded message, which is used by traceroute to identify the intermediate hops.

To allow the Sangfor IAM internal IP to be visible in the traceroute output instead of "*", you need to enable ICMP Time Exceeded messages on the Sangfor IAM device. Here are the general steps to do so:

Access the management interface of the Sangfor IAM device.
Look for a configuration setting related to ICMP or traceroute.
Enable the ICMP Time Exceeded message response or traceroute support.
Save the configuration changes and apply them.
The specific steps and configuration options may vary depending on the version and model of the Sangfor IAM device. It is recommended to consult the documentation or contact Sangfor support for detailed instructions on how to enable ICMP Time Exceeded messages or traceroute support on your specific device.

Keep in mind that enabling ICMP Time Exceeded messages or traceroute support may have security implications, so it is important to consider the potential risks and ensure that appropriate security measures are in place.

I Can Help:

Change

Moderator on This Board

15
21
3

Started Topics

Followers

Follow

Board Leaders