The default UNIX traceroute uses UDP sockets, port > 30,000+. ICMP would not help him here, unless he is using (mtr) which uses ICMP. -----Original Message----- From: netfilter-admin@xxxxxxxxxxxxxxxxxxx [mailto:netfilter-admin@xxxxxxxxxxxxxxxxxxx] On Behalf Of Ruprecht Helms Sent: Wednesday, June 30, 2004 10:04 AM To: Peter Marshall Cc: netfilter Subject: Re: traceroute Peter Marshall wrote: >Hi. I was wondering what I would need for rules to have traceroute work >through my firewall. (I have a box behind the firewall trying to get out >using traceroute). > >Have a look to the icmp-types. You can begin by enabling icmp generally. > > Regards, Ruprecht