What Happened?
Customers or the SOC require a traceroute to be collected for troubleshooting or information gathering purposes.
Environment
-
Silverline WAF
- Silverline DDoS
Resolution/Answer
To take a Forward Traceroute (Client -> Silverline):
For Proxy Services:
-
-
- Run a traceroute from a client/user to your Silverline Proxy IP Address, Assigned DNS Name, or FQDN pointing towards your proxy.
From Windows:tracert 107.x.x.x
From macOS/Linux:
OR
tracert X.X.gslb.f5silverline.com
OR
tracert example.comtraceroute 107.x.x.x
OR
traceroute X.X.gslb.f5silverline.com
OR
traceroute example.com - Provide the output of the traceroute to the Silverline SOC
- Run a traceroute from a client/user to your Silverline Proxy IP Address, Assigned DNS Name, or FQDN pointing towards your proxy.
-
For Routed Services:
-
-
- Retrieve the IP for your allocated F5 Tunnel Endpoint from your router or in the Portal under Config > Routed Configuration > GRE Tunnel Management > Deployed
- Run a traceroute from client-side to the IP for your allocated F5 Tunnel Endpoint
traceroute 107.x.x.x
- Provide the output of the traceroute to the Silverline SOC.
-
To take a Reverse Traceroute (Origin Server or Customer premise equipment (CPE) -> Silverline SNAT):
For Proxy Services:
-
-
- Retrieve an IP address from Silverline's SNAT Ranges for one of your enabled Scrubbing Centers/Regions. Please See What are the Silverline Subnets (SNAT) / IP Address ranges? for a complete list of our SNAT Ranges and instructions for filtering for a specific region.
- Run a traceroute to the SNAT IP from your configured proxy backend or edge firewall
From Windows:tracert 107.x.x.x
From macOS/Linux:traceroute 107.x.x.x
- Provide the output of the traceroute to the Silverline SOC
-
For Routed Services:
-
-
- Retrieve the IP for your allocated F5 Tunnel Endpoint from your router or in the Portal under Config > Routed Configuration > GRE Tunnel Management > Deployed
- Run a traceroute from CPE to the specific Silverline F5 Tunnel Endpoint IP
traceroute 107.x.x.x
- Provide the output of the traceroute to the Silverline SOC.
-
Additional Information
ROUTED NOTE: When taking traceroutes from routing devices, additional flags may be necessary to get a successful trace. If you are unsure, please consult the team responsible for defining your router configurations.