National Research and Education Network
Education Cloud Data Center
Multi-Channel HD Telemedicine Solution
Over The Top/Multi-Tenant Data Center (OTT/MTDC)
Internet Exchange Point (IXP)
Internet Access Provider (IAP)
Design & Simulation
Planning & Analytics
Oil & Gas IoT
HPC & Operations Management
Digital Urban Rail
Retail Cloud Platform
Enterprise Data Center
Enterprise Cloud Communications
Network Management System
Buy from Huawei
If you want to get more information about your project, you can submit your information and we will contact you as soon as possible.
If your company has signed an eDeal contract with Huawei, please buy your required product/solution via the link below.
Buy from resellers
Search for a nearby reseller and get direct contact information.
Become a Partner
Resources and Support
Huawei Authorized Learning Partner
Huawei Authorized Information and Network Academy
Customer cannot see it's firewall IP in a tracert output.
when customer do traceroute from client to some destination, he noted that the first hop (the USG Firewall)
is hidden. Example:
1 * * * --> this hop is the firewall and tracert response is hidden to client
2 <1ms <1ms <1ms 90.147.131.xxx
3 1 1 1 193.206.xxx.1
By CLI command, from the system view, execute:
icmp ttl-exceeded send - By default, an interface is disabled to send ICMP Time Exceeded message;
icmp host-unreachable send - this command enables transmitting the ICMP host-unreachable packets;
undo firewall defend tracert enable - if (firewall defend tracert enable) command is configured, a FW discards ICMP timeout packets, UDP timeout packets, or destination port unreachable packets.