We are currently trying to use netpath to monitor a service on a remote device outside of our local LAN however the path is not showing all of the required hops.
If you look at the attached image the device on the far left is the NPM server and the device on the far right is the external device, sitting inbetween these devices is a Cisco ASA Firewall (shown)

We have rules configured on the Cisco ASA Firewall to allow ICMP port 11 Time-Exceed incoming see images below


Even though these rules are configured Netpath still doesn't show the additional hops between the firewall and the end device.
After reading through some Solarwinds Success Articles for similar issues i can see the following errors in our firewall logs

The firewall is throwing out the port 11 message because in order to avoid DOS attacks it insists that the packet should have been the reply to an ICMP request from the safe side of the firewall.
I don't know how Hetpath works internally but it looks like these packets are hitting the outside interface of our firewall without any context and since the firewall doesn't want to be attacked it drops the returns.
Has anyone had a similar issue, and what did they do to resolve, asking on here first prior to possibly opening a service ticket for further assistance from Solarwinds.