<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firewall 5506-x blocking all DNS queries in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725395#M1013775</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Have configured Firepower or are you just using ASA? Do you get any logs when the issue occurs?&lt;/P&gt;</description>
    <pubDate>Mon, 15 Oct 2018 09:04:45 GMT</pubDate>
    <dc:creator>Martin Kling</dc:creator>
    <dc:date>2018-10-15T09:04:45Z</dc:date>
    <item>
      <title>Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725282#M1013772</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;
&lt;P&gt;I am observing my firewall 5506-x&amp;nbsp;since a month that after 2 or 3 days, firewall suddenly stop resolving&amp;nbsp;DNS queries and all internet traffic stop. while in this situation IP communication remain OK which means i can ping/browse across the firewall but if i will reboot firewall then it will start working normally.&lt;/P&gt;
&lt;P&gt;any idea what is happening with&amp;nbsp;firewall ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725282#M1013772</guid>
      <dc:creator>Zargham Haider</dc:creator>
      <dc:date>2019-03-12T14:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725344#M1013773</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;What code do you use? ASA, ASA + Firepower or FTD? What version?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 07:38:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725344#M1013773</guid>
      <dc:creator>Martin Kling</dc:creator>
      <dc:date>2018-10-15T07:38:44Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725387#M1013774</link>
      <description>&lt;P&gt;Hi&amp;nbsp;Martin ...&lt;/P&gt;
&lt;P&gt;Thanks for reply..&lt;/P&gt;
&lt;P&gt;this is ASA 5506-x FirePOWER&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;# sh ver&lt;/P&gt;
&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.6(2)23&lt;BR /&gt;Device Manager Version 7.6(1)&lt;/P&gt;
&lt;P&gt;Compiled on Thu 28-Sep-17 07:50 PDT by builders&lt;BR /&gt;System image file is "disk0:/asa962-23-lfbff-k8.SPA"&lt;BR /&gt;Config file at boot was "startup-config"&lt;/P&gt;
&lt;P&gt;ProjectFW up 3 days 23 hours&lt;/P&gt;
&lt;P&gt;Hardware: ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)&lt;BR /&gt;Internal ATA Compact Flash, 7168MB&lt;BR /&gt;BIOS Flash N25P64 @ 0xfed01000, 16384KB&lt;/P&gt;
&lt;P&gt;Encryption hardware device : Cisco ASA Crypto on-board accelerator (revision 0x1)&lt;BR /&gt; Number of accelerators: 1&lt;/P&gt;
&lt;P&gt;1: Ext: GigabitEthernet1/1 : address is 2c5a.0f79.d225, irq 255&lt;BR /&gt; 2: Ext: GigabitEthernet1/2 : address is 2c5a.0f79.d226, irq 255&lt;BR /&gt; 3: Ext: GigabitEthernet1/3 : address is 2c5a.0f79.d227, irq 255&lt;BR /&gt; 4: Ext: GigabitEthernet1/4 : address is 2c5a.0f79.d228, irq 255&lt;BR /&gt; 5: Ext: GigabitEthernet1/5 : address is 2c5a.0f79.d229, irq 255&lt;BR /&gt; 6: Ext: GigabitEthernet1/6 : address is 2c5a.0f79.d22a, irq 255&lt;BR /&gt; 7: Ext: GigabitEthernet1/7 : address is 2c5a.0f79.d22b, irq 255&lt;BR /&gt; 8: Ext: GigabitEthernet1/8 : address is 2c5a.0f79.d22c, irq 255&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 08:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725387#M1013774</guid>
      <dc:creator>Zargham Haider</dc:creator>
      <dc:date>2018-10-15T08:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725395#M1013775</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Have configured Firepower or are you just using ASA? Do you get any logs when the issue occurs?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 09:04:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725395#M1013775</guid>
      <dc:creator>Martin Kling</dc:creator>
      <dc:date>2018-10-15T09:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725406#M1013776</link>
      <description>&lt;P&gt;Hi Martin........&lt;/P&gt;
&lt;P&gt;I am just using Firewall services not FirePOWER....unfortunately i didn't copy logs. (Just configured syslog today.. ) right now firewall is working fine. One thing i want to share is....I think due to some&amp;nbsp;strange activity ASA skips all ACL rules for DNS query and all dns queries fall in global deny list. because that specific time i checked packet trace which was denied by global acl list. but i am not able to find the reason why it happening like this. need your expert judgement here.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 09:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725406#M1013776</guid>
      <dc:creator>Zargham Haider</dc:creator>
      <dc:date>2018-10-15T09:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725432#M1013777</link>
      <description>&lt;P&gt;Can you mask you config and paste it here?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 09:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725432#M1013777</guid>
      <dc:creator>Martin Kling</dc:creator>
      <dc:date>2018-10-15T09:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725469#M1013778</link>
      <description>&lt;P&gt;Ok Martin...here is config file info&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!!&lt;/P&gt;
&lt;P&gt;!!&lt;/P&gt;
&lt;P&gt;!!&lt;/P&gt;
&lt;P&gt;: Saved&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;:&lt;/P&gt;
&lt;P&gt;: Serial Number: XXXXXXXXXXX&lt;/P&gt;
&lt;P&gt;: Hardware:&amp;nbsp;&amp;nbsp; ASA5506, 4096 MB RAM, CPU Atom C2000 series 1250 MHz, 1 CPU (4 cores)&lt;/P&gt;
&lt;P&gt;:&lt;/P&gt;
&lt;P&gt;ASA Version 9.6(2)23&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;hostname ProjectFW&lt;/P&gt;
&lt;P&gt;domain-name abc.com&lt;/P&gt;
&lt;P&gt;enable password 7sI3Z.cdfer2iY encrypted&lt;/P&gt;
&lt;P&gt;passwd 7sI3Z.xcvfgt2iY encrypted&lt;/P&gt;
&lt;P&gt;names&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nameif outside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security-level 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ip address x.x.x.x 255.255.255.0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nameif inside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ip address 192.168.81.7 255.255.255.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;dhcprelay server 192.168.81.25&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/3&lt;/P&gt;
&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/4&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nameif Winside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security-level 100&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ip address 192.168.83.7 255.255.255.0&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/6&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;shutdown&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;nameif xxx_Outside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;security-level 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;ip address&amp;nbsp;x.x.x.x 255.255.255.252&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/7&lt;/P&gt;
&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet1/8&lt;/P&gt;
&lt;P&gt;&amp;nbsp;shutdown&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;interface Management1/1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;management-only&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no nameif&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no security-level&lt;/P&gt;
&lt;P&gt;&amp;nbsp;no ip address&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;boot system disk0:/asa962-23-lfbff-k8.SPA&lt;/P&gt;
&lt;P&gt;ftp mode passive&lt;/P&gt;
&lt;P&gt;dns domain-lookup inside&lt;/P&gt;
&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;
&lt;P&gt;&amp;nbsp;name-server 192.168.81.25 inside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;domain-name abc.com&lt;/P&gt;
&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;
&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;
&lt;P&gt;object network obj_any&lt;/P&gt;
&lt;P&gt;&amp;nbsp;subnet 0.0.0.0 0.0.0.0&lt;/P&gt;
&lt;P&gt;object network Printer_192.168.81.31_Plotter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.81.31&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description Plotter&lt;/P&gt;
&lt;P&gt;object network Printer_192.168.81.36_xxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.81.36&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description xxxx&lt;/P&gt;
&lt;P&gt;object network Printer_192.168.81.47_xxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.81.47&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description xxx Printer&lt;/P&gt;
&lt;P&gt;object network Printer_192.168.81.41_xxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.81.41&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description xxxx&lt;/P&gt;
&lt;P&gt;object network Printer_192.168.81.45_xxxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.81.45&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description xxxx&lt;/P&gt;
&lt;P&gt;object network Printer_192.168.81.48_xxxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.81.48&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description xxxx&lt;/P&gt;
&lt;P&gt;object network Printer_192.168.81.42_xxxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.81.42&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description xxxx&lt;/P&gt;
&lt;P&gt;object network Printer_192.168.81.43_xxxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;host 192.168.81.43&lt;/P&gt;
&lt;P&gt;&amp;nbsp;description xxxx&lt;/P&gt;
&lt;P&gt;object-group service Syslog udp&lt;/P&gt;
&lt;P&gt;&amp;nbsp;port-object eq syslog&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit udp object-group DM_INLINE_NETWORK_2 any object-group DM_INLINE_UDP_1 log disable&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit object-group DM_INLINE_SERVICE_1 192.168.81.0 255.255.255.0 object-group ApprovedDNSServer&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 any object-group DM_INLINE_TCP_16 log disable&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 object sftp.norc.org eq ssh&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit object-group TCP-UDP 192.168.81.0 255.255.255.0 any object-group DM_INLINE_TCPUDP_1&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit ip object Server_xxx any&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit ip object-group NoRestrictionSource_aaa any log disable&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit ip object-group NoRestrictionSource_IT_Team any log disable&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit ip object-group NoRestrictionSource_aaaa any log disable&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit ip object-group Server_Live any&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended deny ip object-group Restricted_IPs any log disable&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit ip object-group NoRestrictionSources any&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 any object-group DM_INLINE_TCP_14&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 any object-group DM_INLINE_TCP_8&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 any object-group ApplePushNotificationService&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp any object-group Printers object-group Printer_TCP&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 any object-group DM_INLINE_TCP_15&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit ip 192.168.81.0 255.255.255.0 192.168.83.0 255.255.255.0 inactive&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit icmp 192.168.81.0 255.255.255.0 any&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit udp 192.168.81.0 255.255.255.0 any eq ntp&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp object Server_MigrationManager_81.199 any object-group DM_INLINE_TCP_18 inactive&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 any object-group DM_INLINE_TCP_9&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 any object-group DM_INLINE_TCP_5&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit udp any any object-group WhatsApp_UDP&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit object-group TCP-UDP any any object-group XMPP&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit tcp 192.168.81.0 255.255.255.0 any object-group DM_INLINE_TCP_7 inactive&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended permit ip 192.168.81.0 255.255.255.0 object-group GoodServers&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended deny ip any object-group Blocked_Addresses&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended deny object-group TCP-UDP any any object-group Torrent&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended deny ip object-group Blocked_Sources any&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended deny object-group TCP-UDP 192.168.81.0 255.255.255.0 any object-group HotspotShield&lt;/P&gt;
&lt;P&gt;access-list inside_access_in extended deny ip any any&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit udp 192.168.83.0 255.255.255.0 any object-group DM_INLINE_UDP_2&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit object-group DM_INLINE_SERVICE_6 192.168.83.0 255.255.255.0 object Server_xxx&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit udp 192.168.83.0 255.255.255.0 object-group Printers object-group Printer_HP_Ports&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit tcp 192.168.83.0 255.255.255.0 192.168.81.0 255.255.255.0 object-group DM_INLINE_TCP_13&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit tcp object-group xxx object-group DM_INLINE_NETWORK_4 object-group xxx&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit tcp 192.168.83.0 255.255.255.0 object-group ApprovedDNSServer eq domain&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit ip object-group NoRestrictionSources any&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit tcp 192.168.83.0 255.255.255.0 object-group Printers object-group Printer_TCP&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit icmp any any&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit object-group DM_INLINE_SERVICE_5 any object Server_xxx inactive&lt;/P&gt;
&lt;P&gt;access-list Winside_access_in extended permit object-group DM_INLINE_SERVICE_4 192.168.83.0 255.255.255.0 any inactive&lt;/P&gt;
&lt;P&gt;access-list outside_access_in extended permit object-group ICMP any any&lt;/P&gt;
&lt;P&gt;access-list outside_access_in extended permit tcp any interface outside object-group DM_INLINE_TCP_1&lt;/P&gt;
&lt;P&gt;access-list outside_access_in extended permit tcp any object aaa_x.x.x.x_ object-group DM_INLINE_TCP_2&lt;/P&gt;
&lt;P&gt;access-list outside_access_in extended permit tcp any object aab_x.x.x.x object-group DM_INLINE_TCP_3&lt;/P&gt;
&lt;P&gt;access-list outside_access_in extended permit tcp any object aac_x.x.x.x object-group DM_INLINE_TCP_4&lt;/P&gt;
&lt;P&gt;access-list inboundSurvey extended permit icmp any any object-group DM_INLINE_ICMP_1&lt;/P&gt;
&lt;P&gt;access-list inboundSurvey extended permit tcp any object xxx_Interface_Outside object-group DM_INLINE_TCP_12&lt;/P&gt;
&lt;P&gt;access-list OUTSIDE-IN extended permit icmp any any&lt;/P&gt;
&lt;P&gt;access-list outside_access_Out extended permit tcp any4 object xxx object-group DM_INLINE_TCP_10&lt;/P&gt;
&lt;P&gt;access-list outside_access_Out extended permit tcp any4 object Server_MigrationManager_81.199 object-group DM_INLINE_TCP_0&lt;/P&gt;
&lt;P&gt;access-list outside_access_Out extended permit ip object-group xxx object xxx_81.29&lt;/P&gt;
&lt;P&gt;access-list outside_access_Out extended permit object-group DM_INLINE_SERVICE_7 any4 object xxx&lt;/P&gt;
&lt;P&gt;access-list outside_access_Out extended permit object-group DM_INLINE_SERVICE_0 any4 object xxx&lt;/P&gt;
&lt;P&gt;access-list outside_access_Out extended permit icmp object-group DM_INLINE_NETWORK_3 any inactive&lt;/P&gt;
&lt;P&gt;access-list outside_access_Out extended permit icmp any any&lt;/P&gt;
&lt;P&gt;access-list outside_access_Out extended deny ip any any&lt;/P&gt;
&lt;P&gt;access-list x_Outsite_access_in extended permit icmp any any&lt;/P&gt;
&lt;P&gt;access-list xxx-THROTTLE extended permit ip object Server_xxx any&lt;/P&gt;
&lt;P&gt;access-list xxxx-THROTTLE extended permit ip any object Server_xxx inactive&lt;/P&gt;
&lt;P&gt;access-list&amp;nbsp;xxx extended permit tcp 192.168.83.0 255.255.255.0 any object-group DM_INLINE_TCP_17&lt;/P&gt;
&lt;P&gt;pager lines 24&lt;/P&gt;
&lt;P&gt;logging enable&lt;/P&gt;
&lt;P&gt;logging timestamp&lt;/P&gt;
&lt;P&gt;logging trap critical&lt;/P&gt;
&lt;P&gt;logging asdm informational&lt;/P&gt;
&lt;P&gt;logging host inside 192.168.81.x&lt;/P&gt;
&lt;P&gt;no logging message 106015&lt;/P&gt;
&lt;P&gt;no logging message 313001&lt;/P&gt;
&lt;P&gt;no logging message 313008&lt;/P&gt;
&lt;P&gt;no logging message 106023&lt;/P&gt;
&lt;P&gt;no logging message 710003&lt;/P&gt;
&lt;P&gt;no logging message 106100&lt;/P&gt;
&lt;P&gt;no logging message 302015&lt;/P&gt;
&lt;P&gt;no logging message 302014&lt;/P&gt;
&lt;P&gt;no logging message 302013&lt;/P&gt;
&lt;P&gt;no logging message 302018&lt;/P&gt;
&lt;P&gt;no logging message 302017&lt;/P&gt;
&lt;P&gt;no logging message 302016&lt;/P&gt;
&lt;P&gt;no logging message 302021&lt;/P&gt;
&lt;P&gt;no logging message 302020&lt;/P&gt;
&lt;P&gt;flow-export destination inside 192.168.81.17 9996&lt;/P&gt;
&lt;P&gt;flow-export delay flow-create 15&lt;/P&gt;
&lt;P&gt;mtu outside 1500&lt;/P&gt;
&lt;P&gt;mtu inside 1500&lt;/P&gt;
&lt;P&gt;mtu Winside 1500&lt;/P&gt;
&lt;P&gt;mtu NTL_Outside 1500&lt;/P&gt;
&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;
&lt;P&gt;no asdm history enable&lt;/P&gt;
&lt;P&gt;arp timeout 14400&lt;/P&gt;
&lt;P&gt;no arp permit-nonconnected&lt;/P&gt;
&lt;P&gt;arp rate-limit 16384&lt;/P&gt;
&lt;P&gt;nat (inside,outside) source dynamic any interface dns&lt;/P&gt;
&lt;P&gt;nat (Winside,inside) source dynamic any interface dns&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;object network aaa&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) static interface service tcp 3389 3389&lt;/P&gt;
&lt;P&gt;object network aab&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) static xxx&lt;/P&gt;
&lt;P&gt;object network aac&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) static xxx&lt;/P&gt;
&lt;P&gt;object network aad&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) static xxx&lt;/P&gt;
&lt;P&gt;object network aae&lt;/P&gt;
&lt;P&gt;&amp;nbsp;nat (inside,outside) static xxx&lt;/P&gt;
&lt;P&gt;access-group outside_access_Out in interface outside&lt;/P&gt;
&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;
&lt;P&gt;access-group Winside_access_in in interface Winside&lt;/P&gt;
&lt;P&gt;access-group x Outsite_access_in in interface xxx Outside&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;route-map xxx permit 10&lt;/P&gt;
&lt;P&gt;&amp;nbsp;match ip address xxx&lt;/P&gt;
&lt;P&gt;&amp;nbsp;set ip next-hop x.x.x.x&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;route-map xxx permit 20&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x 1&lt;/P&gt;
&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;
&lt;P&gt;timeout pat-xlate 0:00:30&lt;/P&gt;
&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 sctp 0:02:00 icmp 0:00:02&lt;/P&gt;
&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;
&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;
&lt;P&gt;timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute&lt;/P&gt;
&lt;P&gt;timeout tcp-proxy-reassembly 0:01:00&lt;/P&gt;
&lt;P&gt;timeout floating-conn 0:00:00&lt;/P&gt;
&lt;P&gt;timeout conn-holddown 0:00:15&lt;/P&gt;
&lt;P&gt;user-identity default-domain LOCAL&lt;/P&gt;
&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;
&lt;P&gt;http server enable&lt;/P&gt;
&lt;P&gt;http 192.168.1.0 255.255.255.0 inside&lt;/P&gt;
&lt;P&gt;http 192.168.81.0 255.255.255.0 inside&lt;/P&gt;
&lt;P&gt;snmp-server host inside 192.168.81.x community *****&lt;/P&gt;
&lt;P&gt;no snmp-server location&lt;/P&gt;
&lt;P&gt;no snmp-server contact&lt;/P&gt;
&lt;P&gt;snmp-server community *****&lt;/P&gt;
&lt;P&gt;service sw-reset-button&lt;/P&gt;
&lt;P&gt;crypto ipsec security-association pmtu-aging infinite&lt;/P&gt;
&lt;P&gt;crypto ca trustpool policy&lt;/P&gt;
&lt;P&gt;telnet 192.168.81.0 255.255.255.0 inside&lt;/P&gt;
&lt;P&gt;telnet timeout 30&lt;/P&gt;
&lt;P&gt;ssh stricthostkeycheck&lt;/P&gt;
&lt;P&gt;ssh timeout 5&lt;/P&gt;
&lt;P&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;
&lt;P&gt;console timeout 0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;dhcpd domain abc.com&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;dhcpd address 192.168.83.30-192.168.83.245 Winside&lt;/P&gt;
&lt;P&gt;dhcpd dns 192.168.81.25 interface Winside&lt;/P&gt;
&lt;P&gt;dhcpd option 3 ip 192.168.83.253 interface Winside&lt;/P&gt;
&lt;P&gt;dhcpd option 6 ip 192.168.81.25 interface Winside&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;dhcprelay server 192.168.81.25 inside&lt;/P&gt;
&lt;P&gt;dhcprelay enable Winside&lt;/P&gt;
&lt;P&gt;dhcprelay timeout 160&lt;/P&gt;
&lt;P&gt;threat-detection basic-threat&lt;/P&gt;
&lt;P&gt;threat-detection scanning-threat shun except object-group NoRestrictionSource_IT_Team&lt;/P&gt;
&lt;P&gt;threat-detection scanning-threat shun except object-group NoRestrictionSource_xx&lt;/P&gt;
&lt;P&gt;threat-detection scanning-threat shun except object-group NoRestrictionSource_xx&lt;/P&gt;
&lt;P&gt;threat-detection scanning-threat shun except object-group NoRestrictionSources&lt;/P&gt;
&lt;P&gt;threat-detection scanning-threat shun except object-group NoShunnGroup&lt;/P&gt;
&lt;P&gt;threat-detection scanning-threat shun duration 1800&lt;/P&gt;
&lt;P&gt;threat-detection statistics host number-of-rate 3&lt;/P&gt;
&lt;P&gt;threat-detection statistics port number-of-rate 3&lt;/P&gt;
&lt;P&gt;threat-detection statistics protocol number-of-rate 3&lt;/P&gt;
&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;
&lt;P&gt;threat-detection statistics tcp-intercept rate-interval 30 burst-rate 400 average-rate 200&lt;/P&gt;
&lt;P&gt;dynamic-access-policy-record DfltAccessPolicy&lt;/P&gt;
&lt;P&gt;username xxx password 2dMuEBodaRTg/ojQ encrypted privilege 15&lt;/P&gt;
&lt;P&gt;username xxx password rFMCRvdj4RRRNLzF encrypted privilege 15&lt;/P&gt;
&lt;P&gt;username xxx password cmyrcWm5arRxckSs encrypted privilege 15&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;class-map global-class-NetFlow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;match any&lt;/P&gt;
&lt;P&gt;class-map CM-xxx-THROTTLE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;match access-list xxx-THROTTLE&lt;/P&gt;
&lt;P&gt;class-map inspection_default&lt;/P&gt;
&lt;P&gt;&amp;nbsp;match default-inspection-traffic&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;
&lt;P&gt;&amp;nbsp;parameters&lt;/P&gt;
&lt;P&gt;&amp;nbsp; message-length maximum client auto&lt;/P&gt;
&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;
&lt;P&gt;&amp;nbsp; no tcp-inspection&lt;/P&gt;
&lt;P&gt;policy-map PM-xxx-THROTTLE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;class CM-xxx-THROTTLE&lt;/P&gt;
&lt;P&gt;&amp;nbsp; police input 4000000 4000&lt;/P&gt;
&lt;P&gt;&amp;nbsp; police output 4000000 4000&lt;/P&gt;
&lt;P&gt;policy-map global_policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;class inspection_default&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect ftp&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect h323 h225&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect h323 ras&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect rsh&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect rtsp&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect esmtp&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect sqlnet&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect skinny&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect sunrpc&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect xdmcp&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect sip&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect netbios&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect tftp&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect ip-options&lt;/P&gt;
&lt;P&gt;&amp;nbsp;class global-class-NetFlow&lt;/P&gt;
&lt;P&gt;&amp;nbsp; flow-export event-type all destination 192.168.81.17&lt;/P&gt;
&lt;P&gt;&amp;nbsp;class class-default&lt;/P&gt;
&lt;P&gt;&amp;nbsp; user-statistics accounting&lt;/P&gt;
&lt;P&gt;policy-map global-policy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;class inspection_default&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect icmp&lt;/P&gt;
&lt;P&gt;&amp;nbsp; inspect icmp error&lt;/P&gt;
&lt;P&gt;!&lt;/P&gt;
&lt;P&gt;service-policy global_policy global&lt;/P&gt;
&lt;P&gt;service-policy PM-xxx-THROTTLE interface inside&lt;/P&gt;
&lt;P&gt;prompt hostname context&lt;/P&gt;
&lt;P&gt;no call-home reporting anonymous&lt;/P&gt;
&lt;P&gt;hpm topN enable&lt;/P&gt;
&lt;P&gt;Cryptochecksum:0d74e8c37dxxxxxxxe6d6166105&lt;/P&gt;
&lt;P&gt;: end&lt;/P&gt;
&lt;P&gt;no asdm history enable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Oct 2018 11:26:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3725469#M1013778</guid>
      <dc:creator>Zargham Haider</dc:creator>
      <dc:date>2018-10-15T11:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3726067#M1013779</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Normally wouldn't configuration issues cause working functions to stop working as they wouldn't work from the beginning. But I see that you have a lot of functions enabled like netflow, route maps, threat inspection etc enabled. Normally you are more exposed to hitting bugs with the more functions you enable. You are also running a code that no longer is downloadable.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My suggestion would be to upgrade the firewall to 9.6.4 or 9.8.2 (both last interim release) that have fixes for various bugs like memory leaks (which could explain your issues) alon with monitoring the logs on your syslog server&lt;/P&gt;
&lt;P&gt;Best regards,&lt;/P&gt;
&lt;P&gt;Martin&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 06:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3726067#M1013779</guid>
      <dc:creator>Martin Kling</dc:creator>
      <dc:date>2018-10-16T06:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall 5506-x blocking all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3726257#M1013780</link>
      <description>&lt;P&gt;Hi Martin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your reply....&lt;/P&gt;
&lt;P&gt;Actually you are right.... this was Memory leak bug. i found&amp;nbsp;the solution. this is&amp;nbsp;&lt;FONT size="3"&gt;&lt;STRONG&gt;Cisco Bug: CSCvd71473&lt;/STRONG&gt;. it relates to DNS memory leak "&lt;/FONT&gt;&lt;FONT size="3"&gt;slow memory leak when using many DNS queries". This issue is seen whenever a DNS query gets resolved on ASA. We could see a small amount of memory leak (around 64 Bytes with each DNS query getting resolved) on ASA.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size="3"&gt;for detailed information please read this Bug info:&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://quickview.cloudapps.cisco.com/quickview/bug/CSCvd71473" target="_blank"&gt;&lt;FONT size="3"&gt;https://quickview.cloudapps.cisco.com/quickview/bug/CSCvd71473&lt;/FONT&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Now i must look for latest codes as you said.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2018 11:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-5506-x-blocking-all-dns-queries/m-p/3726257#M1013780</guid>
      <dc:creator>Zargham Haider</dc:creator>
      <dc:date>2018-10-16T11:18:18Z</dc:date>
    </item>
  </channel>
</rss>

