<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is TCP Inspection is necessary for DNS Inspection ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195359#M1065644</link>
    <description>Very very clear. Thank you so much Karsten &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
    <pubDate>Sat, 07 Oct 2017 10:42:59 GMT</pubDate>
    <dc:creator>Jiramate.Petcharat</dc:creator>
    <dc:date>2017-10-07T10:42:59Z</dc:date>
    <item>
      <title>Is TCP Inspection is necessary for DNS Inspection ?</title>
      <link>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195322#M1065638</link>
      <description>&lt;P&gt;I have a job to upgrade ASA to customer. (From 8.6 &amp;gt; 9.6..)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I saw in ASA version 9.0.2(and earlier) in section of DNS&amp;nbsp;Inspection command they didn't have "tcp-inspection".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;policy-map type inspect dns preset_dns_map&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; parameters&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp; message-length maximum client auto&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp; message-length maximum 512&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But after I upgrade it to 9.6.3 thay have&amp;nbsp; "no tcp-inspection" command show up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;policy-map type inspect dns preset_dns_map&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; parameters&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp; message-length maximum client auto&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp; message-length maximum 512&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;FONT face="courier new,courier" size="2"&gt;&amp;nbsp; &amp;nbsp; &lt;FONT color="#FF0000"&gt;no tcp-inspection&lt;/FONT&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This ASA is act like a firewall of server farm(so I think it's may have a DNS Server in INSIDE, that may need to use TCP), Is it should configure "&lt;SPAN&gt;tcp-inspection&lt;/SPAN&gt;" on DNS inspect paremeters ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Before, I had been implement ASA for other&amp;nbsp;site, I saw it have "no tcp-inspection" too, and DNS server of that site is work fine.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;PS:: From configuration guide, version 9.6 says in Defaults for DNS Inspection "&lt;SPAN&gt;DNS over TCP inspection is disabled.&lt;/SPAN&gt;". But in version 9.0 and 8.6 they didn't say anything.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/inspect-basic.html#ID-2092-00000007" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/firewall/asa-96-firewall-config/inspect-basic.html#ID-2092-00000007&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/inspect_basic.html#10154" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/inspect_basic.html#10154&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/inspect_basic.html#wp1335632" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/inspect_basic.html#wp1335632&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:27:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195322#M1065638</guid>
      <dc:creator>Jiramate.Petcharat</dc:creator>
      <dc:date>2020-02-21T14:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Is TCP Inspection is necessary for DNS Inspection ?</title>
      <link>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195345#M1065639</link>
      <description>&lt;P&gt;Today, DNS should be allowed to &lt;A href="http://ipj.dreamhosters.com/wp-content/uploads/issues/2014/ipj17-1.pdf" target="_self"&gt;run over both UDP and TCP&lt;/A&gt;. Many Admins didn‘t adopt this yet, but blocking TCP for DNS is considered a misconfiguration.&lt;/P&gt;
&lt;P&gt;If you allow TCP-transport, you should also apply security-measures for DNS for this transport.&lt;/P&gt;
&lt;P&gt;What to do:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you don‘t allow any outbound TCP/53 for DNS, then you don‘t need tcp-inspection. But you should think about correcting that.&lt;/LI&gt;
&lt;LI&gt;If you allow TCP-based DNS, then you should think about doing tcp-inspection to apply security also for TCP-transport.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 07 Oct 2017 09:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195345#M1065639</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-10-07T09:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is TCP Inspection is necessary for DNS Inspection ?</title>
      <link>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195353#M1065640</link>
      <description>&lt;P&gt;Thank you for your very clear explanation Karsten.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can I ask you more for my more clear ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If they didn't use TCP for DNS(&lt;SPAN&gt;Actually, I'm not sure), but I have put configure "tcp-inspection", It will impact to the&amp;nbsp;DNS traffic or network security ?&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;If they use&amp;nbsp;TCP&amp;nbsp;for DNS(Other site, I had implement), but I did't put "tcp-inspection",&amp;nbsp;It will impact to the&amp;nbsp;DNS&amp;nbsp;traffic or network security ?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;(I still confure because that site can use DNS server, but I don't know, may be DNS server admin may use other way to communicate with Public DNS? Or they can&amp;nbsp;&lt;SPAN&gt;communicate but did't inspect, cause lacking of security ?&lt;/SPAN&gt;&amp;nbsp;)&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Oct 2017 09:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195353#M1065640</guid>
      <dc:creator>Jiramate.Petcharat</dc:creator>
      <dc:date>2017-10-07T09:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: Is TCP Inspection is necessary for DNS Inspection ?</title>
      <link>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195355#M1065641</link>
      <description>&lt;P&gt;If there is no DNS over TCP, this command should have no effect at all.&lt;/P&gt;
&lt;P&gt;If there is is DNS over TCP but it is not configured, then there is no impact of functionality, but limited security for DNS.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Oct 2017 10:01:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195355#M1065641</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-10-07T10:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: Is TCP Inspection is necessary for DNS Inspection ?</title>
      <link>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195357#M1065642</link>
      <description>&lt;P&gt;So. For my understanding now.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;It should be/can configure, whether it use TCP or not ?&lt;/LI&gt;
&lt;LI&gt;After apply "tcp-inspection" for this network (that already use TCP for DNS and work well), after I had upgrade, It will not impact the DNS traffic ?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Am I right in understand?&lt;/P&gt;</description>
      <pubDate>Sat, 07 Oct 2017 10:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195357#M1065642</guid>
      <dc:creator>Jiramate.Petcharat</dc:creator>
      <dc:date>2017-10-07T10:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: Is TCP Inspection is necessary for DNS Inspection ?</title>
      <link>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195358#M1065643</link>
      <description>&lt;P&gt;After configuring it it will have an impact if there are protocol-anomalies or DNS-based attacks. After implementing it I would take a close look if everything runs right. especially if you run an outdated DNS-resolver. Early implementations of DNS over TCP were not that solid. With up-to-date operating systems there should be no problem with tcp-inspection.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Oct 2017 10:28:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195358#M1065643</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2017-10-07T10:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Is TCP Inspection is necessary for DNS Inspection ?</title>
      <link>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195359#M1065644</link>
      <description>Very very clear. Thank you so much Karsten &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;</description>
      <pubDate>Sat, 07 Oct 2017 10:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/is-tcp-inspection-is-necessary-for-dns-inspection/m-p/3195359#M1065644</guid>
      <dc:creator>Jiramate.Petcharat</dc:creator>
      <dc:date>2017-10-07T10:42:59Z</dc:date>
    </item>
  </channel>
</rss>

