<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco asa defaults for DNS inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392651#M1080264</link>
    <description>&lt;P&gt;is this HA or standalone, if this was there before adding the command not going to harm?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;before adding, do you see any issue with the DNS?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 25 Apr 2021 00:34:43 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-04-25T00:34:43Z</dc:date>
    <item>
      <title>Cisco asa defaults for DNS inspection</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392647#M1080263</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a question regarding DNS inspection on the ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would it make a difference running the DNS inspection without preset_dns_map ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I migrated my ASA newly from 9.4 to 9.8.4.34 and in the configurations I can see the below :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;policy-map global_policy
 class inspection_default
&amp;nbsp;&amp;nbsp;inspect dns&lt;/PRE&gt;&lt;P&gt;I don't see the below in my configuration at all.&lt;/P&gt;&lt;PRE&gt;policy-map type inspect dns preset_dns_map&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;I don't have any special Parameters in use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the question Do I need to copy the configuration from another ASA , to have the below parameters , or Its enabled by default with the DNS inspection and the purpose of preset_dns_map is to have customize it if needed ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class="p"&gt;The maximum DNS message length is 512 bytes.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p"&gt;DNS over TCP inspection is disabled.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p"&gt;The maximum client DNS message length is automatically set to match the Resource Record.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p"&gt;DNS Guard is enabled, so the ASA tears down the DNS session associated with a DNS query as soon as the DNS reply is forwarded by the ASA. The ASA also monitors the message exchange to ensure that the ID of the DNS reply matches the ID of the DNS query.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p"&gt;Translation of the DNS record based on the NAT configuration is enabled.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="p"&gt;Protocol enforcement is enabled, which enables DNS message format check, including domain name length of no more than 255 characters, label length of 63 characters, compression, and looped pointer check.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Sat, 24 Apr 2021 23:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392647#M1080263</guid>
      <dc:creator>MohammadKayed</dc:creator>
      <dc:date>2021-04-24T23:57:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco asa defaults for DNS inspection</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392651#M1080264</link>
      <description>&lt;P&gt;is this HA or standalone, if this was there before adding the command not going to harm?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;before adding, do you see any issue with the DNS?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Apr 2021 00:34:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392651#M1080264</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-25T00:34:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco asa defaults for DNS inspection</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392653#M1080265</link>
      <description>&lt;P&gt;Its an HA active/standby.&lt;/P&gt;&lt;P&gt;I don't have Show tech nor Show run from the old version.&lt;/P&gt;&lt;P&gt;The purpose I am looking on it , My device memory is reaching 90+ ( on both units including the standby ) although the device is not oversubscribed ( ACL count , conn count all lower than the limit ) , I have a lot of traffic is being inspected by DNS when I run show service-policy It might be the reason but not sure as the CPU is normal ( below 20% )/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know it might be a bug or memory leak issue but I would like to understand better the DNS inspection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it necessarily to add&amp;nbsp;preset_dns_map to the DNS inspection although I don't have any costume paraments ?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Apr 2021 00:50:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392653#M1080265</guid>
      <dc:creator>MohammadKayed</dc:creator>
      <dc:date>2021-04-25T00:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco asa defaults for DNS inspection</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392717#M1080269</link>
      <description>&lt;P&gt;here is the release notes and some memory leak bugs are fixed. there is also DNS (CSCvg09778) - check this may be relavant.(but we need more information)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/release/notes/asarn98.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa98/release/notes/asarn98.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;My device memory is reaching 90+ ( on both units including the standby ) although the device is not oversubscribed ( ACL count , conn count all lower than the limit ) , I have a lot of traffic is being inspected by DNS when I run show service-policy It might be the reason but not sure as the CPU is normal ( below 20% )/&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This needs more information for us to confirm what process taking high on CPU.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;#&lt;STRONG&gt;show processes cpu-usage sorted non-zero&lt;/STRONG&gt; - identify the process taking up the most of the CPU&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#&lt;STRONG&gt;show interface&lt;/STRONG&gt; - check for input or output errors&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;#&lt;STRONG&gt;show traffic&lt;/STRONG&gt; - check interfaces with unusually high traffic&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Apr 2021 08:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392717#M1080269</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-04-25T08:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco asa defaults for DNS inspection</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392831#M1080272</link>
      <description>&lt;P&gt;Thank you for the reply.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked the bug , It seems already fixed in 9.8.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;#&lt;/SPAN&gt;&lt;STRONG&gt;show processes cpu-usage sorted non-zero&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp;-- &amp;gt; DATAPATH ( Multiple processes each consume 1.0 - 2 % )&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;CPU usage currently is around 22%&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;#&lt;STRONG&gt;show interface --- &amp;gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I don't see any overrun or underrun on a physical interface&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I do see the below :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1) Internal Data0/0 -- &amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;134721 overrun from 116432711000 input packet ( 1-4% very small value )&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;No underrun&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) Internal Data0/1&lt;/P&gt;&lt;P&gt;5e-4% overrun&lt;/P&gt;&lt;P&gt;no underrun&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Internal Data0/2&lt;/P&gt;&lt;P&gt;3e-5% overrun&lt;/P&gt;&lt;P&gt;no underrun&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) Internal Data0/3&lt;/P&gt;&lt;P&gt;1.3e-4% overrun&lt;/P&gt;&lt;P&gt;2e-4% underrun&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;4) internal data0/4 - 0/7 doesn't have any overrun or underrun&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;#&lt;/SPAN&gt;&lt;STRONG&gt;show traffic&amp;nbsp; --&amp;gt; As the issue with the memory&amp;nbsp;does it worth to look at it ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;All interfaces seems fine except the below :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;g0/4&amp;nbsp; failover link ( which is should be ok as the replication from the active to standby ) - Data collected from active unit&lt;/P&gt;&lt;P&gt;--- &amp;gt; received packets : 11476850&lt;/P&gt;&lt;P&gt;--- &amp;gt; transmitted packets : 24740454127&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---------&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Extra info :&lt;/P&gt;&lt;P&gt;Active current memory :&lt;/P&gt;&lt;P&gt;85% --- &amp;gt;65% global shared pool&lt;/P&gt;&lt;P&gt;CPU-- &amp;gt; around 22%&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Standby unit : ( memory of the standby unit is higher )&lt;/P&gt;&lt;P&gt;90% --- &amp;gt; global shared&lt;/P&gt;&lt;P&gt;4% cpu&lt;/P&gt;</description>
      <pubDate>Sun, 25 Apr 2021 14:49:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-defaults-for-dns-inspection/m-p/4392831#M1080272</guid>
      <dc:creator>MohammadKayed</dc:creator>
      <dc:date>2021-04-25T14:49:06Z</dc:date>
    </item>
  </channel>
</rss>

