<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036938#M144979</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I have done a show tech support report on the asa but cannot see myself any thing odd on the firewall.&lt;/P&gt;
&lt;P&gt;Yes all DNS queries gets dropped so we do not have any internet access out making use of the proxy server as it comes back saying DNS cannot be resolved, how ever if you bypass the proxy and open your IP on the FW for direct access and make use of an external DNS like 8.8.4.4 you are able to browse the internet.&lt;/P&gt;
&lt;P&gt;My problem here is the internal DNS that sits on the internal network is being blocked accessing the external DNS for queries like for example Internal DNS is querying 8.8.8.8 but gets denied.&lt;/P&gt;
&lt;P&gt;Deny udp src Inside_interface:x.x.x.x/53432 dst ISP_Interface 8.8.8.8/53 by access-group "global_access"&lt;/P&gt;
&lt;P&gt;This is one example I get similar denies for the same interface with different acces-groups.&lt;/P&gt;
&lt;P&gt;My CPU is running on 76% and my Memory usage is 3.9GB on the device.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Apr 2017 06:02:01 GMT</pubDate>
    <dc:creator>Hermanus Janse van Vuuren</dc:creator>
    <dc:date>2017-04-17T06:02:01Z</dc:date>
    <item>
      <title>ASA 5525X dropping all DNS queries</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036935#M144969</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have a problem since Friday and no shared support has not been renewed so I cannot open a TAC case.&lt;/P&gt;
&lt;P&gt;We have found that the ASA 5525X on ver 9.4.3(8) just started to deny all DNS requests.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have an ACL that allows the Internal DNS servers to communicated with the internet on port 53 on both udp/tcp.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After I have rebooted the Firewall everything was working 100% for between 20 - 40 min then just suddenly all UDP DNS queries gets dropped from the internal DNS servers to the external DNS servers. You reboot the FW and everything works again for 20 - 40 min.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have tried ver 9.4.4 and ver 9.7.1 and even downgraded to ver 8.6.1 all giving exactly the same problem, after the reboot all DNS queries is allowed and then suddenly everything is denied.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It is as if the FW skips all the ACL's created and denies the request on the global access ACL.&lt;/P&gt;
&lt;P&gt;What is even strangers is I have an Active/Standby setup, switch the 2 FW's around and the same happens, only after a reboot the DNS queries hits the correct ACL but only for 20 - 40 minutes. I have switched off the 1 FW now and is running on only 1 firewall.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any suggestions would be welcome on where or what to look at.&lt;/P&gt;
&lt;P&gt;No environmental changes was made only a few Office365 FQDN's that was added before all of this started.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you in advance.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036935#M144969</guid>
      <dc:creator>Hermanus Janse van Vuuren</dc:creator>
      <dc:date>2019-03-12T09:13:45Z</dc:date>
    </item>
    <item>
      <title>You should collect logs from</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036936#M144973</link>
      <description>&lt;P&gt;You should collect logs from ASA to debug what exactly is going on . Is that just DNS does not work or other services or also getting stopped ?&lt;/P&gt;
&lt;P&gt;Number of connection ,syslog ,cpu ...all these things will help to debug ?where is you DNS server located even packettracer will help .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ajay&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 03:49:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036936#M144973</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2017-04-17T03:49:26Z</dc:date>
    </item>
    <item>
      <title>+1.  What does the log say as</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036937#M144976</link>
      <description>&lt;P&gt;+1. &amp;nbsp;What does the log say as the reason for the traffic being blocked?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 03:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036937#M144976</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2017-04-17T03:56:08Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036938#M144979</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;I have done a show tech support report on the asa but cannot see myself any thing odd on the firewall.&lt;/P&gt;
&lt;P&gt;Yes all DNS queries gets dropped so we do not have any internet access out making use of the proxy server as it comes back saying DNS cannot be resolved, how ever if you bypass the proxy and open your IP on the FW for direct access and make use of an external DNS like 8.8.4.4 you are able to browse the internet.&lt;/P&gt;
&lt;P&gt;My problem here is the internal DNS that sits on the internal network is being blocked accessing the external DNS for queries like for example Internal DNS is querying 8.8.8.8 but gets denied.&lt;/P&gt;
&lt;P&gt;Deny udp src Inside_interface:x.x.x.x/53432 dst ISP_Interface 8.8.8.8/53 by access-group "global_access"&lt;/P&gt;
&lt;P&gt;This is one example I get similar denies for the same interface with different acces-groups.&lt;/P&gt;
&lt;P&gt;My CPU is running on 76% and my Memory usage is 3.9GB on the device.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 06:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036938#M144979</guid>
      <dc:creator>Hermanus Janse van Vuuren</dc:creator>
      <dc:date>2017-04-17T06:02:01Z</dc:date>
    </item>
    <item>
      <title>This seems to be issue with</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036939#M144981</link>
      <description>&lt;P&gt;This seems to be issue with ACL's . Do you have any specific ACL applied on interface where your DNS reside and UDP 53 is allowed ?&lt;/P&gt;
&lt;P&gt;Global access list applies logically to the entire firewall in inbound direction to all interface.&lt;/P&gt;
&lt;P&gt;You may paste device configuration here.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Ajay&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 06:14:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036939#M144981</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2017-04-17T06:14:07Z</dc:date>
    </item>
    <item>
      <title>Hi Ajay,</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036940#M144983</link>
      <description>&lt;P&gt;Hi Ajay,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes I have an ACL explicit for my DNS servers to access the internet on UDP/TCP port53. As I said this works well after a reboot for about 20 - 40 minutes then it skips all ACL's and go straight down to the global_access ACL.&lt;/P&gt;
&lt;P&gt;I have now allowed my DNS servers on the global_Access ACL to query DNS on port 53 TCP/UDP and problem has been resolved.&lt;/P&gt;
&lt;P&gt;Not the ideal solution but at-least we can browse now again and send email.&lt;/P&gt;
&lt;P&gt;I suspect some changes was made the day before this started adding a new VPN group, DMZ for them and some ACL's but I cannot see how this would stop the Firewall from reading the spesific interface ACL's and just go straight down to the Global one.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 07:31:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036940#M144983</guid>
      <dc:creator>Hermanus Janse van Vuuren</dc:creator>
      <dc:date>2017-04-17T07:31:11Z</dc:date>
    </item>
    <item>
      <title>Thank you Sir for actually</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036941#M144984</link>
      <description>&lt;P&gt;Thank you Sir for actually pointing me in the right direction with your question here, I never looked at the end of the deny output.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 07:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036941#M144984</guid>
      <dc:creator>Hermanus Janse van Vuuren</dc:creator>
      <dc:date>2017-04-17T07:32:01Z</dc:date>
    </item>
    <item>
      <title>I just found something</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036942#M144985</link>
      <description>&lt;P&gt;I just found something interesting. &amp;nbsp;There is an ASA DNS memory leak bug in the version of code you are running.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvd71473"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvd71473&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It is not showing any fixed releases, but I would upgrade to&amp;nbsp;&lt;SPAN&gt;asa963-1-smp-k8.bin to try and help.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 08:03:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036942#M144985</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2017-04-17T08:03:10Z</dc:date>
    </item>
    <item>
      <title>I have upgraded to the</title>
      <link>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036943#M144986</link>
      <description>&lt;P&gt;I have upgraded to the version you have mentioned below 9.6.3 and it seems to have resolved my issue. Just a point of note it would seem as if ver 9.7.1 also has the memory leak then as this did not resolve the issue when I ran it on that version.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you very much for the kind advice.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2017 12:11:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5525x-dropping-all-dns-queries/m-p/3036943#M144986</guid>
      <dc:creator>Hermanus Janse van Vuuren</dc:creator>
      <dc:date>2017-04-17T12:11:58Z</dc:date>
    </item>
  </channel>
</rss>

