<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888277#M155460</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is it ok enabling &amp;nbsp;both . ?&lt;/P&gt;
&lt;P&gt;Does it help protecting from &amp;nbsp;dns amplification attack ?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2016 02:52:08 GMT</pubDate>
    <dc:creator>bluesea2010</dc:creator>
    <dc:date>2016-03-22T02:52:08Z</dc:date>
    <item>
      <title>globally vs  class-map inspection</title>
      <link>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888275#M155458</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;What is the differences between enabling &amp;nbsp;dns-guard globally or&amp;nbsp;creating &amp;nbsp;class-map inspection&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;firewall# configure terminal&lt;BR /&gt; firewall(config)# dns-guard&lt;BR /&gt; firewall(config)# exit&lt;BR /&gt; firewall#&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt; class-map inspection_default&lt;BR /&gt; match default-inspection-traffic&lt;BR /&gt;&lt;BR /&gt; policy-map type inspect dns preset_dns_map &lt;BR /&gt; parameters&lt;BR /&gt;&lt;BR /&gt;dns-guard&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888275#M155458</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2019-03-12T07:31:36Z</dc:date>
    </item>
    <item>
      <title>DNS guard allows you to</title>
      <link>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888276#M155459</link>
      <description>&lt;P&gt;DNS guard allows you to enforce check to &lt;G class="gr_ gr_32 gr-alert gr_spell gr_disable_anim_appear undefined ContextualSpelling ins-del multiReplace" id="32" data-gr-id="32"&gt;restrtick&lt;/G&gt; one DNS response per query &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/d3.html#pgfId-2054492"&gt;as stated here.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Whereas DNS inspection is more or less broad range of how DNS packets can be inspected on ASA and tweak and make checks on&amp;nbsp;&lt;SPAN&gt;message length, domain-name length, and label length&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Check &lt;STRONG&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa91/configuration/firewall/asa_91_firewall_config/inspect_basic.html#pgfId-2348065"&gt;this link&lt;/A&gt;&lt;/STRONG&gt; for your reference.&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 01:03:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888276#M155459</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-03-22T01:03:57Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888277#M155460</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Is it ok enabling &amp;nbsp;both . ?&lt;/P&gt;
&lt;P&gt;Does it help protecting from &amp;nbsp;dns amplification attack ?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 02:52:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888277#M155460</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2016-03-22T02:52:08Z</dc:date>
    </item>
    <item>
      <title>You shall enable DNS guard</title>
      <link>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888278#M155461</link>
      <description>&lt;P&gt;You shall enable&amp;nbsp;DNS guard for it and also setup regex to leverage &amp;nbsp;MPF&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/inspect_basic.html#wp1335632&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;BR /&gt;Dinesh Moudgil&lt;/P&gt;
&lt;P&gt;P.S. Please rate helpful posts.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 03:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888278#M155461</guid>
      <dc:creator>Dinesh Moudgil</dc:creator>
      <dc:date>2016-03-22T03:25:30Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888279#M155462</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;here is my setup&lt;/P&gt;
&lt;P&gt;we have local dns ( microsoft ) and configured forward there in microsoft &lt;BR /&gt;sometimes client use external dns (8.8.8.8).&lt;/P&gt;
&lt;P&gt;I don't permit dns port to the outside world&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Here is the output of show service-policy inspect dns&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Global policy: &lt;BR /&gt; Service-policy: global_policy&lt;BR /&gt; Class-map: inspection_default&lt;BR /&gt; Inspect: dns _default_dns_map, packet 222448193, lock fail 0, drop 53231, reset-drop 0, v6-fail-close 0&lt;BR /&gt; dns-guard, count 101342744&lt;BR /&gt; protocol-enforcement, drop 36883&lt;BR /&gt; nat-rewrite, count 0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Why i cant see id-randomization ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Do i need to apply the policy on interface ?&lt;BR /&gt;if yes how can i do that ?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 11:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/globally-vs-class-map-inspection/m-p/2888279#M155462</guid>
      <dc:creator>bluesea2010</dc:creator>
      <dc:date>2016-03-23T11:47:41Z</dc:date>
    </item>
  </channel>
</rss>

