<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic  Hi Vibhor,How can i check if in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708697#M191870</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Vibhor,&lt;/P&gt;&lt;P&gt;How can i check if i am using ASA for DNS functionality?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
    <pubDate>Wed, 06 May 2015 15:17:49 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2015-05-06T15:17:49Z</dc:date>
    <item>
      <title>Cisco ASA DNS Memory Exhaustion Vulnerability</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708695#M191868</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi Everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;As &amp;nbsp;per Cisco our ASA has this vulnerability.&lt;/P&gt;
&lt;P&gt;Workaround is&lt;/P&gt;
&lt;P&gt;For the Cisco ASA DNS Memory Exhaustion Vulnerability, reducing the retries setting to 0 under the DNS server-group provides a workaround for this issue.&lt;BR /&gt;The following example shows how to set the retries setting to 0 for the default DNS server-group (&lt;EM&gt;DefaultDNS&lt;/EM&gt;)&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;PRE&gt;
ciscoasa(config-dns-server-group)# DNS server-group DefaultDNS
ciscoasa(config-dns-server-group)# retries 0 &lt;/PRE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Need to confirm if i config the command retries 0 will it cause any DNS outage for the users?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:53:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708695#M191868</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T05:53:42Z</dc:date>
    </item>
    <item>
      <title>Hi,This value defines the</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708696#M191869</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This value defines the number of times to retry the list of DNS servers when the ASA does not receive a response. Are you using the ASA DNS functionality ? It is mostly used in case of VPN or FQDN objects etc&lt;/P&gt;&lt;P&gt;This will not affect any issues for the users as they are not going to be querying the ASA for the DNS requests.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2015 15:14:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708696#M191869</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-06T15:14:31Z</dc:date>
    </item>
    <item>
      <title> Hi Vibhor,How can i check if</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708697#M191870</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Vibhor,&lt;/P&gt;&lt;P&gt;How can i check if i am using ASA for DNS functionality?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2015 15:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708697#M191870</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-05-06T15:17:49Z</dc:date>
    </item>
    <item>
      <title>Hi,Check this for reference</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708698#M191871</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Check this for reference and verify if you are using any of the features that are using the DNS servers. Also , if you change this setting , this will not affect any of these features as long as the DNS server is responding.&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa90/configuration/guide/asa_90_cli_config/basic_hostname_pw.html#pgfId-1080248&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2015 15:34:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708698#M191871</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-06T15:34:40Z</dc:date>
    </item>
    <item>
      <title> Many thanks Vibhor</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708699#M191872</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks Vibhor.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2015 16:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-dns-memory-exhaustion-vulnerability/m-p/2708699#M191872</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2015-05-06T16:15:56Z</dc:date>
    </item>
  </channel>
</rss>

