<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS reply filtering in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306169#M345143</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS server sits on the other side of the firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client -&amp;gt; firewall -&amp;gt; DNS server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 06 Aug 2013 09:33:32 GMT</pubDate>
    <dc:creator>arunas.usonis</dc:creator>
    <dc:date>2013-08-06T09:33:32Z</dc:date>
    <item>
      <title>DNS reply filtering</title>
      <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306168#M345142</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am trying to make DNS filtering work as URL filtering cannot permit https traffic.&lt;/P&gt;&lt;P&gt;Config is as per below. The thing is that it blocks every url at the moment instead of just test&amp;nbsp; - gmail.com as per regex&lt;/P&gt;&lt;P&gt;It looks simple on the paper but cannot make it work (&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regex test "gmail\.com"&lt;/P&gt;&lt;P&gt;access-list http-user-vlan414-acl extended permit object-group http-inspect-ports 10.4.14.0 255.255.255.0 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type regex match-any DomainBlockList&lt;BR /&gt; description blocked domains&lt;BR /&gt; match regex test&lt;BR /&gt; !&lt;/P&gt;&lt;P&gt;class-map http-user-vlan414-class&lt;/P&gt;&lt;P&gt; match access-list http-user-vlan414-acl&lt;/P&gt;&lt;P&gt;!&lt;BR /&gt; policy-map type inspect dns vlan414-policy&lt;BR /&gt; parameters&lt;BR /&gt; message-length maximum 512&lt;BR /&gt; match domain-name regex class DomainBlockList&lt;BR /&gt; drop-connection log&lt;BR /&gt; !&lt;BR /&gt; policy-map http-main-policy-vlan414&lt;BR /&gt; class http-user-vlan414-class&lt;BR /&gt; inspect dns vlan414-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy http-main-policy-vlan414 interface vlan414&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:21:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306168#M345142</guid>
      <dc:creator>arunas.usonis</dc:creator>
      <dc:date>2019-03-12T02:21:55Z</dc:date>
    </item>
    <item>
      <title>DNS reply filtering</title>
      <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306169#M345143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS server sits on the other side of the firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client -&amp;gt; firewall -&amp;gt; DNS server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 09:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306169#M345143</guid>
      <dc:creator>arunas.usonis</dc:creator>
      <dc:date>2013-08-06T09:33:32Z</dc:date>
    </item>
    <item>
      <title>DNS reply filtering</title>
      <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306170#M345148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;if to rework it into :&lt;/P&gt;&lt;P&gt;policy-map http-main-policy-vlan414&lt;BR /&gt; class inspection_default&amp;nbsp;&amp;nbsp; -&amp;nbsp; have replaced with default class, then it starts somehow to work, still not perfect&lt;BR /&gt; inspect dns vlan414-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so am not sure why it doesn't like the class with ACL , maybe somehow related to inspect dns that you have under default..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 11:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306170#M345148</guid>
      <dc:creator>arunas.usonis</dc:creator>
      <dc:date>2013-08-06T11:18:48Z</dc:date>
    </item>
    <item>
      <title>DNS reply filtering</title>
      <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306171#M345150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;have sorted it myself, seems documentation is misleading a bit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 17:07:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306171#M345150</guid>
      <dc:creator>arunas.usonis</dc:creator>
      <dc:date>2013-08-06T17:07:13Z</dc:date>
    </item>
    <item>
      <title>DNS reply filtering</title>
      <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306172#M345151</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Arunas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was about to ask for some outputs &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad to know you have it up and running, can you share the solution and mark the question as answered so future users can learn from your experience.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Aug 2013 21:00:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306172#M345151</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-06T21:00:29Z</dc:date>
    </item>
    <item>
      <title>DNS reply filtering</title>
      <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306173#M345152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Working example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regex domainlist&amp;nbsp; "example\.com"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type regex match-any vlan414-url-whitelist&lt;/P&gt;&lt;P&gt;description allowed domains&lt;/P&gt;&lt;P&gt;match regex domainlist&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect dns vlan414-policy&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;match not domain-name regex class vlan414-url-whitelist&lt;/P&gt;&lt;P&gt;&amp;nbsp; drop-connection log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map http-main-policy-vlan414&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns vlan414-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy http-main-policy-vlan414 interface vlan414&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Aug 2013 08:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306173#M345152</guid>
      <dc:creator>arunas.usonis</dc:creator>
      <dc:date>2013-08-07T08:58:10Z</dc:date>
    </item>
    <item>
      <title>DNS reply filtering</title>
      <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306174#M345154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Though what I cannot make work - is to use ACL to define which machines are allowed to open url ?&lt;/P&gt;&lt;P&gt;Have tried following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map http-user-vlan414-class&lt;/P&gt;&lt;P&gt; match any - have played with any and ACL, still no luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map http-main-policy-vlan414&lt;/P&gt;&lt;P&gt; class http-user-vlan414-class -&amp;gt; &lt;SPAN style="text-decoration: underline;"&gt;so here basically substituting class inspection_default with http-user-vlan414-class&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns vlan414-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if am applying differetn class under policy-map my traffic stops immediately&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help welcome)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Aug 2013 12:30:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306174#M345154</guid>
      <dc:creator>arunas.usonis</dc:creator>
      <dc:date>2013-08-07T12:30:04Z</dc:date>
    </item>
    <item>
      <title>DNS reply filtering</title>
      <link>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306175#M345156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Arunas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So If u set:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;class-map http-user-vlan414-class&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;match any - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;policy-map http-main-policy-vlan414&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;class http-user-vlan414-class&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp; inspect dns vlan414-policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Okey but have you applied to a service-policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean traffic drops?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check my blog at http:laguiadelnetworking.com for further information. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Aug 2013 16:33:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-reply-filtering/m-p/2306175#M345156</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-08-07T16:33:09Z</dc:date>
    </item>
  </channel>
</rss>

