<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 9.1 conn timeout for DNS? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103848#M392441</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you take out the DNS inspection and test it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Jan 2013 03:17:49 GMT</pubDate>
    <dc:creator>Julio Carvajal</dc:creator>
    <dc:date>2013-01-22T03:17:49Z</dc:date>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103841#M392434</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently had a firewall that wasn't passing traffic (ASA 5510 running software version 9.1).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It turned out it had 130000 active connections.&amp;nbsp; Doing a "clear conn port 53" dropped the active connection count back to 38k, and the firewall started passing traffic again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A lot of the connections looked like this:&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;﻿&lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55639, idle 112:33:59, bytes 419, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55638, idle 112:34:00, bytes 419, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55603, idle 112:34:30, bytes 129, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55602, idle 112:34:30, bytes 227, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55600, idle 112:34:31, bytes 227, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55599, idle 112:34:31, bytes 227, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55597, idle 112:34:31, bytes 479, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55595, idle 112:34:31, bytes 128, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55594, idle 112:34:31, bytes 413, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55568, idle 112:34:44, bytes 227, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55567, idle 112:34:44, bytes 227, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55566, idle 112:34:44, bytes 413, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55565, idle 112:34:44, bytes 413, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55564, idle 112:34:44, bytes 227, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55563, idle 112:34:44, bytes 227, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55562, idle 112:34:44, bytes 479, flags - &lt;/P&gt;&lt;P&gt;UDP prod&amp;nbsp; x.x.x.x:53 dmz&amp;nbsp; y.y.y.y:55561, idle 112:34:44, bytes 479, flags - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config guide notes that the "timeout udp ..." command doesn't affect DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas on how to time out DNS connections?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Ken.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103841#M392434</guid>
      <dc:creator>aimken123</dc:creator>
      <dc:date>2019-03-12T00:50:19Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103842#M392435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ken,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I saw it once ( bug) , I am looking for the bug ID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround available was :&lt;/P&gt;&lt;P&gt;Please remove the DNS inspection and clear the local host table of the ASA....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this is the case&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 00:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103842#M392435</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-22T00:54:08Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103843#M392436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seeing these types of posts make me laugh &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One of the many features that Cisco claimed to be better than other firewall vendors is the "deep inspection" packets such as sqlnet, esmtp, DNS, etc...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen a lot of postings in this firewall forums that whenever someone has an issue with either sqlnet, esmtp, and in this case, DNS, the work around is almost always "disable inspection".&amp;nbsp; If you're going to disable "inspection" of the ASA, then what is the point of using the firewall in the first place?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 01:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103843#M392436</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-01-22T01:33:07Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103844#M392437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No need to be&amp;nbsp; sarcastic...... Try to provide something useful to the discussion so we can help each other. In this case we are mentioning a software bug and as I said is a ****Work-around**** Not a solution.. If this is the same Bug I remember we are still working on the fix code,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are&amp;nbsp; here to help not to criticize.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 01:42:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103844#M392437</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-22T01:42:42Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103845#M392438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am trying to be funny, guess that did not work &lt;SPAN __jive_emoticon_name="silly" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On a serious note, let say if this is an Internet facing firewall and I run into this issue.&amp;nbsp; As a "work-around", I have to "disable DNS inspection" on my Internet facing firewall to get things working again.&amp;nbsp; By disabling dns inspection on my Internet firewall, isn't that a security risk?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 01:50:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103845#M392438</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-01-22T01:50:38Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103846#M392439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Luckily, this particular firewall is only in a sandpit environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been doing a bit more looking though, and it seems the remaining 38k connections are mostly a mix of udp 161 (SNMP) and udp 389 (AD LDAP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inspection for SNMP was never enabled, and there doesn't seem to be any inspection option for LDAP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;p.s.&amp;nbsp; It looks like I won't be rolling this version into production...&lt;/P&gt;&lt;P&gt; &lt;IMG ___jive_emoticon_name="sad" jivemacro="emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt;&lt;IMG ___jive_emoticon_name="sad" jivemacro="emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 02:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103846#M392439</guid>
      <dc:creator>aimken123</dc:creator>
      <dc:date>2013-01-22T02:26:52Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103847#M392440</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry if I was a little serious &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;of course it is a&amp;nbsp; security risk, but we are trying to solve this, let;s try to get to the root cause of the issue and then move from there&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 03:17:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103847#M392440</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-22T03:17:29Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103848#M392441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you take out the DNS inspection and test it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 03:17:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103848#M392441</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-22T03:17:49Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103849#M392442</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS inspection has been removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The DNS connections still aren't timing out though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 03:39:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103849#M392442</guid>
      <dc:creator>aimken123</dc:creator>
      <dc:date>2013-01-22T03:39:30Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103850#M392443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the update, so it is definetly something new and interesting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me see what I can investigate on this&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jan 2013 05:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103850#M392443</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-22T05:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103851#M392444</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you by any chance applying connection limits/timeouts via a policy-map? I noted unexpected behaviour with this and DNS timeouts just today. ASA 5540 active/active 9.1.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2013 21:09:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103851#M392444</guid>
      <dc:creator>farrell.da</dc:creator>
      <dc:date>2013-01-23T21:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103852#M392445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had 'match any' and the timeouts I _thought_ were TCP specific (30 min idle timeout) also applied to UDP. Result - thousands of idle DNS, SNMP etc. state entries.&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2013 21:12:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103852#M392445</guid>
      <dc:creator>farrell.da</dc:creator>
      <dc:date>2013-01-23T21:12:55Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103853#M392446</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;David, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of my policy maps set connection limits or timeouts (they're all for inspection).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On another note, I've since cleared all the connections, and none of the new ones seem to be exceeding the timeout values.&amp;nbsp; Seems like I can't replicate my original problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2013 23:55:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103853#M392446</guid>
      <dc:creator>aimken123</dc:creator>
      <dc:date>2013-01-23T23:55:14Z</dc:date>
    </item>
    <item>
      <title>ASA 9.1 conn timeout for DNS?</title>
      <link>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103854#M392447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ken,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way you could provide your configuration or send it on a private message so I can doble check it,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2013 23:59:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-9-1-conn-timeout-for-dns/m-p/2103854#M392447</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-01-23T23:59:53Z</dc:date>
    </item>
  </channel>
</rss>

