<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS response traffic getting dropped in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113994#M394982</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why are&amp;nbsp; you telling him in increase the dns length to 1024?&amp;nbsp; When he turns OFF dns inpsect (aka no fixup protol 53 dns), should that turns off inspecting DNS altogether?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Nov 2012 12:51:14 GMT</pubDate>
    <dc:creator>david.tran</dc:creator>
    <dc:date>2012-11-29T12:51:14Z</dc:date>
    <item>
      <title>DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113991#M394979</link>
      <description>&lt;P&gt;We have a FWSM running 3.2 IOS in a cat 6509&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Clients and server conducting queries against MS 2003 AD servers running DNS are having problems, and in the syslog I see messages like&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny inbound UDP from 172.25.59.106/53 to 172.25.55.11/56465 due to DNS Response&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;UDP 53 is allowed from the subnets into the subnets/vlans where the DNS servers reside, and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;has been enabled (the vlans have the same security level).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have also attempted to turn off DNS inspection in the global policy (no inspect dns)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nevertheless, these errors persist. Anyone have any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:29:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113991#M394979</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2019-03-12T00:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113992#M394980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please add&lt;BR /&gt;inspect dns maximum-length 1024&lt;BR /&gt;&lt;BR /&gt;To your configuration. If you read the DNS RFC as with TFTP the packets should not exceed 512 bytes.&lt;BR /&gt;As such the FWSM/ASA has a default DNS size of 512 bytes&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;BR /&gt;&lt;BR /&gt;Ju&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2012 21:56:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113992#M394980</guid>
      <dc:creator>ju_mobile</dc:creator>
      <dc:date>2012-11-28T21:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113993#M394981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the DNS servers being used by your local area network clients?&lt;/P&gt;&lt;P&gt;How many are there?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 01:31:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113993#M394981</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-29T01:31:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113994#M394982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why are&amp;nbsp; you telling him in increase the dns length to 1024?&amp;nbsp; When he turns OFF dns inpsect (aka no fixup protol 53 dns), should that turns off inspecting DNS altogether?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 12:51:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113994#M394982</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-11-29T12:51:14Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113995#M394983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The RFC states and Cisco obliges that DNS responses should be less than 512Bytes. The Firewall will drop any DNS response over 512bytes, unles sthe size is increased. The changes to DNS for DNSSEC means that the 512byte limit is often exceeded.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/web/about/security/intelligence/dnssec.html"&gt;http://www.cisco.com/web/about/security/intelligence/dnssec.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously, turning inspect off would negate the need for this command. Based on me missing that part of his post altogether. In which case its probably worth disabling DNS-GUARD..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ju&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 13:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113995#M394983</guid>
      <dc:creator>ju_mobile</dc:creator>
      <dc:date>2012-11-29T13:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113996#M394984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't work with ASA on daily basis (checkpoint is what I am doing these days);&amp;nbsp; however, I thought can disable dns-guard if you have inspect DNS enable.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My understand of this is that once you turn OFF inspect DNS, dns-guard is also disabled as well because dns-guard is a subset of inspect DNS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 13:13:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113996#M394984</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-11-29T13:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113997#M394985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As i'm sure your aware, I believe there are some variations between the ASA/PIX/FWSM. As i understand it teh question raised was in reference to teh FWSM 3.2 which has its own features or whatever semantics you wish to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/web/about/security/intelligence/dns-bcp.html"&gt;http://www.cisco.com/web/about/security/intelligence/dns-bcp.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;search for DNS-GUARD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ju (stuff is what I do these days)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 13:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113997#M394985</guid>
      <dc:creator>ju_mobile</dc:creator>
      <dc:date>2012-11-29T13:24:38Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113998#M394986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;jcarvaja:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have two DNS servers in the environment, both on the same subnet, which is a firewalled VLAN on the FWSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am seeing these DNS errors on reply traffic from those servers to other VLANs/subnets on the same FWSM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It appears as though this "dns guard" feature cannot be turned off yes?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 14:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113998#M394986</guid>
      <dc:creator>Colin Higgins</dc:creator>
      <dc:date>2012-11-29T14:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113999#M394987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS-Guard can be disabled. On the ASDM go to device management, advanced, DNS and from in that location untick the DnS-guard box&lt;BR /&gt;&lt;BR /&gt;Best Regards&lt;BR /&gt;&lt;BR /&gt;Ju&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 14:20:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2113999#M394987</guid>
      <dc:creator>ju_mobile</dc:creator>
      <dc:date>2012-11-29T14:20:17Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2114000#M394988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that's goes back to my original thought.&amp;nbsp; Once you disable inspecting DNS "no fixup protocol 53 dns", shouldn't that turn OFF dns-guard as well?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 15:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2114000#M394988</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2012-11-29T15:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2114001#M394990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes,&lt;BR /&gt;&lt;BR /&gt;But not on a FWSM running a 3.2 code.&lt;BR /&gt;&lt;BR /&gt;Regards&lt;BR /&gt;&lt;BR /&gt;Ju&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2114001#M394990</guid>
      <dc:creator>ju_mobile</dc:creator>
      <dc:date>2012-11-29T16:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response traffic getting dropped</title>
      <link>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2114002#M394993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Colin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Exactly, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is because of the DNS guard feature.. One of your local DNS servers is replying later than the other DNS so as the ASA already received a DNS reply from one DNS server the other one will be dropped. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this message can be safely ignored &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you do understand what I mean &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2012 16:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response-traffic-getting-dropped/m-p/2114002#M394993</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-11-29T16:49:15Z</dc:date>
    </item>
  </channel>
</rss>

