<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA dropping UDP/53 traffic on inside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001239#M401765</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there other clients with that problem? Have you doublechecked the DHCP-Scope?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 23 Jul 2012 07:58:45 GMT</pubDate>
    <dc:creator>Karsten Iwen</dc:creator>
    <dc:date>2012-07-23T07:58:45Z</dc:date>
    <item>
      <title>ASA dropping UDP/53 traffic on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001236#M401762</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've spent the better part of a week trying to pound this out.&lt;/P&gt;&lt;P&gt;We have a Cisco ASA 5505 (v7.2(3)) with a "fairly" normal configuration yet we have a problem where it appears UDP/53 traffic is denied on our inside network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is output from our sys log:&lt;/P&gt;&lt;P&gt;SyslogID&amp;nbsp;&amp;nbsp; Source IP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dest IP&amp;nbsp;&amp;nbsp;&amp;nbsp; Description&lt;/P&gt;&lt;P&gt;305006&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.18.22.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; portmap translation creation failed for udp src inside:172.18.22.156/42013 dst inside:172.18.22.3/53&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To give some clarification:&lt;/P&gt;&lt;P&gt;172.18.22.3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; is one of our DNS servers&lt;/P&gt;&lt;P&gt;172.18.22.156&amp;nbsp; is a device we're experimenting with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've bypassed the Cisco by using a 4G wireless router with this same device - and it works flawlessly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a [scrubbed] copy of our config. It is what I inherited from the previous admin - I'm not sure of all its finer points (I'm not Cisco certified -- perhaps I'm just certifiable.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-knme&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 7.2(3) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hostname [redacted]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;domain-name [redacted]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password [redacted] encrypted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ip address 172.18.22.6 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Vlan2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nameif outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ip address 999.999.999.999 255.255.255.248 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; switchport access vlan 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;passwd [redacted] encrypted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ftp mode passive&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clock timezone EST -5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;clock summer-time EDT recurring&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns domain-lookup outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; name-server 198.6.1.142&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; name-server 198.6.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; domain-name ocm.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit inter-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same-security-traffic permit intra-interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_nat0_outbound extended permit ip any 172.18.22.64 255.255.255.240 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark inbound icmp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any echo &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in remark inbound icmp-echo-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in extended permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any eq domain any eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit udp any eq domain any eq domain &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit tcp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit udp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit icmp any any echo &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit icmp any any traceroute &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging asdm informational&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool ABC 172.18.22.70-172.18.22.74 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-523.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat-control&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 101 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list inside_nat0_outbound&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 101 172.18.22.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group outside_access_in in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 65.215.53.161 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server OCM protocol nt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server OCM host 172.18.22.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; nt-auth-domain-controller Fileserv&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http 172.18.22.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-3DES-SHA esp-3des esp-sha-hmac &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set pfs &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto dynamic-map outside_dyn_map 20 set transform-set ESP-3DES-SHA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map 65535 ipsec-isakmp dynamic outside_dyn_map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp enable outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp policy 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; authentication pre-share&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; encryption 3des&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; hash sha&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; group 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; lifetime 86400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 172.18.22.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd auto_config outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; parameters&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; message-length maximum 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect dns preset_dns_map &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 h225 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect h323 ras &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rsh &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect rtsp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect esmtp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sqlnet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect skinny &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sunrpc &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect xdmcp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect sip &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect netbios &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect pptp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect http &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect icmp error &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inspect ipsec-pass-thru &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ntp server 64.90.182.55 source outside prefer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy ABC internal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group-policy ABC attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; dns-server value 172.18.22.2 172.18.22.3&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; vpn-tunnel-protocol IPSec &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; default-domain value ABC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;username admin password [redacted] encrypted privilege 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group ABC type ipsec-ra&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group ABC general-attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; address-pool ABC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; authentication-server-group ABC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; default-group-policy ABC&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group ABC ipsec-attributes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; pre-shared-key *&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;prompt hostname context &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cryptochecksum:5d3c117cfd8e54a4ba032de9330c51f9&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-523.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no asdm history enable&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:33:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001236#M401762</guid>
      <dc:creator>kenneth.eisner</dc:creator>
      <dc:date>2019-03-11T23:33:26Z</dc:date>
    </item>
    <item>
      <title>ASA dropping UDP/53 traffic on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001237#M401763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Without looking at your config: You need to find out why your client .156 sends the packets to the ASA when he wants to reach your internal DNS. As they are both in the same subnet, the ASA shouldn't see that traffic. Start your troubleshooting at the IP-config and routing-config of the client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 21:49:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001237#M401763</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-07-22T21:49:03Z</dc:date>
    </item>
    <item>
      <title>ASA dropping UDP/53 traffic on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001238#M401764</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Karsten,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for a very prompt response. I do apreciate it.&lt;/P&gt;&lt;P&gt;Sadly I do not have access to the IP-config nor routing-config of the client. They're "black box units". They obtain IP address from our DHCP server - that is pretty much all I know about them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-knme&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 22:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001238#M401764</guid>
      <dc:creator>kenneth.eisner</dc:creator>
      <dc:date>2012-07-22T22:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA dropping UDP/53 traffic on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001239#M401765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there other clients with that problem? Have you doublechecked the DHCP-Scope?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2012 07:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001239#M401765</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-07-23T07:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: ASA dropping UDP/53 traffic on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001240#M401766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again Karsten,&lt;/P&gt;&lt;P&gt;No - no other users.&lt;/P&gt;&lt;P&gt;Did discover that when pinging the device the reply is being rejected by the firewall. All are in agreement that this sort of traffic should not be seen at the firewall level so we're really not sure what is going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Almost seems like the subnet of the device does not match the subnet of the rest of the network but it is nearly impossible to check b/c the device is not capable.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-knme&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 01:11:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001240#M401766</guid>
      <dc:creator>kenneth.eisner</dc:creator>
      <dc:date>2012-07-24T01:11:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA dropping UDP/53 traffic on inside interface</title>
      <link>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001241#M401767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are the other clients getting their IP-config also from the same DHCP-server? You can capture the packets that are directly leaving the problematic PC. If the destination-L2-address is the ASA, then the problem is in the client-config.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 06:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dropping-udp-53-traffic-on-inside-interface/m-p/2001241#M401767</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2012-07-24T06:55:00Z</dc:date>
    </item>
  </channel>
</rss>

