<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS not functioning properly. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-not-functioning-properly/m-p/1997865#M401804</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Brendan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a small mistake with your config. You have an ACL like the below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended deny ip object-group SRV-DMZ-GROUP 172.20.20.0 255.255.254.0&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit object-group DM_INLINE_SERVICE_2 object-group SRV-DMZ-GROUP &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are denying the entire IP packet in the line 1. So it blocks all the traffic to go out. Also DNS uses UDP not the tcp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please have the premit rule in the 1st. Apply the below mentioned ACL.&lt;/P&gt;&lt;P&gt;ACL&lt;/P&gt;&lt;P&gt;=====&lt;/P&gt;&lt;P&gt;no access-list dmz_access_in&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit udp object-group SRV-DMZ-GROUP host 66.49.220.95 eq 53&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit udp object-group SRV-DMZ-GROUP host 67.55.0.11eq 53&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit&amp;nbsp; object-group SRV-DMZ-GROUP object-group DM_INLINE_SERVICE_2&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended deny ip object-group SRV-DMZ-GROUP 172.20.20.0 255.255.254.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have modified little as per the requirement. Your dns issue will get resolved with this acl's applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate if the given info helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Jul 2012 06:05:06 GMT</pubDate>
    <dc:creator>nkarthikeyan</dc:creator>
    <dc:date>2012-07-22T06:05:06Z</dc:date>
    <item>
      <title>DNS not functioning properly.</title>
      <link>https://community.cisco.com/t5/network-security/dns-not-functioning-properly/m-p/1997864#M401803</link>
      <description>&lt;P&gt;My DNS is giving me plenty of errors such as:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;Jul 21 2012&lt;/TD&gt;&lt;TD&gt;18:57:45&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;172.21.20.2&lt;/TD&gt;&lt;TD&gt;58390&lt;/TD&gt;&lt;TD&gt;66.49.220.95&lt;/TD&gt;&lt;TD&gt;53&lt;/TD&gt;&lt;TD&gt;Deny udp src dmz:172.21.20.2/58390 dst outside:66.49.220.95/53 by access-group "dmz_access_in" [0x0, 0x0]&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;4&lt;/TD&gt;&lt;TD&gt;Jul 21 2012&lt;/TD&gt;&lt;TD&gt;18:59:23&lt;/TD&gt;&lt;TD&gt;&lt;BR /&gt;&lt;/TD&gt;&lt;TD&gt;172.21.20.2&lt;/TD&gt;&lt;TD&gt;59567&lt;/TD&gt;&lt;TD&gt;67.55.0.11&lt;/TD&gt;&lt;TD&gt;53&lt;/TD&gt;&lt;TD&gt;Deny udp src dmz:172.21.20.2/59567 dst outside:67.55.0.11/53 by access-group "dmz_access_in" [0x0, 0x0]&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was wondering if anyone can suggest changes to make to fix this DNS issue.&amp;nbsp; My DNS servers are external to my network and are located at &lt;/P&gt;&lt;P&gt;66.49.220.95 and &lt;/P&gt;&lt;P&gt;67.55.0.11.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:33:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-not-functioning-properly/m-p/1997864#M401803</guid>
      <dc:creator>Brendan Wood</dc:creator>
      <dc:date>2019-03-11T23:33:08Z</dc:date>
    </item>
    <item>
      <title>DNS not functioning properly.</title>
      <link>https://community.cisco.com/t5/network-security/dns-not-functioning-properly/m-p/1997865#M401804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Brendan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a small mistake with your config. You have an ACL like the below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended deny ip object-group SRV-DMZ-GROUP 172.20.20.0 255.255.254.0&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit object-group DM_INLINE_SERVICE_2 object-group SRV-DMZ-GROUP &lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are denying the entire IP packet in the line 1. So it blocks all the traffic to go out. Also DNS uses UDP not the tcp.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please have the premit rule in the 1st. Apply the below mentioned ACL.&lt;/P&gt;&lt;P&gt;ACL&lt;/P&gt;&lt;P&gt;=====&lt;/P&gt;&lt;P&gt;no access-list dmz_access_in&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit udp object-group SRV-DMZ-GROUP host 66.49.220.95 eq 53&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit udp object-group SRV-DMZ-GROUP host 67.55.0.11eq 53&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit&amp;nbsp; object-group SRV-DMZ-GROUP object-group DM_INLINE_SERVICE_2&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended deny ip object-group SRV-DMZ-GROUP 172.20.20.0 255.255.254.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have modified little as per the requirement. Your dns issue will get resolved with this acl's applied.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please do rate if the given info helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Karthik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Jul 2012 06:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-not-functioning-properly/m-p/1997865#M401804</guid>
      <dc:creator>nkarthikeyan</dc:creator>
      <dc:date>2012-07-22T06:05:06Z</dc:date>
    </item>
  </channel>
</rss>

