<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External DNS query issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669115#M536874</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Anu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently dont have syslogs setup at the moment. This environment is fairly new and hasn't really been implemented as well as one would hope. But here is the service policy and policy mappings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh service-policy"&lt;/P&gt;&lt;P&gt;Global policy: &lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns maximum-length 512, packet 985870, drop 27855, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 356, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rtsp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: esmtp, packet 16421670, drop 0, reset-drop 197&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 21, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip, packet 146, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 2729, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Result of the command: "sh run policy-map"&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns maximum-length 512 &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Sherwin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 01 Jul 2011 01:58:19 GMT</pubDate>
    <dc:creator>sherwin79</dc:creator>
    <dc:date>2011-07-01T01:58:19Z</dc:date>
    <item>
      <title>External DNS query issues</title>
      <link>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669113#M536870</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Apologies if I'm in the wrong area but this if my first post. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I'm currently having issues where external DNS is going through to our secondary DNS server in our Production environment but not being returned to the client. Below is how our network was configured by another staff member and all I'm trying to do is enable the DNS queries from an external source. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(ISP Modem)--------(Cisco ASA 5520)--------(Cisco 2921)--------------(DNS Server)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the ASA I have enable the following rules.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list OUTSIDE_access_in extended permit tcp any x.x.x.x 255.255.255.240 eq https &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any x.x.x.x 255.255.255.240 eq smtp &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit gre host x.x.x.x x.x.x.x 255.255.255.240 &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit udp any host x.x.x.x eq domain&lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any host x.x.x.x eq domain&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list INSIDE_access_in extended permit udp host x.x.x.x eq domain any &lt;/P&gt;&lt;P&gt;access-list INSIDE_access_in extended permit tcp host x.x.x.x eq domain any &lt;/P&gt;&lt;P&gt;access-list INSIDE_access_in extended permit tcp x.x.x.x 255.255.255.240 any eq www &lt;/P&gt;&lt;P&gt;access-list INSIDE_access_in extended permit tcp x.x.x.x 255.255.255.240 any eq smtp &lt;/P&gt;&lt;P&gt;access-list INSIDE_access_in extended permit tcp x.x.x.x 255.255.255.240 any eq https &lt;/P&gt;&lt;P&gt;access-list INSIDE_access_in extended permit udp x.x.x.x 255.255.255.240 any eq domain &lt;/P&gt;&lt;P&gt;access-list INSIDE_access_in extended permit tcp x.x.x.x 255.255.255.240 any eq domain &lt;/P&gt;&lt;P&gt;access-list INSIDE_access_in extended permit tcp x.x.x.x 255.255.255.240 any eq pptp &lt;/P&gt;&lt;P&gt;access-list INSIDE_access_in extended permit gre x.x.x.x 255.255.255.240 any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the router:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ip nat inside source static tcp 10.0.2.201 25 x.x.x.x 25 extendable&lt;BR /&gt;ip nat inside source static tcp 10.0.2.16 443 x.x.x.x 443 extendable&lt;BR /&gt;ip nat inside source static tcp 10.0.2.201 25 x.x.x.x 25 extendable&lt;BR /&gt;ip nat inside source static tcp 10.0.2.201 443 x.x.x.x 443 extendable&lt;BR /&gt;ip nat inside source static tcp 10.0.2.17 443 x.x.x.x 443 extendable&lt;BR /&gt;ip nat inside source static tcp 10.0.2.20 443 x.x.x.x 443 extendable&lt;BR /&gt;ip nat inside source static tcp 10.0.2.4 53 x.x.x.x 53 extendable&lt;BR /&gt;ip nat inside source static udp 10.0.2.4 53 x.x.x.x 53 extendable&lt;BR /&gt;ip nat inside source static tcp 10.0.2.100 443 x.x.x.168 443 extendable&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So I've enable the rule on the ASA to permit dns from any sources to our published external ip address of the dns server. I've also configure a static nat on the router. Looking at the ASA monitoring tool I can see the ASA builds and then quickly tears down the connection. I can telnet all the way through to the server however when I attemp to perform a nslookup using the external ip address of the dns server it times out and fails. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Not sure where I'm going wrong but any help would be appreciated, thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Sherwin79&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669113#M536870</guid>
      <dc:creator>sherwin79</dc:creator>
      <dc:date>2019-03-11T20:53:15Z</dc:date>
    </item>
    <item>
      <title>External DNS query issues</title>
      <link>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669114#M536871</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sherwin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have inspect dns enabled on the ASA? Could you post the output of "sh service-policy" and "sh run policy-map here"? Also, please post the syslogs from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Jun 2011 08:27:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669114#M536871</guid>
      <dc:creator>Anu M Chacko</dc:creator>
      <dc:date>2011-06-30T08:27:43Z</dc:date>
    </item>
    <item>
      <title>External DNS query issues</title>
      <link>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669115#M536874</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Anu,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently dont have syslogs setup at the moment. This environment is fairly new and hasn't really been implemented as well as one would hope. But here is the service policy and policy mappings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Result of the command: "sh service-policy"&lt;/P&gt;&lt;P&gt;Global policy: &lt;BR /&gt;&amp;nbsp; Service-policy: global_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns maximum-length 512, packet 985870, drop 27855, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: ftp, packet 356, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 h225, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: h323 ras, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rsh, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: rtsp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: esmtp, packet 16421670, drop 0, reset-drop 197&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sqlnet, packet 21, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: skinny, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sunrpc, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: xdmcp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: sip, packet 146, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: netbios, packet 2729, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: tftp, packet 0, drop 0, reset-drop 0&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Result of the command: "sh run policy-map"&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect dns maximum-length 512 &lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect sqlnet &lt;BR /&gt;&amp;nbsp; inspect skinny &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect sip &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Sherwin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 01:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669115#M536874</guid>
      <dc:creator>sherwin79</dc:creator>
      <dc:date>2011-07-01T01:58:19Z</dc:date>
    </item>
    <item>
      <title>External DNS query issues</title>
      <link>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669116#M536875</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you disable inspect dns and test?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt; class inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp; no inspect dns maximum-length 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Anu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jul 2011 07:41:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/external-dns-query-issues/m-p/1669116#M536875</guid>
      <dc:creator>Anu M Chacko</dc:creator>
      <dc:date>2011-07-01T07:41:01Z</dc:date>
    </item>
  </channel>
</rss>

