<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX 515 started blocking udp 53 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284287#M565589</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No windows servers - good thought though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have "fixup protocol dns maximum-length 512" specified though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 26 May 2004 01:30:59 GMT</pubDate>
    <dc:creator>waifurchin</dc:creator>
    <dc:date>2004-05-26T01:30:59Z</dc:date>
    <item>
      <title>PIX 515 started blocking udp 53</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284284#M565586</link>
      <description>&lt;P&gt;This really shouldn't be giving me this much trouble...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This morning I started seeing hundreds of the following log entry (destination port number differs, but the rest is the same):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deny udp src outside:ns1_isp/53 dst inside:pix_ext/xxxxx by access-group "out"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ns1_isp is the dns server from our ISP.  I assume that these are replies to dns requests.  Why are they being blocked?  Suddenly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The access-list the log entry refers to is listed below, please help because I can't see anything that would cause this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list out permit udp any host ns2_ext eq domain &lt;/P&gt;&lt;P&gt;access-list out permit udp any host ns1_ext eq domain &lt;/P&gt;&lt;P&gt;access-list out permit tcp any host ns1_ext eq smtp &lt;/P&gt;&lt;P&gt;access-list out permit tcp any host ns1_ext eq imap4 &lt;/P&gt;&lt;P&gt;access-list out permit tcp any host ns1_ext eq www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group out in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ns1 &amp;amp; ns2 refer to an internal mail/dns server we are testing on the dmz.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284284#M565586</guid>
      <dc:creator>waifurchin</dc:creator>
      <dc:date>2020-02-21T07:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 started blocking udp 53</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284285#M565587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are they Windows 2003 servers by any chance?  If so, it might be something to do with &lt;A class="jive-link-custom" href="http://support.microsoft.com/default.aspx?scid=kb;en-us;828263&amp;amp;Product=winsvr2003" target="_blank"&gt;http://support.microsoft.com/default.aspx?scid=kb;en-us;828263&amp;amp;Product=winsvr2003&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If it is you should be able to fix this by altering the maximum length of DNS query responses using the "fixup protocol dns maximum-length" command, or disable EDNS probes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kev&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 May 2004 21:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284285#M565587</guid>
      <dc:creator>kagodfrey</dc:creator>
      <dc:date>2004-05-25T21:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 started blocking udp 53</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284286#M565588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you post the static, nat, and global commands?  The pix runs dns guard to prevent an answer from more than one dns server from coming back as a response to a request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you notice the log entries as soon as you were testing the internal mail and dns on the DMZ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 May 2004 01:05:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284286#M565588</guid>
      <dc:creator>ehirsel</dc:creator>
      <dc:date>2004-05-26T01:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 started blocking udp 53</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284287#M565589</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No windows servers - good thought though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do have "fixup protocol dns maximum-length 512" specified though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 May 2004 01:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284287#M565589</guid>
      <dc:creator>waifurchin</dc:creator>
      <dc:date>2004-05-26T01:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 started blocking udp 53</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284288#M565590</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list dmz&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (dmz,outside) ns1_ext ns1_dmz netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (dmz,outside) ns2_ext ns2_dmz netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-group out in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 router 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 May 2004 12:12:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284288#M565590</guid>
      <dc:creator>waifurchin</dc:creator>
      <dc:date>2004-05-26T12:12:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 started blocking udp 53</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284289#M565591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The fixup for DNS blocks responses larger than 512 bytes.  You either need to disable it or increase the length. A few DNS servers on the Internet, notably Yahoo, have too many servers in their responses and violate the RFC for max UDP DNS repsones.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 May 2004 13:53:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284289#M565591</guid>
      <dc:creator>shannong</dc:creator>
      <dc:date>2004-05-26T13:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 started blocking udp 53</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284290#M565592</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you still seeing the messages?  I am thinking that they could be the result of the isp dns server(s) acting/responding slowly causing the pix to close the udp session before the response is sent.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You mentioned that the isp has two dns servers - were both of them being listed in the log messages?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2004 14:23:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284290#M565592</guid>
      <dc:creator>ehirsel</dc:creator>
      <dc:date>2004-05-28T14:23:46Z</dc:date>
    </item>
    <item>
      <title>Re: PIX 515 started blocking udp 53</title>
      <link>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284291#M565593</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Everything seems to be back to normal.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your suggestion may have in fact been the case.  The issue started prior to my changing anything, and silently corrected itself as well which would seem to indicate the issue was not our equipment per say.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2004 15:30:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-515-started-blocking-udp-53/m-p/284291#M565593</guid>
      <dc:creator>waifurchin</dc:creator>
      <dc:date>2004-05-28T15:30:02Z</dc:date>
    </item>
  </channel>
</rss>

