<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dns question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-question/m-p/1598792#M595635</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the corresponding dns reply should return. It will return the corresponding NAT address according to the static NAT statement that is configured with DNS doctoring.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 31 Dec 2010 12:28:32 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-12-31T12:28:32Z</dc:date>
    <item>
      <title>dns question</title>
      <link>https://community.cisco.com/t5/network-security/dns-question/m-p/1598791#M595633</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i was goin through dns doctorig example in the cisco site and was going through packet captures of same . as dns request is udp , is it true that its corresp. dns reply will also come back . As it is UDP packet which is not reliable like TCP , is reply a new session initiated from the destionation ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-question/m-p/1598791#M595633</guid>
      <dc:creator>techkamleshs</dc:creator>
      <dc:date>2019-03-11T19:29:15Z</dc:date>
    </item>
    <item>
      <title>Re: dns question</title>
      <link>https://community.cisco.com/t5/network-security/dns-question/m-p/1598792#M595635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the corresponding dns reply should return. It will return the corresponding NAT address according to the static NAT statement that is configured with DNS doctoring.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 12:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-question/m-p/1598792#M595635</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-12-31T12:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: dns question</title>
      <link>https://community.cisco.com/t5/network-security/dns-question/m-p/1598793#M595637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns doctorig example was just reference , my ques is more related to networking as dns request is udp i believe it will just deliver the packet to destn , but seeing this eg. as corresp. dns reply is also coming back .i wanted to understnad if reply is a new session initiated from the destination towards source (As it is UDP packet which is not reliable like TCP )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 12:45:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-question/m-p/1598793#M595637</guid>
      <dc:creator>techkamleshs</dc:creator>
      <dc:date>2010-12-31T12:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: dns question</title>
      <link>https://community.cisco.com/t5/network-security/dns-question/m-p/1598794#M595639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you are right. UDP is connectionless, and ASA will actually match the ID of the DNS request and reply and makes sure that it matches.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"inspect dns" is required to make sure that it is a legitemate DNS reply that matches the DNS request on the ASA connection table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is more information on dns in specific on ASA for your reference:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1719130"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1719130&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, for other UDP packet, you are absolutely right.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 13:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-question/m-p/1598794#M595639</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-12-31T13:25:06Z</dc:date>
    </item>
    <item>
      <title>Re: dns question</title>
      <link>https://community.cisco.com/t5/network-security/dns-question/m-p/1598795#M595640</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks ! and matching the ID of the DNS request with reply is done by DNS guard. right ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 14:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-question/m-p/1598795#M595640</guid>
      <dc:creator>techkamleshs</dc:creator>
      <dc:date>2010-12-31T14:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: dns question</title>
      <link>https://community.cisco.com/t5/network-security/dns-question/m-p/1598796#M595641</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kamlesh,&lt;/P&gt;&lt;P&gt;dns guard - ensures one response per request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can read here: &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/d2.html#wp1951632"&gt;http://www.cisco.com/en/US/docs/security/asa/asa82/command/reference/d2.html#wp1951632&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 31 Dec 2010 14:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-question/m-p/1598796#M595641</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-12-31T14:30:46Z</dc:date>
    </item>
  </channel>
</rss>

