<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cisco asa issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508879#M599320</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, the changes that you did should have not affect anything. The problem resided on your ISP's DNS. Like you said before if you change the dns to google dns everything worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now it would be a good practice to set the&amp;nbsp; DNS request lenght as auto, put the firewall in place and check the logs/service policy to see if you get packet drops over the inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any questions, please feel free to contact us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 03 Nov 2010 23:20:22 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2010-11-03T23:20:22Z</dc:date>
    <item>
      <title>cisco asa issues</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508874#M599315</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have just purchased a new&lt;/P&gt;&lt;P&gt;cisco ASA firewall. cisco ASA 5520 series ios ver 8.2&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;my earlier linux shorwall firewall was used in 2 interface mode&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;so i jus had a exact replica of the rules. and put the asa online&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Every thing was working but from outside world our internal public&lt;/P&gt;&lt;P&gt;websites could not be reached . also mail from yahoo or google bounce back&lt;/P&gt;&lt;P&gt;and also not able to send mail to yahoo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we do have our own dns server using bind 9 hosting a couple of websites&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i reverted back to my shorewall firewall and things were working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then i jus got the clue of message size for ASA .. that is the last server&lt;/P&gt;&lt;P&gt;which was rolled to dns sec and the message length has to be increased to&lt;/P&gt;&lt;P&gt;4096&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i did the following on my ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;jus to check i ran&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh run policy policy-map type inspect dns&lt;/P&gt;&lt;P&gt;and it showed me message length size maximun 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i did the change&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt; policy-map type inspect dns preset_dns_map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt;&amp;nbsp; parameters&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt;&amp;nbsp;&amp;nbsp; message-length maximum 4096&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt; policy-map global_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt;&amp;nbsp; class inspection_default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt;&amp;nbsp;&amp;nbsp; inspect dns preset_dns_map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then the show run policy-map was showing me message length maximum as&lt;/P&gt;&lt;P&gt;4096&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then i put my cisco firewall online and it was working. i mean i did send mail to&lt;/P&gt;&lt;P&gt;yahoo from my mail server and also replied it worked fine&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but after 30 minutes our network became very very slow as if crawling&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i removed the cisco asa network cables and reverted back to my shorewall&lt;/P&gt;&lt;P&gt;firewall and all was well immeditely&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then also one of user called me that the website was not working.&lt;/P&gt;&lt;P&gt;then i found that my immedite upstream ISP dns was not able to resolve the&lt;/P&gt;&lt;P&gt;sites which my dns server is authorative&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i tried to resolve from google public dns (8.8.8.8) and i could resolve it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;calling the isp dns admin he said he would check and after 4 hrs the isp&lt;/P&gt;&lt;P&gt;dns could resolve my website he told me that he had to update his dns&lt;/P&gt;&lt;P&gt;server and that i had changed the ip address of my web sites or my dns&lt;/P&gt;&lt;P&gt;server had a problem. which was neither&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now im jus wondering what exactly could be the problem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;since i dont want to put the cisco ASA online without being positive that&lt;/P&gt;&lt;P&gt;it gonna work smooth&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;( also i wondering&lt;/P&gt;&lt;P&gt;can this change in the asa firewall made some change in&lt;BR /&gt;my isp dns.&lt;/P&gt;&lt;P&gt;and if so what can i do to prevent this from happening again)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also after googleing i see that the change is not required&lt;/P&gt;&lt;P&gt;and some post say instead of jus haveing the message length maximum to 4096&lt;/P&gt;&lt;P&gt;i could have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;message-length maximum client auto&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now I am jus wondering how could i go about this&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;i would highy apprecite if someone could help me&lt;/P&gt;&lt;P&gt;also if some problem in my network i can go back to old&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;but if something changes in my isp dns its something very serious cause it&lt;/P&gt;&lt;P&gt;would take huge time. and they very slow in response&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 19:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508874#M599315</guid>
      <dc:creator>benedict dcunha</dc:creator>
      <dc:date>2019-03-11T19:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa issues</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508875#M599316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tough to guess what was happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Were you doing any dns doctoring on the ASA (translation rules with dns option)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 19:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508875#M599316</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-11-03T19:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa issues</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508876#M599317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt; &amp;amp; really apprecite your quick reply.&lt;/P&gt;&lt;P&gt;i dont think any dns translation is done im sure of it&lt;/P&gt;&lt;P&gt;it jus has standard rules ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) by the way can I how can i know or check&amp;nbsp; if any dns translation rules with dns option is done&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Just to be sure and want to know&amp;nbsp; can the&amp;nbsp; commands for incresing the message length to 4096 where there is allso command inspect dns&amp;nbsp; which i have added could have caused the network bog down and caused my ISP DNS not to resolve my websites. to tell you more the ISP has 4 dns 2 of the dns were resolving and 2 were not and only after repeated followup with the ISP admin ( after 8 hrs the other 2 dns were also OK ) and one of the dns was the primary dns of the isp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;wd apprecite your reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 19:35:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508876#M599317</guid>
      <dc:creator>benedict dcunha</dc:creator>
      <dc:date>2010-11-03T19:35:48Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa issues</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508877#M599318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Simon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was your DNS preset map for DNS inspection as auto at the very begining? You are right, if you are running version 8.2.2 or later, this problem should go away and the DNS respond will be allowed with the auto option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 19:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508877#M599318</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-11-03T19:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa issues</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508878#M599319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks once again guys. really apprecitye your super fast reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;actually when i fisrt ran the below command just to check the current message length&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show run policy-map inspect type dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it showed me that the message length was 512 bytes&lt;/P&gt;&lt;P&gt;i did not see any auto&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so i did update the message length with the below commands&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: 'Garamond','serif'; font-size: 12pt;"&gt;policy-map type inspect&amp;nbsp; dns preset_dns_map&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: 'Garamond','serif'; font-size: 12pt;"&gt;parameters&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: 'Garamond','serif'; font-size: 12pt;"&gt;message-length maximum&amp;nbsp; 4096&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: 'Garamond','serif'; font-size: 12pt;"&gt;policy-map&amp;nbsp; global_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: 'Garamond','serif'; font-size: 12pt;"&gt;class&amp;nbsp; inspection_default&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-family: 'Garamond','serif'; font-size: 12pt;"&gt;inspect dns&amp;nbsp; preset_dns_map&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;and after doin this i put the firewall online and things worked fine but after 30 to 45 min or somy network bogged down commpletely .&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;&lt;BR /&gt;i tried to find out the problem bu no luck so i reverted back to my linux shorewall firewall and the network was jus as normal as b4&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;and then i did get compalints from our users tht our websites were not accesable.&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;i tried to do a dns lookup through google's public dns&amp;nbsp; and it was fine and then tried with my ISP's&amp;nbsp; ns1 and it was not resolving .. &lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;i tried to check with the ns2 n ns3&amp;nbsp; n ns4 dns servers of the isp and found that ns2 was workin n so also ns4 but not ns1 n ns3 .&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;only after 8 hrs or so after repeated follwoup ns1 of the isp was resolving.&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;and as I said in my first post after checking with the isp i was abruptly told that it was my dns problem either i had chnged the ip of the webserver or the a record or some problem with my dns. also the guy claimed he had to update his dns .. i dont know wht he meant by that&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;so once again sorry for the repeat could this issue have been caused by the above commands&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;and now could i just if i have the auto option toghther with message-length maximum 512 wd that really help me out or do i need to check something else&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;i know I am a bit in silly and confused but just wanna make things go right this time&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;really sorry and do apologise to you guys&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;if you need any more details plss do ask me&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;regards&lt;/P&gt;&lt;P class="MsoNoSpacing"&gt;&lt;/P&gt;&lt;P class="MsoNoSpacing" style="margin: 0in 0in 0pt;"&gt;simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 20:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508878#M599319</guid>
      <dc:creator>benedict dcunha</dc:creator>
      <dc:date>2010-11-03T20:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa issues</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508879#M599320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;SPAN __jive_emoticon_name="grin" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/grin.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, the changes that you did should have not affect anything. The problem resided on your ISP's DNS. Like you said before if you change the dns to google dns everything worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now it would be a good practice to set the&amp;nbsp; DNS request lenght as auto, put the firewall in place and check the logs/service policy to see if you get packet drops over the inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have any questions, please feel free to contact us.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 23:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508879#M599320</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-11-03T23:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: cisco asa issues</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508880#M599321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i had this sme query posted in another forum and a guy called RYAN came out with a lovely n wise explanation to the problem i had&lt;/P&gt;&lt;P&gt;i paste what he said so it gonna help us share knowledge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and what he says he perfectly true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My advise is to disable the DNS inspection and I am going to tell you why say&amp;nbsp; that. Basically when DNS inspection is turned (which it is by default) it&amp;nbsp; "translates" or re-writes the A record on a DNS request. That is probably what&amp;nbsp; caused the ISP to think that the DNS record changed and so had not updated on&amp;nbsp; their servers. Below is a link that explains the DNS inspect (DNS&amp;nbsp; rewrite).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1719130" target="_blank"&gt;http://www.cisco.com/en/US/docs/secu...html#wp1719130&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;as I said before the first time when I disconnected my linux firewall and connected my cisco ASA things were OK but I was not able to resovle my websites from outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so after googling arround and came about the edns issue and did the following to my ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;policy-map type inspect dns preset_dns_map&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt;&amp;nbsp; parameters&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt; message-length maximum&amp;nbsp; 4096&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt; policy-map global_policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt; class inspection_default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt;&amp;nbsp; inspect dns preset_dns_map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after this things worked fine i cd send mail and receive mail from yahoo which earlier i was not able too&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but after 30 to 45 min as i mentioned earlier my network began to crawl .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so soon I discoonected my cisco ASA and connectd my linux firewall and my network as as normal immediately&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but then i go complain that our websites cd not be resolved&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after doing to a nslookup to our upsteam ISP dns i too found that the websites could not be resolved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this exactly explains what RYAN has said.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now I am still wondering as to why our network could bog down completely and became normal immediately when i disconnected my cisco ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;would the above commands be resposible too&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now on sunday i gonna do the below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;config t&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;policy-map type inspect dns preset_dns_map&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt; parameters&lt;/SPAN&gt;&lt;BR /&gt;&amp;gt;message-length maximum client&amp;nbsp; auto&lt;BR /&gt;&amp;gt;message-length maximum 512&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt;policy-map&amp;nbsp; global_policy&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt; class&amp;nbsp; inspection_default&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;and &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;&amp;gt; no inspect dns preset_dns_map&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just wanna confirm that i do not miss anything&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also since I have other services being inspected guess that would not make a problem ( since class inspection is set to default and only dns ispection is disabled )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;just wanna take all the precuations that i dont run into the same trouble as before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your kind advice and help will be highly appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;simon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Nov 2010 20:13:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-issues/m-p/1508880#M599321</guid>
      <dc:creator>benedict dcunha</dc:creator>
      <dc:date>2010-11-04T20:13:23Z</dc:date>
    </item>
  </channel>
</rss>

