<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fixup DNS issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560068#M649969</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, sounds great. Let us know how the upgrade of the code goes. If you want to continue troubleshooting, you can enable the logs at debugging level and check why the connection is being dropped and also set some captures and match them againts the other captures where the servers work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has been nice working with you, let us know how does it go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Oct 2010 04:18:40 GMT</pubDate>
    <dc:creator>Maykol Rojas</dc:creator>
    <dc:date>2010-10-29T04:18:40Z</dc:date>
    <item>
      <title>fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560059#M649960</link>
      <description>&lt;P&gt;Got an interesting scenerio.&amp;nbsp; I have a DMZ that has some public facing serves that are a part of a windows domain.&amp;nbsp; We are trying to get these machines to register dns records dynamically.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Long story short, we found that when the fixup DNS is enabled, they don't register, but when we disable fixup for DNS, they register just fine. &lt;/P&gt;&lt;P&gt;I tried lengthening the maximum length to the very max and still got nothing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I don't mind creating static DNS records for these servers, that is not a big deal.... what I am wondering is what kind of security risk is there to have fixup for DNS disabled?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560059#M649960</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2019-03-11T18:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560060#M649961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike here, when you say fixup it makes me think that you are using Pix version 6.3 is that correct? Would you pleae take the logs when the Server is trying to register and when the firewall drops the packet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Oct 2010 19:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560060#M649961</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-20T19:39:09Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560061#M649962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a FWSM and it doesn't show that the firewall drops the packet.&amp;nbsp; The only hint I had was a DNS error on the server.&amp;nbsp; If I disable fixup for DNS, everything is fine.&amp;nbsp; Now, my main question is what is the security risk of turning this off?&amp;nbsp; I can still create static dns records, which I am not opposed to.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Oct 2010 23:20:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560061#M649962</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2010-10-23T23:20:23Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560062#M649963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's what will happen with fixup for DNS:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/command/reference/df.html#wp1067379"&gt;http://www.cisco.com/en/US/docs/security/fwsm/fwsm23/command/reference/df.html#wp1067379&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i would like to know what kind of packets are being dropped by the FWSM. What version are you running on the FWSM? You can apply captures on the FWSM and get them in a .pcap format.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-1222"&gt;https://supportforums.cisco.com/docs/DOC-1222&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Oct 2010 00:21:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560062#M649963</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-10-24T00:21:15Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560063#M649964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wouldnt suggest you to leave it off. It is very important to have it on since they match the DNS packet against the RFC and assure that the packet is actually a dns packet. Otherwise many attacks can be leverage against your network,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cant see any dns packets dropped on the show service-policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Oct 2010 20:44:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560063#M649964</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-24T20:44:07Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560064#M649965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;nope.&amp;nbsp; However, this firewall is running a very old version.&amp;nbsp; I know it needs upgraded, I am just waiting fo&lt;SPAN style="background-color: #f8fafd;"&gt;r a window of oppertunity to do so.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 16:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560064#M649965</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2010-10-26T16:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560065#M649966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The other strange thing is that other servers, that are in different FWSM interfaces, are having no issue.&amp;nbsp; It is only servers on this one interface.&amp;nbsp; That is really what has me stumped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 16:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560065#M649966</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2010-10-26T16:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560066#M649967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are they running the same OS? Sometimes the Inspection engines on the Firewalls get stuck, it would be a bad idea to reload the module just for testing purposes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Oct 2010 16:35:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560066#M649967</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-26T16:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560067#M649968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;They are running the Same OS.&amp;nbsp; All servers are 2008 R2 Data Center.&amp;nbsp; It really isn't too big of a concern.&amp;nbsp; Creating static DNS records for these boxes is acceptable.&amp;nbsp; I at least know what is causing the issue, I just don't know the why.&amp;nbsp; I know I need to update the code so I may just work on doing that and then revisit the issue later on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all of the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 02:34:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560067#M649968</guid>
      <dc:creator>jlhainy</dc:creator>
      <dc:date>2010-10-29T02:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: fixup DNS issue</title>
      <link>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560068#M649969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, sounds great. Let us know how the upgrade of the code goes. If you want to continue troubleshooting, you can enable the logs at debugging level and check why the connection is being dropped and also set some captures and match them againts the other captures where the servers work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It has been nice working with you, let us know how does it go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 04:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fixup-dns-issue/m-p/1560068#M649969</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2010-10-29T04:18:40Z</dc:date>
    </item>
  </channel>
</rss>

