<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Query error in ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464312#M708396</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's strange that you were able to resolve DNS using the same DNS server, while others can't from a different address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can run packet capture from both your address and your customer's address on the outside interface, and download it in pcap format to see if there is any difference between the 2 DNS queries. Is your customer able to test it with a different machine? or using the same machine and testing it from another internet provider?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Jun 2010 11:04:12 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-06-22T11:04:12Z</dc:date>
    <item>
      <title>DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464309#M708371</link>
      <description>&lt;P&gt;hi halijenn / experts&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;106007 Deny Inbound UDP from 63.131.5.11/32411 to 63.131.64.142/53 due to DNS Query &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the error which customer is getting when he is having Public DNS Server inside the organization .Following static and ACL configured for the same .However when i do it from my end , i am able to see that it is getting resolved to a name&amp;nbsp; But customer says that on public internet when he type in nslookup, and type server 63.131.64.142 he wait for the response and he never gets that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group protocol DOMAIN&lt;BR /&gt; protocol-object udp&lt;BR /&gt; protocol-object tcp&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ,Outside) 63.144.54.1 192.168.16.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list Out2In extended permit object-group DOMAIN any host 63.144.54.1 eq domain &lt;BR /&gt;access-group Out2Inin in interface Outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have gone through the link for syslog 106007 , but i was not pretty sure if the explanation fits over here as i see the acls are configured . Please let me know what could be the probable reason .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4768890" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/system/message/logmsgs.html#wp4768890&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:02:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464309#M708371</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2019-03-11T18:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464310#M708376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ankur,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please advise what is the DNS server ip address?&lt;/P&gt;&lt;P&gt;From the syslog, it seems that the DNS server is 63.131.64.142, however from the static NAT configuration, it's 63.144.54.1 (which is a different address).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please confirm. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 10:43:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464310#M708376</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T10:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464311#M708384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;halijenn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i am sorry , please read the syslog as 63.144.54.1 .There is no IP as 63.131.X.X .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 10:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464311#M708384</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-06-22T10:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464312#M708396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's strange that you were able to resolve DNS using the same DNS server, while others can't from a different address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can run packet capture from both your address and your customer's address on the outside interface, and download it in pcap format to see if there is any difference between the 2 DNS queries. Is your customer able to test it with a different machine? or using the same machine and testing it from another internet provider?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 11:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464312#M708396</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T11:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464313#M708403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi halijenn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for looking into issue . please let me know if the below packet captures will be correct to take .Yes , i have asked him to chk with a diff . machine and from a different ISP as well .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list capi permit udp host &lt;SERVER private="" ip=""&gt; eq 53 any&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;access-list capi permit udp any host &lt;SERVER private="" ip=""&gt; eq 53&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list capo permit udp host &lt;SERVER pub="" ip=""&gt; eq 53 any&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;access-list capo permit udp any host &lt;SERVER pub="" ip=""&gt; eq 53&lt;/SERVER&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 11:12:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464313#M708403</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-06-22T11:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464314#M708408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure "any" for the client, or you can have a more specific ip address (your customer's actual ip address). Just in case there are a lot of DNS query going towards the DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Further to that, i wouldn't worry too much about the port# in the ACL, just match it on UDP without port as I wouldn't think there would be other types of UDP traffic going towards the DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list capi permit udp host &lt;SERVER private="" ip=""&gt; any&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;access-list&amp;nbsp; capi permit udp any host &lt;SERVER private="" ip=""&gt;&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list&amp;nbsp; capo permit udp host &lt;SERVER pub="" ip=""&gt; any&lt;/SERVER&gt;&lt;/P&gt;&lt;P&gt;access-list&amp;nbsp; capo permit udp any host &lt;SERVER pub="" ip=""&gt;&lt;/SERVER&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 11:17:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464314#M708408</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T11:17:38Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464315#M708412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Besides that can u please let me know as to what possibly cud be the issue&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 12:51:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464315#M708412</guid>
      <dc:creator>ankurs2008</dc:creator>
      <dc:date>2010-06-22T12:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464316#M708414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately at this stage we don't have enough information to determine possible causes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You might also want to issue "clear asp drop", test the failed dns resolution and check "show asp drop" output and see if there is any specific asp drop reason that might be dropping the dns query.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 12:57:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464316#M708414</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-22T12:57:19Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Query error in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464317#M708417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you get us the output of show run pol ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Jun 2010 13:02:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-query-error-in-asa/m-p/1464317#M708417</guid>
      <dc:creator>abinjola</dc:creator>
      <dc:date>2010-06-22T13:02:39Z</dc:date>
    </item>
  </channel>
</rss>

