<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS response  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-response/m-p/993289#M918142</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working on the same issue and what I get it that one DNS server has responded and the firewall DNS inspection engine realizes this so it doesn't respond to the DNS query. I don't think its a harmful log message but I'm looking into it further on my end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 10 Nov 2008 18:09:34 GMT</pubDate>
    <dc:creator>craig.eyre</dc:creator>
    <dc:date>2008-11-10T18:09:34Z</dc:date>
    <item>
      <title>DNS response</title>
      <link>https://community.cisco.com/t5/network-security/dns-response/m-p/993285#M918138</link>
      <description>&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am getting following critical log message: &lt;/P&gt;&lt;P&gt;DENY INBOUND UDP from X.Y.Z.1/53 to P.Q.R.2/1025 due to DNS response &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No impact on client/server side though. But this is continuosly generating log.Related ACL are allowed for DNS response. &lt;/P&gt;&lt;P&gt; what is causing this message to log.Please advise. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;SAS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:01:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response/m-p/993285#M918138</guid>
      <dc:creator>anwar.shariff</dc:creator>
      <dc:date>2019-03-11T13:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response</title>
      <link>https://community.cisco.com/t5/network-security/dns-response/m-p/993286#M918139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please post the complete log line? Also including the Log number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2008 01:58:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response/m-p/993286#M918139</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-06-19T01:58:06Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response</title>
      <link>https://community.cisco.com/t5/network-security/dns-response/m-p/993287#M918140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The number of message is 106007.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Explanation : This is a connection-related message. This message is displayed if a UDP packet containing a DNS query or response is denied. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Recommended Action :   If the inside port number is 53, the inside host probably is set up as a caching name server. Add an access-list command statement to permit traffic on UDP port 53, and a translation entry for the inside host. If the outside port number is 53, a DNS server was probably too slow to respond, and the query was answered by another server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference: &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html#wp1279764" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa72/system/message/logmsgs.html#wp1279764&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps.&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;Massimiliano. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2008 03:05:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response/m-p/993287#M918140</guid>
      <dc:creator>massimiliano.serafino</dc:creator>
      <dc:date>2008-06-19T03:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response</title>
      <link>https://community.cisco.com/t5/network-security/dns-response/m-p/993288#M918141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply, In fact I had referred to this link and tried allowing required policies but same problem persists... any advices further. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;SAS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jun 2008 18:13:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response/m-p/993288#M918141</guid>
      <dc:creator>anwar.shariff</dc:creator>
      <dc:date>2008-06-19T18:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response</title>
      <link>https://community.cisco.com/t5/network-security/dns-response/m-p/993289#M918142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm working on the same issue and what I get it that one DNS server has responded and the firewall DNS inspection engine realizes this so it doesn't respond to the DNS query. I don't think its a harmful log message but I'm looking into it further on my end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Nov 2008 18:09:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response/m-p/993289#M918142</guid>
      <dc:creator>craig.eyre</dc:creator>
      <dc:date>2008-11-10T18:09:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS response</title>
      <link>https://community.cisco.com/t5/network-security/dns-response/m-p/993290#M918143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes this message is normal if you have two servers configured for DHCP relay in the firewall. The first DNS response is allowed through but the second is blocked (and rightly so).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Nov 2008 06:33:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-response/m-p/993290#M918143</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-11-11T06:33:01Z</dc:date>
    </item>
  </channel>
</rss>

