<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC/FTD DNS inspection issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/3408388#M926069</link>
    <description>&lt;P&gt;Did you ever figure this out? I am having trouble even disabling inspection of DNS. Did you use the flexconfig to disable inspection?&lt;/P&gt;</description>
    <pubDate>Sat, 30 Jun 2018 14:25:39 GMT</pubDate>
    <dc:creator>nathan40</dc:creator>
    <dc:date>2018-06-30T14:25:39Z</dc:date>
    <item>
      <title>FMC/FTD DNS inspection issues</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/3314748#M926068</link>
      <description>&lt;P&gt;To all:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to configure FMC/FTD to use my clients internal DNS servers for guest wireless.&amp;nbsp; The interface for the guest wireless hangs off the FTD appliance and I have the policy built in FMC to allow DNS traffic from the guest wireless network inbound and vice versa.&amp;nbsp; However, in the one location, they must have DNS inspection for one NAT statement that requires DNS doctoring.&amp;nbsp; If I disable DNS inspection, they can reach the internal DNS servers.&amp;nbsp; Otherwise, it fails with the following drop-reason:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;(inspect-dns-invalid-pak) DNS Inspect invalid packet&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can't figure out how to get around this problem in FTD.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;TIA for any ideas,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dan&lt;/P&gt;</description>
      <pubDate>Sat, 22 Feb 2020 07:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/3314748#M926068</guid>
      <dc:creator>deyster94</dc:creator>
      <dc:date>2020-02-22T07:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD DNS inspection issues</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/3408388#M926069</link>
      <description>&lt;P&gt;Did you ever figure this out? I am having trouble even disabling inspection of DNS. Did you use the flexconfig to disable inspection?&lt;/P&gt;</description>
      <pubDate>Sat, 30 Jun 2018 14:25:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/3408388#M926069</guid>
      <dc:creator>nathan40</dc:creator>
      <dc:date>2018-06-30T14:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD DNS inspection issues</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/4296639#M1078756</link>
      <description>&lt;P&gt;I am not sure if this still a problem, but have you looked at creating a FlexConfig to not inspect DNS traffic? If this what you are after?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-advanced.html#concept_53C22C306B57480D99DB905E90D5FDC9" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/623/fdm/fptd-fdm-config-guide-623/fptd-fdm-advanced.html#concept_53C22C306B57480D99DB905E90D5FDC9&lt;/A&gt;&lt;/P&gt;&lt;P&gt;We are looking at doing something similar for Cisco Umbrella as DNS traffic cannot be inspected due to encryption to the Cisco Umbrella Cloud.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2021 03:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/4296639#M1078756</guid>
      <dc:creator>WeedyNaana2308</dc:creator>
      <dc:date>2021-02-24T03:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: FMC/FTD DNS inspection issues</title>
      <link>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/4515256#M1085608</link>
      <description>&lt;P&gt;Did the flexconfig resolve your encrypted DNS traffic to Umbrella issue?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Dec 2021 15:18:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-ftd-dns-inspection-issues/m-p/4515256#M1085608</guid>
      <dc:creator>Jack G</dc:creator>
      <dc:date>2021-12-08T15:18:55Z</dc:date>
    </item>
  </channel>
</rss>

