cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3323
Views
10
Helpful
9
Replies

cisco firepower is sending dns queries to open DNS 208.67.222.222

NetExprt
Level 1
Level 1

Dear ,

we noticed that cisco firepower FTD 2130 is sending DNS requests to the open DNS 208.67.222.222 which is not required and we didn't configured.

we need to disable this featrue , please advice

9 Replies 9

#Mat
Level 6
Level 6

Hi @NetExprt , from FMC > System > Administration interfaces you can change this configuration.

Umbrella's servers were configured in the first FMC boot.

 

Regards.-

.

NetExprt
Level 1
Level 1

Thanks Mat ,

I already cheked that and found nothing there is configured with open DNS .

only our internal DNS is configured.

is there any embeded configuration cause this behavior ?

 

 

#Mat
Level 6
Level 6

Hi there, I'm sorry but I got confused when I wrote about FMC, you asked about FTD.

Check from FTD CLI "show network" or "show running | grep 208.67.222.222"

Also, you can verify the platform setting from FMC if Umbrella server is configured.

 

 

is there any embeded configuration cause this behavior ?


They are preset if you don't change them when you install FTD. Anyway, you can also change them at any time.

 

Regards.-

 

HTH.

.

NetExprt
Level 1
Level 1

Excellent Mat

it is there , is it fine to change in working hours ?

#Mat
Level 6
Level 6

Excellent Mat

it is there , is it fine to change in working hours ?


Hi there! If you change the Umbrella servers for any other DNS server that works, you shouldn't have to have trouble.

Hope this helps you, regards.-

.

We have 2110 in platform mode. We see lot of dns requests from the management interface of firepower to the open dns servers. Although we have removed the open dns from the platform settings of the chassis manager, we still see dns queries from the management interface. Any suggestions?

From the FTD CLI, do a "show network" to see if the open dns servers are still in use. You can change the DNS servers with the "configure network dns servers" command.

BTW. As far as I know, chassis manager are only availible on the 4100 and the 9300  series and not on the 2100.

/Chess

Hi Chris,

 

2100 in platform mode has chassis manager:

https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp2100/firepower-2100-gsg/asa-platform.html

show network command does not work on the fxos cli.

Thanks,

@dijeshkeloth "connect ftd" first or login directly to the FTD management interface. Then you can run the "configure network..." commands.

Review Cisco Networking for a $25 gift card