Hi,
To allow EDNSO packets, please increase the length of the packet to more than 2K under the default policy map.
policy-map global_policy
class inspection_default
inspect dns maximum-length 4096
Or, you can just configure "inspect dns".
Let me know.
Regards,
Anu