01-19-2018
11:30 AM
- last edited on
02-21-2020
11:35 PM
by
cc_security_adm
To all:
I am trying to configure FMC/FTD to use my clients internal DNS servers for guest wireless. The interface for the guest wireless hangs off the FTD appliance and I have the policy built in FMC to allow DNS traffic from the guest wireless network inbound and vice versa. However, in the one location, they must have DNS inspection for one NAT statement that requires DNS doctoring. If I disable DNS inspection, they can reach the internal DNS servers. Otherwise, it fails with the following drop-reason:
(inspect-dns-invalid-pak) DNS Inspect invalid packet
I can't figure out how to get around this problem in FTD.
TIA for any ideas,
Dan
06-30-2018 07:25 AM
Did you ever figure this out? I am having trouble even disabling inspection of DNS. Did you use the flexconfig to disable inspection?
02-23-2021 07:42 PM
I am not sure if this still a problem, but have you looked at creating a FlexConfig to not inspect DNS traffic? If this what you are after?
We are looking at doing something similar for Cisco Umbrella as DNS traffic cannot be inspected due to encryption to the Cisco Umbrella Cloud.
12-08-2021 07:18 AM
Did the flexconfig resolve your encrypted DNS traffic to Umbrella issue?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide