06-18-2007 10:56 AM - edited 02-21-2020 01:34 AM
Hi.I have a rather strange problem. We have a PIX515E in our company and for the last couple of days we have been receiving packets with an invalid domain name on our DNS server from addresses outside of our network. What is really strange is that from the outside traffic can enter only our DMZ(not the inside network) via specific ports (mostly tcp port 80) for specific services and the problem is happening on the inside.
Is there any way to monitor for such packets when they arrive on a PIX or better yet block them(they arrived from 4 different IP adresses from 4 different ranges)? Is it perhaps possible that a PC on the inside is allowing access to such packets?
Any help is most welcome.
Solved! Go to Solution.
06-22-2007 09:53 AM
Refer to the following document for more detail
ASA 7.x/PIX 6.x and Above: Open/Block the Ports Configuration Example
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080862017.shtml
06-22-2007 09:53 AM
Refer to the following document for more detail
ASA 7.x/PIX 6.x and Above: Open/Block the Ports Configuration Example
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080862017.shtml
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide