cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

FMC/FTD DNS inspection issues

deyster94
Level 5
Level 5

To all:

 

I am trying to configure FMC/FTD to use my clients internal DNS servers for guest wireless.  The interface for the guest wireless hangs off the FTD appliance and I have the policy built in FMC to allow DNS traffic from the guest wireless network inbound and vice versa.  However, in the one location, they must have DNS inspection for one NAT statement that requires DNS doctoring.  If I disable DNS inspection, they can reach the internal DNS servers.  Otherwise, it fails with the following drop-reason:

 

 (inspect-dns-invalid-pak) DNS Inspect invalid packet

 

I can't figure out how to get around this problem in FTD.  

 

TIA for any ideas,

 

Dan

Who Me Too'd this topic