11-28-2015 05:19 AM - edited 03-05-2019 02:49 AM
Hi All;
I found lots of messages like below in my 1941 router:
%DNSSERVER-3-BADQUERY: Bad DNS query from <IP address>.
How can I get ride of it?
11-29-2015 12:15 AM
Hi Masoud;
I have already set below command to my router, but I still see lots of DNS in log?
ip access-list extended filter-inbound
evaluate CHECK-TRAFFIC
deny tcp any any eq domain
deny udp any any eq domain
permit ip any any
ip access-list extended filter-outbond
permit tcp any any eq domain reflect CHECK-TRAFFIC timeout 300
permit udp any any eq domain reflect CHECK-TRAFFIC timeout 300
permit ip any any
11-29-2015 04:57 AM
Please post the output of
show access-list filter-inbound
Show access-list filter-outbound.
And please post some of the logs with their ips
Masoud
11-30-2015 06:38 AM
FYI
#show access-list filter-inbound
Extended IP access list filter-inbound
10 evaluate CHECK-TRAFFIC
20 deny tcp any any eq domain
30 deny udp any any eq domain (2 matches)
40 permit ip any any (838823 matches)
#Show access-list filter-outbound
#
%DNSSERVER-3-BADQUERY: Bad DNS query from 1.197.242.39
%DNSSERVER-3-BADQUERY: Bad DNS query from 117.90.248.59
%DNSSERVER-3-BADQUERY: Bad DNS query from 101.85.236.189
11-30-2015 07:26 AM
Try this one intead just for test and check the result. I will direct others attention to your question if you still receive that log after applying this.
ip access-list extended filter-outbond
permit tcp any any reflect CHECK-TRAFFIC
permit udp any any reflect CHECK-TRAFFIC
permit icmp any any reflect CHECK-TRAFFIC
ip access-list extended filter-inbound
evaluate CHECK-TRAFFIC
interface [wan interface]
ip access-group filter-inbound in
ip access-group filter-outbond out
12-09-2015 03:05 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide