Refusal due to the DNS response

Hello

I get after spammed in my syslog all of a sudden our PIX. The incoming port is always the same, but the receiver's port.

% 2 PIX-106007: Deny UDP incoming 204.117.214.10/53 to 63.xxx.xxx.xxx/21465 because of the DNS response.

My understanding is that the PIX has called DNS Guard (which I can not turn off) and it corresponds to DNS responses to DNS queries and only allows the first DNS request in. I guess that's what is blocking? How can I prevent continuous errors?

If anyone can throw some light for a new user of PIX I'd appreciate it. Thank you.

204.117.214.10 is our ISP (sprint), btw.

Custody of DNS in the PIX is a number of things, one is that when he sees the query DNS turns off and when he sees the DNS response come back, he checks to see that they meet all upward and closes its doors opening to at the outset. So basically you can only have one answer per request to come back through, any subsequent action will be denied and you will see this error.

The usual cause for this error is that 204.117.214.10 took too long to respond, and the query was answered by another DNS server. When this response through the PIX, the PIX has closed the session and the answer later 204.117.214.10 was denied. Generally not to worry.

6.3 code you can disable the DNS guard, although I would not recommend this, trigger this means packets DNS will be treated as standard UDP packets and expire after 2 minutes, rather than just after the DNS response. If you do a lot of DNS requests then this will dramatically increase your number of xlate and conn, then you'll want to keep an eye on it. The command to turn it off is:

No fixup protocol dns

Tags: Cisco Security

Similar Questions

  • I can't open certain pages due to the DNS error that can do about it?

    I can't open some pages that I know are not handicapped, yesterday I entered bathandbodyworks.com and today I can't. It seems that I need to a few add-ins or something; I tried to open it in google chrome and in internet explore, but the same thing happens. What can I do about it? I tried a lot of things, but nothing seems to work. If the page does not work on chrome or in Solution Explorer. It's so weird!

    Please help me!
    Thank you

    Hello

    Thanks for joining us out on Microsoft Community Forums.

    From your post, it seems you found DNS error when you access a few sites.

    Quick questions:

    1. What did you solve the problem?
    2. What is the exact error message?

    We will try these steps and check:

    Method 1:

    Clear the DNS cache forces DNS to query a DNS server rather than using the information stored in the cache.

    You can clear the DNS cache that you receive repeated errors when you know that you type an address is correct.

    Try these steps and check for the issue:

    a. click the Start button.

    (b) in the search box, type command prompt.

    c. in the list of results, right-click guestand then click run as administrator. If you are prompted for an administrator password or a confirmation, type the password or provide confirmation.

    d. at the command prompt, type ipconfig/flushdns.

    Reference:

    http://Windows.Microsoft.com/en-us/Windows7/DNS-domain-name-system-frequently-asked-questions

     

     

    Method 2:

    Perform the steps mentioned below and check if the problem persists.

    a. click on start and then Control Panel.

    b. go to the networking and sharing Center and then click on change adapter settings.

    c. right-click on connection to the Local network and select Properties.

    d. Select Internet Protocol Version 6, and then click Properties.

    e. Select obtain DNS server automatically an address and press Ok.

    f. Select obtain IP address automatically.

    g. Repeat steps for Internet Protocol version 4 as well.

    Post us the result of the suggested steps.

    If you need help about Windows, let know us and we will be happy to help you.

  • Packages refused due to the overall correlation

    Under the overall correlation reports I see reputation filtering 86,88% and Tranditional 13.12% IPS detection Techniques and Inspection of overall correlation of 0%. I can't see what reputation filtering is blocking or decline, how to see it in the reports? Is also the detection Techniques in traditional IPS what version 6.X?

    Currently, there is no method to see what has been denied by reputation filtering.

    The system has an enhancement request to add data showing the addresses denied by reputation filtering. This is being considered for a future version.

    And Yes, the detection Techniques in traditional IPS is what would prevent a sensor of version 6.x for the same traffic.

  • operation refused due to the elevation

    Installation tried hooked on phonics program and was denied because it featured a rise more

    Try this, right-click on the Setup installer for HOF file and select 'run as administrator '.

    You may need to browser the cd/dvd installation to find setup.exe.

  • NB200-h-13 - no response from the DNS server and gateway

    Hello

    I have netbook NB200-h-13 with XP SP3. Its impossible to connect to wireless internet and the error messages are
    HE DIDN'T THERE WAS NO RESPONSE FROM THE DNS SERVER
    HE DIDN'T THERE WAS NO RESPONSE FROM THE DEFAULT GATEWAY

    The connection with the ethernet cable is ok with the adpter reltek that also adpter atheros ar9285 WiFi is activation, working properly and the modem router signal is strong.

    Hi abk55,

    What program you receive this error message?
    Have you tried another browser, for example Firefox or Opera?

    I guess it has something to do with your wireless network card or WLAN parameters if the LAN cable is working properly. So you should try to update the WLAN driver on the Toshiba site.
    Also, try to disable the filtering of MAC addresses and use another encryption.

  • LVRTE 2012 installation refuses due to higher versions

    LVRTE 2012 install refuses due to higher versions already installed

    See attachment

    probably LVRTE 2012 is installed, but not visible in programs and features OR...

    In C:\Program Files (x 86) \National Instruments\Shared\LabVIEW run time, they are all visible...

    Perhaps another reason why the application LV closes / disappears without notice... (e.g. security dongle)

  • What it means that the DNS server instead sends a node adapter directly status request to the IP address?

    What it means that the DNS server instead sends a node adapter directly status request to the IP address involved in the reverse DNS query. When the DNS server gets the NetBIOS name of the node status response, it adds the DNS domain name specified in the WINS - R record the NetBIOS name provided in the node status response and passes the result to the client applicant. ?

    Hello

    Please repost these questions in the Technet Forums

    http://social.technet.Microsoft.com/forums/en-us/category/WindowsServer

    See you soon.

  • Email problem: Error 550 - 0x800CCC69 - Message rejected due to the reputation of the sender's IP

    Hello

    I have a problem running Outlook Express in WinXP SP3. I can receive but not send an email, I got the error next message when sending email:

    Error 550 - 0x800CCC69 - Message rejected due to the reputation of the IP of the sender (or words to that effect, at least)

    I have other messages on the forum the impression is that this error occurs usually when there is a suspicion that an e-mail account is used to send the spam, but I talked to our ISP and email provider (this does not relate to a Hotmail address) and they said that there is no problem from their point of view , and it must be something to do with OE. We also checked all the settings of the ISP account and everything is perfect.

    Can anyone offer any help?

    Thank you

    This error message comes from your ISP. They refuse to relay messages. Unless you are not connected to your ISP directly, IOW, sending another address through your ISP, they have blocked you.

    Remember their service tech and ask to speak to a technician level 2.

    P.S. When an error message in question, please copy and paste in your message. Wording right can make a difference.

    Bruce Hagen
    MS - MVP October 1, 2004 ~ September 30, 2010
    Imperial Beach, CA

  • High load on the DNS lookups strange made BBNTD

    I don't know if there is a bug report area (I have to confess I always get lost on this site - between BB and Quest, but that's for another day), but I see some very crazy behaviors of one of my installations of BBPE. I'm still running v4.4 (access to builds more returned was one of my many problems with taken BB - a site for hours chatting with someone - again, for another day), but my config remained relatively unchanged for some time, but recently, I have been see a lot of testing side purple server will year it corresponds with a heavy load of CPU on BBNTD - almost 60% on a Server 2 processors with 3 GB of RAM. The server is 2008 R2 with all the patches. When I drilled down, I saw a large number of packets DNS targeting the DNS server (flooding the server DNS - something like 750 packets per second). Queries seem to be for a part of the name. All my internal machines are in the DNS netway.priv space, but queries are for y.priv and y.priv.netway.priv, again and again in order. The DNS server sends responses without a name such as one might imagine.

    I can provide the config files and wireshark capturing traffic, but there seems to be a parse error, perhaps for a nonprintable character or something. The last thing I did to the system was to allow and to start using the web - host configuration editor. This may have introduced a problem or it would be completely different.

    At the present time, my server is useless noctilucence, because it shows stale random tests more than actual errors. BBPE and BBBTF have been quite reliable, as I am unaware of any troubleshooting tools available to the attention of implementers. Is there a way to put BB server logging mode or debug? Can someone tell me how can solve this problem. I'm reduced to systematically change the bbhosts file to try to isolate the problem. I am trying to turn off all DNS queries for devices in the namespace my, using testip and no conn, but even if it works, it is not acceptable in the long term.

    Advice or guidance would be appreciated.

    Jim Graczyk

    [email protected]

    Hi Jim,.

    I understand your frustration, but I've never seen that happen before (I thought at first, but when you bring DNS queries, then it was something new, at least for me). And as there is no ticket open with Quest (at least to my knowledge), it is difficult to debug without access or data from the facility.

    At this point, I strongly suggest an opening with Quest support call. If you have purchased licenses BBPE, you are entitled to it. This site is a community where it's more of the "how can I" or "where can I" type of questions. When it comes to questions like yours, if after one or two responses, the problem cannot be resolved, it is better to contact quest support (as I suggested). It will probably find its way to me. And I'll be happy to work with you to resolve the issue.

    concerning

  • Change the DNS settings in the Pool of IP network

    Hello

    Due to a migration of our DNS servers, I have to change the IP addresses of the DNS servers defined in the (currently used) our BDE server IP pools. There is a Hadoop cluster with a large amount of data running using this pool and I do not have to deploy the cluster again. Restart of the cluster is not matter, so I planned the settings DNS for the cluster nodes have to change after reboot. Unlikely, I could not change the DNS settings. Is there a way (perhaps non-elegant) change those settings for the pool?

    See you soon,.

    Dustin

    Hi Dustin,

    BDE provides the interface to change the DNS server in the network added to the BDE.  You must change the BDE database to do.  Here is the solution:

    1 Server BDE connect you as user serengeti

    2. run this command: echo ' network dns1 set update = 'the_new_dns_server_ip' where name = 'the_network_name '; \q" | psql

    3. apply the new DNS server. There are two approach. You can choose one.

    (a) connection BDE CLI and run "cluster stop - name...". ' and 'start cluster - name... '. "to restart the virtual machines in the cluster, then the new DNS server will be applied.

    (b) on BDE server, run "serengeti - ssh.sh cluster_name " sudo sed-i of | nameserver. * | nameserver the_new_dns_server_ip| ' g' / etc/etc/resolv.CONF. The new DNS server should take effect immediately.

    Thank you for using BDE.

    Jesse @BDE

  • fdmload failed due to the ORA-00942 on passage with custom liability

    Hello

    I created a top custom applications R12

    When I go to personal responsibility

    It gives an error

    fdmload failed due to the ORA-00942: table or view doesnot exist

    Thus a long sql code is given

    in the message mentioned tables are fnd_menu_entries_tl and fnd_menu_entries

    APPS Version: 12.1.2
    DB 11.2.0.1

    Hello

    full error message

    APP-FND-01564 error 942 in fdmload
    cause: failed to fdmload EU to ora-00942 table or view doesnot exist

    I also gave access to tables

    Please see (RSOB responsibility: FDMLOAD fails Due to ORA-00942 [337896.1 ID]).

    Thank you
    Hussein

  • I bring you my affected MacBook Pro (17-inch late 2011) at the centre for Apple in Algeria and they refused to cover the repair and asked to pay $ 350.

    I bring you my affected MacBook Pro (17-inch late 2011) at the centre for Apple in Algeria and they refused to cover the repair and asked to pay $ 350.

    When did you purchase the MacBook? What reason they gave for the tarp does not it? What you expect from us, your fellow users?

  • How can I review the three responses to my question

    Last week, I posted the question "can I Tbird to download a load from the rear of the unread messages in my Inbox Gmail account?", and three volunteers responded. Their help solved my problem so the wire has been closed. How can I see the 3 responses to make a reference to their content?

    Peter
    in Thailand

    Come on the forum. Click on your name next to your ad on this thread. will take you to your profile where your questions are displayed when you click the number of the question.

    When I click on your name it shows 2 questions. By clicking on that shows two questions.

  • can not change the dns server, always comes back.

    10.10.5 Yosemite

    My ISP has provided DNS servers are terrible and I still get messages "site is not reachable. I'd like to change the DNS from Google or Open DNS servers

    In SYSTEM preferences > network > DNS tab I delete 2 default entries & entry "8.8.8.8" & "8.8.4.4" (google dns)
    In the "areas of research" box, there are 2 entrances & I can't delete them.

    I click OK & apply - when I go back to the DNS tab, it was the old DNS.

    What should do?

    May be a corrupt .plist.

    Make a backup, preferably 2 backups on 2 separate drives.

    Quit the application.

    Go to Finder and select your user folder. With this Finder window as the windshield, select Finder/display/display options for presenting or order - J.  When the display options opens, check "show the library folder. This should make your visible user library folder in your user folder.  Select the library. Then go to Preferences/com.apple.systempreferences.plist.  Move the .plist on your desktop.

    Restart your computer, open the application and test. If it works fine, delete the plist for the office.

    If the application is the same, return the .plist where you got it, crushing the latest.

    Thanks to leonie for certain information contained in this.

  • version 31.0 refuses to install the spelling dictionary

    New facilities or profiles Firefox 31.0 refuse to install the Nederlands spelling dictionary with: "Not available for Firefox 31,0", which is silly, because the dictionary in question works very well in the existing versions of Firefox (where this spelling dictionary has been installed previously) have been updated to 31.0.

    How can I get Firefox to install the dictionary anyway? I have this problem with a new installation on my laptop (Ubuntu Linux) and a new profile on my PC (Slackware Linux).

    Just click on the gray button 'add to Firefox' and click 'Install Anyway'.

Maybe you are looking for

  • Open a link in a new tab

    Instead of opening a link in a new tab, now when I click on a link, a new window opens. How can I stop this and put in place the system to open links in a new tab instead?

  • My Satellite C660 turns on itself

    Several times after putting on sleep, I come back to find that he himself lit! I only noticed this, while it set to never sleep while it's totally shut down/turn off. It's a Satellite C660-1UG (France) This is my second Toshiba, my last one also a Sa

  • iTunes game is automatically downloading songs on the phone

    iTunes game is automatically download all the songs to my iPhone once they were put in correspondence / downloaded. I don't see all the settings to stop this and download only the specified titles.  Any ideas?

  • Keypad entry

    All, Is there a simple way to manage the keypad entry similar to most of the HMI/SCADA systems? Click on IE on the control and the small pavement rises? -Ken

  • How my laptop memorysupport

    Mr President. I using hp 630 laptop. I switch window 7 ultimate to business window 8.Sir can you tell me my laptop maximum requirement means my laptop a lot holding slot 1 ram. I have install 2 GB DDR 3 memory. what I upgraded from 2 GB to 4 GB or 8