Virus.Org  IT Security News and Information Portal. We offer the latest IT security news, updates, product reviews, books, and articles for all you IT security professionals out there. Enter and get the best IT security information on the Internet.

 

. Welcome to the Virus.Org Mailing List Archive  
.
.


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]


Re: [FW-1] SmartDefense DNS UDP Protocol Enforcement and BIND 9.2.1
.

  • To: [EMAIL PROTECTED]
  • Subject: Re: [FW-1] SmartDefense DNS UDP Protocol Enforcement and BIND 9.2.1
  • From: Lars Troen <[EMAIL PROTECTED]>
  • Date: Tue, 20 May 2003 22:36:37 +0200
  • Reply-to: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]>
  • Sender: Mailing list for discussion of Firewall-1 <[EMAIL PROTECTED]>
  • Thread-index: AcMe2k8tmOJelJHRToWVN2bvSZutrgANF1bA
  • Thread-topic: [FW-1] SmartDefense DNS UDP Protocol Enforcement and BIND 9.2.1
.
 
> We are running FW-1 NG FP3 with SmartDefense. We just started
> implementing
> this configuration and I have noticed that if I turn on the
> SmartDefense
> DNS UDP Protocol Enforcement, my BIND 9.2.1 DNS servers
> behind the firewall
> can not perform recursive lookups.
>
> It would appear that the returned packets from the external
> DNS servers are
> getting dropped with SmartDefense claiming that it's "Badly
> Formed DNS".
>
> Any suggestions?

Maybe this is a similar issue as with Cisco Pix not handling dns udp requests >512 bytes as EDNS0 allows larger dns packets:
http://www.cisco.com/cgi-bin/Support/Bugtool/onebug.pl?bugid=cscds58726

Lars

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to [EMAIL PROTECTED]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[EMAIL PROTECTED]
=================================================

 
.
.
 
Copyright (c) Virus.Org 1997-2006.
All Trademarks Acknowledged.
Please view our Terms and Conditions and our Privacy Policy.