Hi.I have a rather strange problem. We have a PIX515E in our company and for the last couple of days we have been receiving packets with an invalid domain name on our DNS server from addresses outside of our network. What is really strange is that from the outside traffic can enter only our DMZ(not the inside network) via specific ports (mostly tcp port 80) for specific services and the problem is happening on the inside.
Is there any way to monitor for such packets when they arrive on a PIX or better yet block them(they arrived from 4 different IP adresses from 4 different ranges)? Is it perhaps possible that a PC on the inside is allowing access to such packets?
Any help is most welcome.
Refer to the following document for more detail
ASA 7.x/PIX 6.x and Above: Open/Block the Ports Configuration Example