cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1373
Views
3
Helpful
3
Replies

DNS UDP datagram size

Rutger Blom
Level 1
Level 1

Hello,

The default policy on an ASA firewall is to drop DNS UDP datagrams larger than 512 bytes. Have you modified this policy? We had quite some DNS root-servers sending UDP packets of 541 bytes. Is there som general recommendation?

Best regards,

Rutger Blom

3 Replies 3

a.alekseev
Level 7
Level 7

I allways increase this number to 1024.

Security-525(config)# policy-map type inspect dns migrated_dns_map_1

Security-525(config-pmap)# parameters

Security-525(config-pmap-p)# message-length maximum 1024

adrianotte
Level 1
Level 1

I know this is an old post and my question relates to IOS Firewall. How do you change the DNS UPD packet size on an IOS firewall?

I know how to do this on a PIX, but not on the IOS firewall.

Thanks.

Review Cisco Networking products for a $25 gift card