PIX DACL won't match UDP

Unanswered Question
Jan 16th, 2008
User Badges:

I have setup downloadable ACL's between a IAS Radius Server and a PIX 515e running 6.3(3) code.

The downloading of ACL's works fine and I can see all the Access-list entries downloading to the pix.

But for some reason the pix never matches entries for UDP traffic. eg ;

ip:inacl#200=permit udp host eq 53

Even though the entry is in the AAA-USER-username ACL, DNS traffic will never be permitted. I have double checked in ethereal that the queries are udp and are going to the configured dns server.

Anyone able to fill me in on what is going on here?



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
ivillegas Tue, 01/22/2008 - 11:43
User Badges:
  • Silver, 250 points or more

Try configuring the reverse statement , permit udp host eq 53 to allow the DNS traffic back to the PC.


This Discussion