Does PIX IOS version 6.1(5) have a problem with DNS zone transfer?
I experienced an issue when I configured zone tansfer between 2 dns servers at internal and external zones. The PIX version is 6.1(5). I believe all the ports (TCP and UDP)are opened. Actually, from internal DNS server, I could query the external DNS server (which is UDP traffic), as well, I could use the 'dig' command to manually transfer the zone file from the external DNS server (which is TCP traffic). However, I could not use 'rdnc reload' to transfer the zone file from the external server (which is UDP traffic). From the firewall log, I got the following information as attached.
However, I tested from a PIX with version 6.3. The 'rndc reload' command worked.
Re: Does PIX IOS version 6.1(5) have a problem with DNS zone tra
the logs which you have attached suggest the connection is bilt up properly.as well as the teardown is normal,i.e,without any interruption at either ends.It's a normal tcp close down sequence with out any flags,but the data transferred in verl low ( 1 byte ).I would recommend you to upgrade to 6.3.5 gd release as that's far more caveat free then 6.1.as far as your question as to what might cause this,i m not sure as logs look fine. ( in fact in 6.1,logs did n't use to give much info )...hope this helps.
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...