cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
274
Views
0
Helpful
1
Replies

Get stuck for a year, alias UDP checksum Error.

eddie195hk
Level 1
Level 1

Hi all, we really need some help.

when we were using PIX 515 firewall, I try to use alias command to change the external IP to internal IP, but when the DNS packet came back from external DNS server, 515 success to translate the IP but I got an udp error in the packet also. Does anybody can help me out, cos we got this problem for a year, thanks so much.

1 Reply 1

rpathani
Level 1
Level 1

Hi Eddie,

Hope you are not doing port forwarding to implement dns doctoring using alias command.

Secondly,make sure fixup for dns max length is set to 1500 and not disabled.

Can you provide with the following information:

1) "show tech" form pix without removing any part or truncating/altering any ip address from it.

2) public and private ip address of web/mail server.

3) Exact error message you get.

You can e-mail me the file directly on my e-mail address too.

Rahul Pathania

TAC Engg - Security

rpathani@cisco.com