Re: [fw-wiz] How does your firewall handle DNS messages > 512 octets?



We use a PIX, but rather than change its config we chose this:
C:\dnscmd DNSSERVER/Config /EnableEDnsProbes 0

Much easier and DNS still "just works."

@@ron Smith

On Tue, 2006-08-29 at 15:13 -0400, Dave Piscitello wrote:
Hi all,

I am trying to understand how different firewalls behave when they
receive a UDP datagram containing a DNS message that uses EDNS0 (RFC
2671) to support message sizes greater than the 512 maximum specified in
RFC 1035 (original DNS).

Specifically,

- does your firewall block/silently discard such messages by default?
- do you know the command to allow the message if blocked by default?

I've found dozens of claims that firewalls don't handle EDNS0 correctly,
but after a long search, I've only found URLs indicating that Firewall-1
and Pix block by default and have workarounds.

I'm curious whether SonicWall, Netscreen, Symantec, etc. behave
similarly. I'd also be curious to learn the behavior of IPS devices and
DNS proxies (Watchguard, WinProxy, etc).

You can send replies directly to me and I'll compile responses and post
to the list to save electrons.

Thanks in advance,

Dave

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: [fw-wiz] How does your firewall handle DNS messages > 512 oct ets?
    ... As for the Pix it is configurable to allow dns max packet length to be ... I am trying to understand how different firewalls behave when they ...
    (Firewall-Wizards)
  • Re: AD/DNS with NAT
    ... Datacenters host servers as Domain Controllers AD2003, DNS, Exchange ... sites with the Net ID they use and how they are connected (VPN, ... every small offices to use NAT in order to keep the private IP range ... Forget Firewalls and forget NAT. ...
    (microsoft.public.windows.server.networking)
  • Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....
    ... If you're saying that MAC address ... > Internet, because MAC ADDRESSES ARE A LAN issue, not a WAN issue. ... > "Most firewalls do not come preconfigured to block Private Addresses, ... > "...gain entry via DNS UDP, or worse yet, DNS TCP for Zone Transfers"? ...
    (comp.security.firewalls)
  • Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....
    ... If you're saying that MAC address ... Internet, because MAC ADDRESSES ARE A LAN issue, not a WAN issue. ... "Most firewalls do not come preconfigured to block Private Addresses, ... "...gain entry via DNS UDP, or worse yet, DNS TCP for Zone Transfers"? ...
    (comp.security.firewalls)
  • Re: 99.9 % of Software/Hardware Firewalls DO-NOT.....
    ... The only way your really going to get someone's mac address, ... > Internet, because MAC ADDRESSES ARE A LAN issue, not a WAN issue. ... > "Most firewalls do not come preconfigured to block Private Addresses, ... > "...gain entry via DNS UDP, or worse yet, DNS TCP for Zone Transfers"? ...
    (comp.security.firewalls)