Message Code | ASA-2-106007 |
Severity | Critical |
Description | Deny inbound UDP from outside_address/outside_port to inside_address/inside_port due to DNS {Response|Query}. |
Explanation | This is a connection-related message. This message is displayed if a UDP packet containing a DNS query or response is denied. |
User Action | If the inside port number is 53, the inside host probably is set up as a caching name server. Add an access-list command statement to permit traffic on UDP port 53 and a translation entry for the inside host. If the outside port number is 53, a DNS server was probably too slow to respond, and the query was answered by another server. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.