Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 815
  • Last Modified:

DNS Fixup on a PIX

All,

Is there any reason why I cant increase the DNSfixup size on a PIX to 1028 from 512, I heard that there is some security issues with spoofing. Is this really that much of a security consideration?

Thanks people
0
credmood
Asked:
credmood
  • 2
  • 2
1 Solution
 
Tim HolmanCommented:
This is something I've NEVER had to change.   Why would you want to allow a bigger DNS packet ?  Problems with long DNS names ??  This doubles the impact of any DNS related dDOS attack...  ;)
However, I wouldn't imagine that making much of a difference.  The limit is really designed so that people can't send you DNS packets with the max size of 65535 bytes, a lot of which would quickly swamp your systems (bit like a ping o' death with DNS).

There's more about DNS fixup here:

http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_configuration_guide_chapter09186a008017278b.html#wp1063720

As long as your DNS packet size doesn't go over your MTU size, things should work out fine.

0
 
hawgpigCommented:
I agree with Tim...
The only reason to change your dns fixup is if you are running the new EDNS...
But, you can do it if you would like.....
0
 
credmoodAuthor Commented:
Thanks people, sorry for the delay in replying, had a week off,

Yes we are running windows 2003 DNS server, which apparently uses EDNS, havent read up on EDNS, whats the score with that and why does it use  (sometimes) need over 512?
0
 
Tim HolmanCommented:
0
 
credmoodAuthor Commented:
Thanks for your help Tim, increased fixup to 1028 and no longer have syslog telling me that it cant process dns queries over 512
0

Featured Post

Automating Your MSP Business

The road to profitability.
Delivering superior services is key to ensuring customer satisfaction and the consequent long-term relationships that enable MSPs to lock in predictable, recurring revenue. What's the best way to deliver superior service? One word: automation.

  • 2
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now