smeek
asked on
New PIX- Can't access www.yahoo.com
I set up a PIX with 6.3.4 and 3.0.2. Everything seems to work except the ability to access the main yahoo site. I do not have any filters for Java or ActiveX. I am not doing URL filtering. Any ideas?
Steve
Steve
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Can you access the yahoo IP addresses ?
Is DNS working internally ?
This sounds to me like a name resolution problem. Maybe the PIX isn't configured to be able to see port 53 on Internet DNS servers in order to resolve the name, and you're just left with whatever DNS entries are cached on local machines ??
Is DNS working internally ?
This sounds to me like a name resolution problem. Maybe the PIX isn't configured to be able to see port 53 on Internet DNS servers in order to resolve the name, and you're just left with whatever DNS entries are cached on local machines ??
ASKER
TD, You got me on thinking down a track...
I think it was actually a change in Windows 2003 DNS implementation. It seems the 2003 implementation of DNS allows DNS to accept >512 byte UDP replies. Cisco's DNS fixup seemed to limit it to 512K inspection. I could have removed the fixup but instead increased it's max length. As soon as I changed, I could connect with no issues.
Steve
I think it was actually a change in Windows 2003 DNS implementation. It seems the 2003 implementation of DNS allows DNS to accept >512 byte UDP replies. Cisco's DNS fixup seemed to limit it to 512K inspection. I could have removed the fixup but instead increased it's max length. As soon as I changed, I could connect with no issues.
Steve
> TD, You got me on thinking down a track...
Hmmm... I fail to see why, seeming I was the only one to mention DNS ?
*sigh*
;)
Hmmm... I fail to see why, seeming I was the only one to mention DNS ?
*sigh*
;)
Tim, I'm happy to offer you some of the points if you feel hard done by ?
ASKER
Well, as you can see from my posting, I started back on the issue at 7:41am. I had it solved by 9:30am... I could have used your suggestion a bit earlier, maybe I could have resolved even quicker.
Steve
Steve
A-ha... ! No problem, I see your point ! Sorry. ;)
ASKER
Additional info, this is a T1. We replaced a SnapGear firewall with a PIX.
Steve