Could someone tell me what rules are required to allows DNS traffic through a PIX box?

I have to host 3 domains on a Win2K DNS server, but the PIX is currently blocking the requests.

>access-list 100 line 39 permit udp any host eq domain (hitcnt=344) <== obviously being permitted in...
So what is not working?
What is default gateway of the DNS server? Paste result of C:\>route print
You have to have two things:
1. static nat translation for either the IP or port 53 (UDP) that identifies the public IP and private ip of the server
2. An access-list (or conduit) permitting udp source "any" to public ip, port 53

If you can post your PIX config, I can give you the exact commands necessary.
just1coderAuthor Commented:
the internal ip is:

the external ip is: (let's say) is NAT'd to

I currently have

access-list 100 permit udp any host eq 53
OK. Can you post result of
"Show access-list" and include that line. Is there anything in the (hitcount) ?
Is the acl applied? Do you have a line like:
   access-group 100 in interface outside

What is the default gateway of your DNS server? Is it - the inside interface of the PIX?
Are you secondary DNS or Primary DNS? Do you need to do zone transfers?
You might also need to permit TCP port 53 the same way.
just1coderAuthor Commented:
yes, I have: access-group 100 in interface outside

Inside interface of the pix is

Primary DNS, no zone transfers.

access-list 100 line 38 permit tcp any host eq domain (hitcnt=0)
access-list 100 line 39 permit udp any host eq domain (hitcnt=344)
just1coderAuthor Commented:
The default GW of the DNS server is

Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
       1       1       1       1       1       1       1       1
Default Gateway:

The DNS server fails on test querries.
>The DNS server fails on test querries.
Where is the testing PC physically in relation to the server? On the same internal LAN, but using the Public IP? It won't work.

Try going to  and put in your domain name.

just1coderAuthor Commented:
it's failing right on the server itself. when you go into the DNS snap in, right click the server name, hit properties, and then use the monitoring tab to run test querries ... it fails... I wasn't sure if the PIX was still blocking something...

I can telnet into the DNS server from any other location to port 53 using the hostname and the ip address ...
If it's failing at that point (mine says 'pass'), you might have to look deeper into the server logs...;EN-US;275525

just1coderAuthor Commented:
Dah! Thought so :|
