Solved

Restrict outbound DNS traffic

Posted on 2008-10-15
3
392 Views
Last Modified: 2012-05-05
How do i restrict all DNS access outbound on a PIX firewall except for a specific DNS server?
0
Comment
Question by:Muscella
3 Comments
 
LVL 70

Expert Comment

by:Chris Dent
ID: 22725575

Hey,

Depends a little on where you apply the rule. Lets assume the inside of an internal interface (for the sake of the example) and closest to the server you want to make the requests.

This rule will only allow the host 10.10.10.10 to make outbound DNS requests. All other internal clients will have to use that DNS service.

access-list your_acl_name extended permit udp host 10.10.10.10 any eq 53
accessl-list your_acl_name extended permit tcp host 10.10.10.10 any eq 53

TCP is included as it will be used when the response for a request is too big for UDP. Feel free not to include it in your rule-set, it's only worth knowing about in the rare situations where the response is too big.

Chris
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 22725754
You have to be careful when applying restrictive acls or you will block everything. You have to remember the implicit deny all at the end of any acl

Here's an example that will only allow dns server 10.100.110.10 out
access-list outbound_restriction permit udp host 10.100.110.10 any eq domain
access-list outbound_restriction deny udp any any eq domain
access-list outbound_restriction permit ip any any

access-group outbound_restriction in interface inside

0
 

Author Comment

by:Muscella
ID: 22733275
I think this will work.  Thanks!
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

There have been a lot of times when we have seen the need to enter a large number of DNS entries in a forward lookup zone. The standard procedure would be to launch the DNS Manager console, create the Zone and start adding new hosts using the New…
Occasionally you run into the website or two that will not resolve properly using your own DNS servers.  Some people simply set up global forwarders for their DNS server.  I don’t recommend doing this because it can cause problems resolving addresse…
This video discusses moving either the default database or any database to a new volume.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now