Solved

Restrict outbound DNS traffic

Posted on 2008-10-15
3
393 Views
Last Modified: 2012-05-05
How do i restrict all DNS access outbound on a PIX firewall except for a specific DNS server?
0
Comment
Question by:Muscella
3 Comments
 
LVL 70

Expert Comment

by:Chris Dent
ID: 22725575

Hey,

Depends a little on where you apply the rule. Lets assume the inside of an internal interface (for the sake of the example) and closest to the server you want to make the requests.

This rule will only allow the host 10.10.10.10 to make outbound DNS requests. All other internal clients will have to use that DNS service.

access-list your_acl_name extended permit udp host 10.10.10.10 any eq 53
accessl-list your_acl_name extended permit tcp host 10.10.10.10 any eq 53

TCP is included as it will be used when the response for a request is too big for UDP. Feel free not to include it in your rule-set, it's only worth knowing about in the rare situations where the response is too big.

Chris
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 22725754
You have to be careful when applying restrictive acls or you will block everything. You have to remember the implicit deny all at the end of any acl

Here's an example that will only allow dns server 10.100.110.10 out
access-list outbound_restriction permit udp host 10.100.110.10 any eq domain
access-list outbound_restriction deny udp any any eq domain
access-list outbound_restriction permit ip any any

access-group outbound_restriction in interface inside

0
 

Author Comment

by:Muscella
ID: 22733275
I think this will work.  Thanks!
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I will assume you are running a non-server version of some sort of Windows throughout this article. There are many flavors of Windows since Windows Server 2000 - 2008, XP Home & Pro, Vista Home & Pro, and Windows 7 Starter, Home, Pro, Ultimate, etc.…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now