Solved

Restrict outbound DNS traffic

Posted on 2008-10-15
3
404 Views
Last Modified: 2012-05-05
How do i restrict all DNS access outbound on a PIX firewall except for a specific DNS server?
0
Comment
Question by:Muscella
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 71

Expert Comment

by:Chris Dent
ID: 22725575

Hey,

Depends a little on where you apply the rule. Lets assume the inside of an internal interface (for the sake of the example) and closest to the server you want to make the requests.

This rule will only allow the host 10.10.10.10 to make outbound DNS requests. All other internal clients will have to use that DNS service.

access-list your_acl_name extended permit udp host 10.10.10.10 any eq 53
accessl-list your_acl_name extended permit tcp host 10.10.10.10 any eq 53

TCP is included as it will be used when the response for a request is too big for UDP. Feel free not to include it in your rule-set, it's only worth knowing about in the rare situations where the response is too big.

Chris
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 22725754
You have to be careful when applying restrictive acls or you will block everything. You have to remember the implicit deny all at the end of any acl

Here's an example that will only allow dns server 10.100.110.10 out
access-list outbound_restriction permit udp host 10.100.110.10 any eq domain
access-list outbound_restriction deny udp any any eq domain
access-list outbound_restriction permit ip any any

access-group outbound_restriction in interface inside

0
 

Author Comment

by:Muscella
ID: 22733275
I think this will work.  Thanks!
0

Featured Post

[Webinar] How Hackers Steal Your Credentials

Do You Know How Hackers Steal Your Credentials? Join us and Skyport Systems to learn how hackers steal your credentials and why Active Directory must be secure to stop them. Thursday, July 13, 2017 10:00 A.M. PDT

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
You deserve ‘straight talk’ from your cloud provider about your risk, your costs, security, uptime and the processes that are in place to protect your mission-critical applications.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses
Course of the Month4 days, 11 hours left to enroll

635 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question