Avatar of AhmedCrabgrass
AhmedCrabgrass

asked on 

How do I block DNS queries with ANY as header in Cisco 5510 or BIND?

I keep getting attacks on my DNS servers from China I am trying to formulate a rule on my Cisco 5510 with ADSM 6.3 to drop this malicious traffic. it is all udp traffic I have been blocking ip ranges but i know there is a better fix.

here is an example packet I am seeing in wireshark -- I will get 1,000s of connection from this one host (in this case the 115 addr but it will just change if I block it) the request always seems to be for any and will roll through all of the domains I host.

102      0.064022      10.137.2.2      115.238.236.6      DNS      345      Standard query response 0x2132  SOA ns1.xxxt.net NS ns1.xxxt.net NS ns2.xxxt.net MX 10 ALT1.ASPMX.L.GOOGLE.com MX 20 ALT2.ASPMX.L.GOOGLE.com MX 0 ASPMX.L.GOOGLE.com TXT A xxx.xxx.48.215

My DNS Server is running CENTOS 5.5 and BIND 9.3.6-P1-RedHat-9.3.6-20.P1.el5_8.1


I am not familiar with the Cisco platform as much so any guidance or if you need more info let me know.
or will this ACL rule on bind work for the named.conf

aclNotTheseIPs{
      !1.48.0.0/15;!1.50.0.0/16;!1.68.0.0/14;!1.80.0.0/13;!1.92.0.0/20;
};

Dont know if this helps but almost all the traffic comes from

CHINANET Zhejiang province network
No.31,jingrong street
CN
No.31 ,jingrong street,beijing
China Telecom
VulnerabilitiesRouters

Avatar of undefined
Last Comment
netcmh
ASKER CERTIFIED SOLUTION
Avatar of netcmh
netcmh
Flag of United States of America image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
Avatar of AhmedCrabgrass
AhmedCrabgrass

ASKER

I am afraid we are for now the authoritative responder for now.. I do want to move away from this but we inherited this setup. I will review the doc. however do you think it is easier to drop the ANY requests on the BIND servers themselves? or create an ACL rule there?
SOLUTION
Avatar of netcmh
netcmh
Flag of United States of America image

Blurred text
THIS SOLUTION IS ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
Avatar of netcmh
netcmh
Flag of United States of America image

Thanks for the grade. Good luck.
Routers
Routers

A router is a networking device that forwards data packets between computer networks. Routers perform the "traffic directing" functions on the Internet. The most familiar type of routers are home and small office cable or DSL routers that simply pass data, such as web pages, email, IM, and videos between computers and the Internet. More sophisticated routers, such as enterprise routers, connect large business or ISP networks up to the powerful core routers that forward data at high speed along the optical fiber lines of the Internet backbone. Though routers are typically dedicated hardware devices, use of software-based routers has grown increasingly common.

49K
Questions
--
Followers
--
Top Experts
Get a personalized solution from industry experts
Ask the experts
Read over 600 more reviews

TRUSTED BY

IBM logoIntel logoMicrosoft logoUbisoft logoSAP logo
Qualcomm logoCitrix Systems logoWorkday logoErnst & Young logo
High performer badgeUsers love us badge
LinkedIn logoFacebook logoX logoInstagram logoTikTok logoYouTube logo