Solved

OpenDNS Access-list

Posted on 2015-01-26
4
158 Views
Last Modified: 2015-02-18
I have the following access-list on a Layer 3 switch to allow access to OpenDNS for a specific group of PCs.
When I test by doing a DNS lookup, it fails. I can see the number of hits going out increasing but the replies do not get any hits.
I did a Wireshark capture from our Firewall to make sure it was not the cause of the problem by denying the reply traffic back in but it does allow it and then gets dropped by the switch (I am guessing) which sends an ICMP unreachable back to OpenDNS. Do I can see the DNS query to OpenDNS, the reply from open DNS and then the ICMP unreachable from the switch which makes me think the switch is the one dropping the returned traffic.

Can anyone see anything wrong with the following access-list that might be causing the traffic to be blocked?

Extended IP access list PCL_Access_In
    20 permit udp 192.168.95.0 0.0.0.255 host 208.67.220.220 eq domain log (473 matches)
    30 permit udp 192.168.95.0 0.0.0.255 host 208.67.222.222 eq domain log (648 matches)
Extended IP access list PCL_Access_Out
    20 permit udp host 208.67.220.220 192.168.95.0 0.0.0.255 eq domain log
    30 permit udp host 208.67.222.222 192.168.95.0 0.0.0.255 eq domain log
      
interface Vlan10
 description PCL_Machines
 ip address 192.168.95.1 255.255.255.0
 ip access-group PCL_Access_In in
 ip access-group PCL_Access_Out out


Thanks in advance
0
Comment
Question by:troubleshooter141
  • 2
4 Comments
 
LVL 45

Accepted Solution

by:
Craig Beck earned 500 total points
ID: 40572270
Just use the in direction when applying the ACL to the SVI to see if that helps - don't use the out ACL.
0
 
LVL 5

Expert Comment

by:Feroz Ahmed
ID: 40580311
Hi,

Can you have a look at the Cabling on Swtich end connecting to Specific Hosts .I hope there is Cross Cabling done in between Switch and Hosts that is the reason you are getting Destination Host Unreachable at Firewall end.Or you can just change the switch and look for the Ping Status .
0
 
LVL 45

Expert Comment

by:Craig Beck
ID: 40580318
^^^ ??
0
 
LVL 3

Author Closing Comment

by:troubleshooter141
ID: 40616887
Thanks CraigBeck, removing the access-list from the Out direction fixed the issue.
0

Featured Post

DevOps Toolchain Recommendations

Read this Gartner Research Note and discover how your IT organization can automate and optimize DevOps processes using a toolchain architecture.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Cisco vWLC DHCP issues 36 61
Sharing same loopback address on different switches 1 48
Cisco Aironet 1140: setting up basic SSID 12 35
decoding the error message TEI_ASSIGNED 8 40
This article will cover setting up redundant ISPs for outbound connectivity on an ASA 5510 (although the same should work on the 5520s and up as well).  It’s important to note that this covers outbound connectivity only.  The ASA does not have built…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question