Posted on 2015-01-26
I have the following access-list on a Layer 3 switch to allow access to OpenDNS for a specific group of PCs.
When I test by doing a DNS lookup, it fails. I can see the number of hits going out increasing but the replies do not get any hits.
I did a Wireshark capture from our Firewall to make sure it was not the cause of the problem by denying the reply traffic back in but it does allow it and then gets dropped by the switch (I am guessing) which sends an ICMP unreachable back to OpenDNS. Do I can see the DNS query to OpenDNS, the reply from open DNS and then the ICMP unreachable from the switch which makes me think the switch is the one dropping the returned traffic.
Can anyone see anything wrong with the following access-list that might be causing the traffic to be blocked?
Extended IP access list PCL_Access_In
20 permit udp 192.168.95.0 0.0.0.255 host 220.127.116.11 eq domain log (473 matches)
30 permit udp 192.168.95.0 0.0.0.255 host 18.104.22.168 eq domain log (648 matches)
Extended IP access list PCL_Access_Out
20 permit udp host 22.214.171.124 192.168.95.0 0.0.0.255 eq domain log
30 permit udp host 126.96.36.199 192.168.95.0 0.0.0.255 eq domain log
ip address 192.168.95.1 255.255.255.0
ip access-group PCL_Access_In in
ip access-group PCL_Access_Out out
Thanks in advance