• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 196
  • Last Modified:

OpenDNS Access-list

I have the following access-list on a Layer 3 switch to allow access to OpenDNS for a specific group of PCs.
When I test by doing a DNS lookup, it fails. I can see the number of hits going out increasing but the replies do not get any hits.
I did a Wireshark capture from our Firewall to make sure it was not the cause of the problem by denying the reply traffic back in but it does allow it and then gets dropped by the switch (I am guessing) which sends an ICMP unreachable back to OpenDNS. Do I can see the DNS query to OpenDNS, the reply from open DNS and then the ICMP unreachable from the switch which makes me think the switch is the one dropping the returned traffic.

Can anyone see anything wrong with the following access-list that might be causing the traffic to be blocked?

Extended IP access list PCL_Access_In
    20 permit udp 192.168.95.0 0.0.0.255 host 208.67.220.220 eq domain log (473 matches)
    30 permit udp 192.168.95.0 0.0.0.255 host 208.67.222.222 eq domain log (648 matches)
Extended IP access list PCL_Access_Out
    20 permit udp host 208.67.220.220 192.168.95.0 0.0.0.255 eq domain log
    30 permit udp host 208.67.222.222 192.168.95.0 0.0.0.255 eq domain log
      
interface Vlan10
 description PCL_Machines
 ip address 192.168.95.1 255.255.255.0
 ip access-group PCL_Access_In in
 ip access-group PCL_Access_Out out


Thanks in advance
0
troubleshooter141
Asked:
troubleshooter141
  • 2
1 Solution
 
Craig BeckCommented:
Just use the in direction when applying the ACL to the SVI to see if that helps - don't use the out ACL.
0
 
Feroz AhmedSenior Network EngineerCommented:
Hi,

Can you have a look at the Cabling on Swtich end connecting to Specific Hosts .I hope there is Cross Cabling done in between Switch and Hosts that is the reason you are getting Destination Host Unreachable at Firewall end.Or you can just change the switch and look for the Ping Status .
0
 
Craig BeckCommented:
^^^ ??
0
 
troubleshooter141Author Commented:
Thanks CraigBeck, removing the access-list from the Out direction fixed the issue.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

Easily Design & Build Your Next Website

Squarespace’s all-in-one platform gives you everything you need to express yourself creatively online, whether it is with a domain, website, or online store. Get started with your free trial today, and when ready, take 10% off your first purchase with offer code 'EXPERTS'.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now