[nsp] Pix 6.3(3) and UDP issues

Virgil virgil at webcentral.com
Thu Sep 25 19:47:37 EDT 2003


> Disabling dns fixup fixed it for us.

BIND9 has a slightly different on-by-default query type that 
caused some Checkpoint firewalls to trigger drops due to DNS
protocol inspection.  It was dropping the messages saying
"drop back to the old method please"

Maybe the PIX fixup code is doing something similar ??

Virgil



More information about the cisco-nsp mailing list