[j-nsp] SRX3400: DNS ALG on 10.2R1

Scott T. Cameron routehero at gmail.com
Thu Aug 12 13:41:29 EDT 2010


Hello,

I just had a very unusual production outage.

All traffic was flowing through the SRX3400 (in chassis cluster mode) no
problem.

Suddenly, DNS started to fail.  Was not passing through the firewall at all
-- all other traffic was.

The resolution was to disable the DNS ALG.

Nothing interesting in the flow log.

Anyone seen this?  Tips?  Tricks?  ALGs are evil?

Scott


More information about the juniper-nsp mailing list