DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Blocking inbound DNS traffic
- haywardi
- Topic Author
- Offline
- Member
Less
More
- Posts: 187
- Thank yous received: 0
05 Nov 2019 09:13 #95163
by haywardi
Iain
Blocking inbound DNS traffic was created by haywardi
Hi,
I am looking for some advise.
In my firewall (2860 & 2862 running latest firmware) I have set all WAN-> LAN traffic on port 53 to BLOCK to prevent any DNS traffic entering my network (I do not run any DNS servers internally).
However, in Syslog I see the following message [Pass][Unknown DNS query type][Hostname=]
What setting have I got wrong in my firewall?
Thank in advance
Iain
I am looking for some advise.
In my firewall (2860 & 2862 running latest firmware) I have set all WAN-> LAN traffic on port 53 to BLOCK to prevent any DNS traffic entering my network (I do not run any DNS servers internally).
However, in Syslog I see the following message [Pass][Unknown DNS query type][Hostname=]
What setting have I got wrong in my firewall?
Thank in advance
Iain
Iain
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank yous received: 0
05 Nov 2019 13:36 #95166
by hornbyp
Replied by hornbyp on topic Re: Blocking inbound DNS traffic
Have you set the rule to be both TCP and UDP?
Please Log in or Create an account to join the conversation.
- haywardi
- Topic Author
- Offline
- Member
Less
More
- Posts: 187
- Thank yous received: 0
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank yous received: 0
05 Nov 2019 14:18 #95168
by hornbyp
Replied by hornbyp on topic Re: Blocking inbound DNS traffic
My equivalent rule uses a 'Service Object' (though that in itself shouldn't make a difference).
The Object is defined:
If that helps..
The Object is defined:
Code:
Name DNS
Protocol TCP/UDP
Source Port = 1 ~ 65535
Destination Port = 53 ~ 53
If that helps..
Please Log in or Create an account to join the conversation.
- hornbyp
- Offline
- Big Contributor
Less
More
- Posts: 1323
- Thank yous received: 0
05 Nov 2019 14:44 #95169
by hornbyp
Replied by hornbyp on topic Re: Blocking inbound DNS traffic
I just had a thought...
Could this be outbound DNS?
i.e. Are you using the 2860/2862 as a caching DNS server for the LAN?
Could this be outbound
i.e. Are you using the 2860/2862 as a caching DNS server for the LAN?
Please Log in or Create an account to join the conversation.
- haywardi
- Topic Author
- Offline
- Member
Less
More
- Posts: 187
- Thank yous received: 0
05 Nov 2019 15:13 #95170
by haywardi
Iain
Replied by haywardi on topic Re: Blocking inbound DNS traffic
OK, I have set up a "Service Object" and lets see if it makes a difference.
Now I had't considered an outbound DNS, let alone the routers operating as a caching server, I have not set this up so may be a defasult. Do you know how to check?
Iain
Now I had't considered an outbound DNS, let alone the routers operating as a caching server, I have not set this up so may be a defasult. Do you know how to check?
Iain
Iain
Please Log in or Create an account to join the conversation.
Moderators: Chris
Copyright © 2025 DrayTek