DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Blocking inbound DNS traffic

More
05 Nov 2019 09:13 #1 by haywardi
Blocking inbound DNS traffic was created by haywardi
Hi,

I am looking for some advise.

In my firewall (2860 & 2862 running latest firmware) I have set all WAN-> LAN traffic on port 53 to BLOCK to prevent any DNS traffic entering my network (I do not run any DNS servers internally).

However, in Syslog I see the following message [Pass][Unknown DNS query type][Hostname=]

What setting have I got wrong in my firewall?

Thank in advance
Iain

Iain

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
05 Nov 2019 13:36 #2 by hornbyp
Replied by hornbyp on topic Re: Blocking inbound DNS traffic
Have you set the rule to be both TCP and UDP?

Please Log in or Create an account to join the conversation.

More
05 Nov 2019 13:38 #3 by haywardi
Replied by haywardi on topic Re: Blocking inbound DNS traffic
Yes :-)

Iain

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
05 Nov 2019 14:18 #4 by hornbyp
Replied by hornbyp on topic Re: Blocking inbound DNS traffic
My equivalent rule uses a 'Service Object' (though that in itself shouldn't make a difference).

The Object is defined:
Code:
Name DNS Protocol TCP/UDP Source Port = 1 ~ 65535 Destination Port = 53 ~ 53



If that helps..

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
05 Nov 2019 14:44 #5 by hornbyp
Replied by hornbyp on topic Re: Blocking inbound DNS traffic
I just had a thought...

Could this be outbound DNS?

i.e. Are you using the 2860/2862 as a caching DNS server for the LAN?

Please Log in or Create an account to join the conversation.

More
05 Nov 2019 15:13 #6 by haywardi
Replied by haywardi on topic Re: Blocking inbound DNS traffic
OK, I have set up a "Service Object" and lets see if it makes a difference.

Now I had't considered an outbound DNS, let alone the routers operating as a caching server, I have not set this up so may be a defasult. Do you know how to check?

Iain

Iain

Please Log in or Create an account to join the conversation.