timeout for query?

Pavel Urban urbanp at mlp.cz
Thu Jul 21 05:08:42 UTC 2005


Hello,

we're having problem with PIX firewalls closing UDP 'connection' after 
30 seconds. Is there a limit to which a response for query must be sent?

sample: (10.7.9.10 is our DNS, doing recursive query somewhere outside. 
It takes some time, so the 'connection' to client 83.208.117.4 is closed 
prematurely)

04:00:16 Teardown UDP connection 404532028 for outside:83.208.117.4/2200 
to dmz:10.7.9.10/53 duration 0:00:30 bytes 276
04:00:16 Deny udp src dmz:10.7.9.10/53 dst outside:83.208.117.4/2200 by 
access-group "acl_dmz"
04:00:16 Deny udp src dmz:10.7.9.10/53 dst outside:83.208.117.4/2200 by 
access-group "acl_dmz"
04:00:16 Deny udp src dmz:10.7.9.10/53 dst outside:83.208.117.4/2200 by 
access-group "acl_dmz"
04:00:16 Deny udp src dmz:10.7.9.10/53 dst outside:83.208.117.4/2200 by 
access-group "acl_dmz"

Thanks!

-- 
***********************************************************************
Pavel Urban (pavel.urban at imaginet.cz)
IOL system disaster
Internet OnLine, owned by Cesky Telecom, a.s. (www.ct.cz)
***********************************************************************
    Vegetables should not operate electronic equipment.
           Computer Stupidities, http://rinkworks.com/stupid/
***********************************************************************



More information about the bind-users mailing list