Diagnostic help part 2

Tony Finch dot at dotat.at
Wed Oct 1 19:45:23 UTC 2014

Mike Hoskins (michoski) <michoski at cisco.com> wrote:
> This isn't even specific to DNS...for example, there was a time when just
> "turning on what sounds good" for cisco, netscreen and even checkpoint
> would break other things like ESMTP.

You mean Cisco have fixed the grossly damaging bugs in the PIX/ASA
application layer filters?

My favourite one is its insufficient cross-packet state, and habit of
XXXXing out commands it does not understand, which leads to it XXXXing out
RCPT commands that happen to be split between packets, leading to things
like people being unsubscribed from mailing lists.

(Sorry for straying off topic. I have less experience of Cisco PIX/ASA
breaking DNS than of them breaking SMTP.)

