On 10/1/2014 3:45 PM, Tony Finch wrote:
> (Sorry for straying off topic. I have less experience of Cisco PIX/ASA
> breaking DNS than of them breaking SMTP.)
I can't resist either..
I specifically remember a PIX that bit me by "helpfully" changing the 
payload of an axfr so that the A records that traveled through the PIX's 
NAT got flipped to the inside RFC-1918 addresses for the servers that 
were behind the NAT as well.

It took a couple rounds of "your sending me the wrong stuff... No I'm 
Not!" until we figured it out.

