ZBF and DNS?
My 887 router will be a DNS server, I have ZBF. I have to open the port to allow traffic from the DNS server.
Jun 14 18:23:50.438: %FW-6-DROP_PKT: Dropping udp session 184.108.40.206:53 172.16.1.23:51872 on zone-pair OUTSIDE-TO-SELF class class-default und in policy-map with ip ident 0
I created an ACL and included it in a class map with 'pass'. It did not work. It worked when I opened ALL udp from this IP?
Extended IP access list DNS
10 permit udp host 220.127.116.11 any eq domain
20 permit udp host 18.104.22.168 any eq domain
30 permit udp host 22.214.171.124 any (7 matches)
<strong>Why is line 10 not working?</strong>