Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» DHCP and DNS» EDNS0 Support
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: EDNS0 Support  (Read 1009 times)
0 Members and 1 Guest are viewing this topic.
beer
Newbie
*
Offline Offline

Posts: 18


View Profile
« on: April 16, 2012, 03:05:52 pm »

My DC (MS W2K8R2) which is running DNS is throwing a lot of 5501 events.

The DNS server encountered a bad packet from 96.7.49.193.  Packet processing leads beyond packet length. The event data contains the DNS packet.

The MS KB says this is the problem with the router (pfsense):

This issue occurs because of the Extension Mechanisms for DNS (EDNS0) functionality that is supported in Windows Server 2003 DNS.

EDNS0 permits the use of larger User Datagram Protocol (UDP) packet sizes. However, some firewall programs may not permit UDP packets that are larger than 512 bytes. As a result, these DNS packets may be blocked by the firewall.


http://support.microsoft.com/kb/832223

Any idea on how to investigate on the router?

Thank you fine folks!

Logged
cmb
Administrator
Hero Member
*****
Offline Offline

Posts: 6055


View Profile WWW
« Reply #1 on: April 17, 2012, 01:29:34 am »

We don't discriminate on packet sizes of any UDP or DNS. By "some firewall programs", what they're specifically referring to there is the old Cisco PIX/ASA default limit of 512 bytes on DNS requests. Almost every PIX config we see has that broken so it's undoubtedly caused numerous issues along those lines. If you're using the DNS forwarder, we default to dnsmasq's default of 4096 for --edns-packet-max, the recommended value per RFC 5625. If your Windows server does its own recursive lookups, there is no limit induced by the firewall.
Logged

pfSense Commercial Support

Paying customers receive support priority and as in depth of assistance as desired through the official commercial support channels at portal.pfsense.org. Forum users receive as much help as time permits.
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.026 seconds with 20 queries.