I have an ASL 3.2 Firewall with 5 interfaces (4 DMZs and 1 external) and DNS Proxy enabled. For a few day now I see in the packet filter log that ASL seems to drop DNS request from my external interface (!) to external (!!) servers which are by connection tracking are identified as DNS servers. It does not seem to block request to servers entered as forwarders, but these drops bring my logfiles to enormous size. I tried to set a rule for allowing DNS requests from the external interface to any, but this didn't help.
This thread was automatically locked due to age.