Hello everyone,
I'm having an issue that I'm not sure how to get rid off.
We have a branch office that is connected via host-to-host VPN. On that branch office, we have a couple of Windows AD servers that also have the DNS role installed.
The trouble is that the server at the remote branch is prevented by astaro from requesting a full zone transfer with the following altert:
Message........: DNS TCP inverse query overflow
Details........: Snort - the de facto standard for intrusion detection/prevention
Time...........: 2009:01:12-16:15:25
Packet dropped.: yes
Priority.......: 1 (high)
Classification.: Attempted Administrator Privilege Gain IP protocol....: 6 (TCP)
I have disabled that rule in the firewall, but I'd like to keep it active for the "regular" external zone.
I tried to add the server in the "DNS servers" in the "advanced" tab of the IPS configuration page but to no avail.
Is there a way to disable that specific alter and rule just for a few specific hosts ?
Thank you
This thread was automatically locked due to age.