Serious DNS issues after installing a Cisco RV325 gateway

Comments

3 comments

  • Avatar
    rotblitz (Edited )

    What did Cisco Support say?  I know, OpenDNS is Cisco too, but a totally different area.

    Btw, the first group of log messages are DNS replies from OpenDNS on your DNS queries to OpenDNS.  They do not seem to be blocked, just reported.

    The second log entry is an ICMP (ping, tracert) packet to OpenDNS being blocked outbound.  Could also be the related echo packet being blocked inbound, as seen in the square brackets.

    0
    Comment actions Permalink
  • Avatar
    vulogiccl2

    The "other" Cisco hasn't replied yet.

    That's what's so confusing about these logs ... That blocked "outbound" ping entry seems to be reporting bidirectional traffic. There is no way that I can find to block outbound ICMP requests on this Netgear modem.

    As for the other entries: Those entries only show up in the Netgear modem's log when DNS requests start to fail. When I start to see yellow DNS query requests pile up on the DNSQuerySniffer screen, the modem logs start to pile up with matching time stamps. Whenever DNS queries are working, the modem remains silent.

    And if I were to check the logs in detail, I would probably find one of those blocked ICMP entries just before a stack of "PortScanLo" entries. (The modem is also legitimately blocking other traffic and logging it, so there's a lot more scattered in that log than just the entries concerning OpenDNS.)

    Do you have any idea what "PortScanLo" means? Is the "Lo" a truncated "Log"? Who would be doing a port scan in this case?

    Thanks for your reply!
    CL

     

    0
    Comment actions Permalink
  • Avatar
    rotblitz

    Sorry, I think I am not able to help with this. This is a pure router problem, and I do not have this router.

    0
    Comment actions Permalink

Please sign in to leave a comment.