11-5
Cisco ASA Series Firewall ASDM Configuration Guide
Chapter11 Configuring Inspection of Basic Internet Protocols
DNS Inspection
Detailed Steps—Filtering
Step1 Click the Filtering tab.
Step2 Global Settings: Drop packets that exceed specified maximum length (global)—Sets the maximum
DNS message length, from 512 to 65535 bytes.
Step3 Server Settings: Drop packets that exceed specified maximum length and Drop packets sent to
server that exceed length indicated by the RR—Sets the maximum server DNS message length, from
512 to 65535 bytes, or sets the maximum length to the value in the Resource Record. If you enable both
settings, the lower value is used.
Step4 Client Settings: Drop packets that exceed specified maximum length and Drop packets sent to server
that exceed length indicated by the RR—Sets the maximum client DNS message length, from 512 to
65535 bytes, or sets the maximum length to the value in the Resource Record. If you enable both settings,
the lower value is used.
Detailed Steps—Mismatch Rate
Step1 Click the Mismatch Rate tab.