24-69
Cisco ASDM User Guide
OL-16647-01
Chapter 24 Configuring Application Layer Protocol Inspection
Inspect Map Field Descriptions
Add/Edit DNS Inspect
The Add/Edit DNS Inspect dialog box lets you define the match criterion and value for the DNS inspect
map.
Fields
Single Match—Specifies that the DNS inspect has only one match statement.
Match Type—Specifies whether traffic should match or not match the values.
For example, if No Match is selected on the string “example.com,” then any traffic that contains
“example.com” is excluded from the class map.
Criterion—Specifies which criterion of DNS traffic to match.
Header Flag—Match a DNS flag in the header.
Type—Match a DNS query or resource record type.
Class—Match a DNS query or resource record class.
Question—Match a DNS question.
Resource Record—Match a DNS resource record.
Domain Name—Match a domain name from a DNS query or resource record.
Header Flag Criterion Values—Specifies the value details for DNS header flag match.
Match Option—Specifies either an exact match or match all bits (bit mask match).
Match Value—Specifies to match either the header flag name or the header flag value.
Header Flag Name—Lets you select one or more header flag names to match, including AA
(authoritative answer), QR (query), RA (recursion available), RD (recursion denied), TC
(truncation) flag bits.
Header Flag Value—Lets you enter an arbitrary 16-bit value in hex to match.
Type Criterion Values—Specifies the value details for DNS type match.
DNS Type Field Name—Lists the DNS types to select.
A—IPv4 address
NS—Authoritative name server
CNAME—Canonical name
SOA—Start of a zone of authority
TSIG—Transaction signature
IXFR—Incremental (zone) transfer
AXFR—Full (zone) transfer
DNS Type Field Value—Specifies to match either a DNS type field value or a DNS type field
range.
Value—Lets you enter an arbitrary value between 0 and 65535 to match.
Range—Lets you enter a range match. Both values between 0 and 65535.
Class Criterion Values—Specifies the value details for DNS class match.
DNS Class Field Name—Specifies to match on internet, the DNS class field name.