user manual

11-5
Cisco ASA Series Firewall ASDM Configuration Guide
Chapter 11 Configuring Inspection of Basic Internet Protocols
DNS Inspection
Detailed Steps—Filtering
Step 1 Click the Filtering tab.
Step 2 Global Settings: Drop packets that exceed specified maximum length (global)—Sets the maximum
DNS message length, from 512 to 65535 bytes.
Step 3 Server Settings: Drop packets that exceed specified maximum length and Drop packets sent to
server that exceed length indicated by the RR—Sets the maximum server DNS message length, from
512 to 65535 bytes, or sets the maximum length to the value in the Resource Record. If you enable both
settings, the lower value is used.
Step 4 Client Settings: Drop packets that exceed specified maximum length and Drop packets sent to server
that exceed length indicated by the RR—Sets the maximum client DNS message length, from 512 to
65535 bytes, or sets the maximum length to the value in the Resource Record. If you enable both settings,
the lower value is used.
Detailed Steps—Mismatch Rate
Step 1 Click the Mismatch Rate tab.