Cisco ASA Audit Event: 106007

106007: Deny inbound UDP due to DNS

Cisco ASA is a security device that provides the combined capabilities of a firewall, an antivirus, and an intrusion prevention system. It also facilitates virtual private network (VPN) connections. It helps to detect threats and stop attacks before they spread through the network.

Message: %ASA-2-106007: Deny inbound UDP from outside_address/outside_port to inside_address/inside_port due to DNS {Response|Query}.

Event 106007 is generated when a UDP packet containing a DNS query or response is denied. The message contains: 

  • The inside IP address and port number.
  • The outside IP address and port number.
  • Information on whether the UDP packet contained a DNS query or response.

How could you resolve this situation?

If the inside port number is 53, the inside host probably is set up as a caching name server. Add an access-list command statement to permit traffic on UDP port 53 and a translation entry for the inside host. If the outside port number is 53, a DNS server was probably too slow to respond and so the query was answered by another server.

Cisco ASA Auditing Tool

EventLog Analyzer is a comprehensive log management software with which you can centrally collect, analyze, and manage logs from all the different log sources in your network. You also get reports and alerts on your network security, making it a power-packed IT security tool.