ScreenOS Firewalls (NOT SRX)
Reply
Contributor
BSOD
Posts: 14
Registered: ‎01-13-2011
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.


sinu42 wrote:

Any news from JTAC?


Still attempting to proove there is a problem...

 

 

adgwytc:

Do you use NSM to deploy policies?  At least according to NSM, there are no policy differnces between the ScreenOS 5.4 and 6.3 devices.

Super Contributor
Spud
Posts: 135
Registered: ‎02-08-2008
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.

I noticed that the DNS queries in your snoop are coming from the IPs 172.22.227.36 and .34, but they don't appear to come from the firewall itself (.31), so these packets may be coming from your LAN hosts.

What happens if you try to set the source interface in the DNS config to vlan1?

Contributor
BSOD
Posts: 14
Registered: ‎01-13-2011
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.

Changing the DNS src-interface to vlan1 doesn't help.

 

Actually, rebooting the firewall temporarily fixes the problem.  A co-worker rebooted it almost 2 days ago and the problem vanished.  No policy changes have been made.  Now I wait again for the problem to surface...

Visitor
sinu42
Posts: 3
Registered: ‎02-07-2009
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.

I am facing a similiar isssue. From time to time no dns resolution is possible "Connection refused by the DNS server". But I f I change only one dns servers ip address (out of three) and apply the changes, it is working again.

I am running 6.3R10

Contributor
BSOD
Posts: 14
Registered: ‎01-13-2011
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.

[ Edited ]

Finally, Juniper issued a patch (ssg5ssg20.6.3.0r11-cpb1.0) for this issue which I'm evaluating now.  At this point looks like it can make it into 6.3.0r13.

 

Root Cause per TSE:

if arp task failed to update session outgoing interface when receive arp responce, box will keep dropping packets match this session. Solution: in this scenario, we need invalid this session and let create a new session again.

Trusted Expert
sarab
Posts: 370
Registered: ‎05-12-2012
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.

Great, al last we have solution for this issue :smileyhappy: Please evaluate this patch and let the Forum know how it worked.
Contributor
BSOD
Posts: 14
Registered: ‎01-13-2011
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.

Received confirmation from enginnering that this problem (JUNOS Defect: 797786), will be fixed in 6.3.0r13.

Contributor
TRK-NKA
Posts: 192
Registered: ‎06-17-2008
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.

So did 6.3.0r13 solve the issue ?

 


Best Regards

Tom Roholm
JNCIS-ENT, FWV, SEC, SA, WLAN
Contributor
BSOD
Posts: 14
Registered: ‎01-13-2011

Re: ScreenOS 6.3 - Connection refused by the DNS server.


TRK-NKA wrote:

So did 6.3.0r13 solve the issue ?

 


Yes, it has.

 

I noticed the JunOS defect # wasnt listed in the r13 release notes. Called JTAC back and had them validate it truly was included, but missed the release notes.

Visitor
emeitner
Posts: 5
Registered: ‎04-15-2014
0

Re: ScreenOS 6.3 - Connection refused by the DNS server.

I have three SSG5 firewalls running 6.3.0r16a-dfj1.0 that are also having this problem. Clearing the sessions to the DNS servers solves the problem. Anybody else having this with 6.3.0r16+?
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.