I've been struggling with the same issue, a customers FTG60c was getting flooded with DNS queries and it was maxing out the customers internet circuit. Finally, after running DNS recursion tests against the customers IP block, we noticed the FTG's WAN interface had port 53 open, though there were no visable policies to allowing this port through the firewall. Seemingly DNS was forwarding through to the WAN to the FTG's internal DNS server... To correct this, we enabled the DNS server feature on the FTG and disabled DNS recursion on the affected WAN interface which effectively closed 53. Not sure how this got turned on in the first place, but hope this helps someone else..
-Chris
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
