This article provides information how to allow the EDNS queries pass through the SRX firewall, with DNS ALG enabled.
To allow EDNS queries to pass through the SRX firewall, with DNS ALG enabled, run the following command from the configuration mode:
user# set security alg dns maximum-message-length 8192
Note : The above setting is valid only from 10.1 or later, to 10.2. From 10.2 onwards, the limitation of 512 bytes will be removed; so the above command will no longer be required from 10.2 or later.