Symptom
EDNS request packets are changed
Conditions
NBAR protocol discovery is enabled
Workaround
Disable DNS guard:
no ip nbar classification dns learning guard
Further Problem Description
For EDNS (Extended DNS) request packets with additional records, the DNS header AR (additional record count) field is changed from 1 to 0, resulting in no response from the DNS server for these requests.
To work around this issue, disable DNS guard.