drop tcp any any -> any !53 (msg:"DNS TCP query custom port"; flow:to_server; app-layer-protocol:dns; sid:2271015; rev:1;)drop udp any any -> any !53 (msg:"DNS UDP query custom port"; flow:to_server; app-layer-protocol:dns; sid:2271017; rev:1;)
drop udp $HOME_NET any -> $EXTERNAL_NET !53 (msg:"Admin-Rule !53 dns Query *.* domain"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|01|."; fast_pattern; distance:0; classtype:bad-unknown; sid:9900202; rev:2;)
drop dns $HOME_NET any -> $EXTERNAL_NET !53 (msg:"Admin-Rule2 !53 dns Query"; dns_query; sid:9900204; rev:2;)
drop dns $HOME_NET any -> $EXTERNAL_NET !53 (msg:"Admin-Rule2 !53 dns Query"; dns_query; content:"google"; nocase; sid:9900204; rev:2;)
pass udp $EXTERNAL_NET [53,123] -> $HOME_NET any (msg:"time-dns"; sid:9900008; rev:1;)drop udp $EXTERNAL_NET [1:65535] -> $HOME_NET [1:65535] (msg:"Golden Rule UDP"; classtype:bad-unknown; sid:9900013; rev:1;)
pass udp [8.8.8.8,8.8.4.4] [53,123] -> $HOME_NET any (msg:"DNS OK"; sid:9900009; rev:1;)