<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks so much. Turns out I in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005743#M1015830</link>
    <description>&lt;P&gt;Thanks so much. Turns out I had to reboot the ASA before the DNS resolution started working after the updates to DNS. I am now able to down load updates.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Again Thanks for your help&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2017 14:52:27 GMT</pubDate>
    <dc:creator>jzkkn5</dc:creator>
    <dc:date>2017-04-27T14:52:27Z</dc:date>
    <item>
      <title>ASA 5506X with Firepower Not resolving DNS</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005737#M1015809</link>
      <description>&lt;P&gt;I just installed the ASA 5506X with firepower&lt;/P&gt;
&lt;P&gt;ASA Ver 9.6&lt;/P&gt;
&lt;P&gt;Firepower ver 5.4.1-211&lt;/P&gt;
&lt;P&gt;ASDM 7.6&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I used the setup wiz in the ASDM to configure interfaces and Firepower management interface. All seem to work well and I have firepower up and running with IPS and other firepower policy running. I have one big issue however. The firepower module did not get a DNS server configured and there is no place in ASDM to configure a DNS. The results is that updates are not working as it can't resolve anything. I looked at the resolv.conf file in the firepower console and it is empty. I was going to add a nameserver entry but when I ran VI the keyboard mappings were not what I expected and so I quit with no save. Can someone help me to figure out how to configure DNS for the firepower module software?&lt;/P&gt;
&lt;P&gt;I only have the one firewall and so I am managing it with ASDM and I do not have a management center VM running nor do I have the resource to spin one up.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005737#M1015809</guid>
      <dc:creator>jzkkn5</dc:creator>
      <dc:date>2019-03-12T13:22:29Z</dc:date>
    </item>
    <item>
      <title>You should be able to log</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005738#M1015810</link>
      <description>&lt;P&gt;You should be able to log into the firepower module console prompt and add a DNS server there using the command "configure network dns servers" as shown below.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That will modify the necessary Linux bits behind the scenes.&lt;/P&gt;
&lt;PRE class="prettyprint" style="padding-left: 30px;"&gt;Cisco Fire Linux OS v6.2.0 (build 42)&lt;BR /&gt;Cisco ASA5525 v6.2.0 (build 362)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; configure network&lt;BR /&gt;&lt;BR /&gt;dns Configure DNS&lt;BR /&gt;hostname Set the hostname&lt;BR /&gt;http-proxy Configure HTTP Proxy settings&lt;BR /&gt;http-proxy-disable Disable HTTP Proxy settings&lt;BR /&gt;ipv4 Configure IPv4 networking&lt;BR /&gt;ipv6 Configure IPv6 networking&lt;BR /&gt;management-interface Change to Management Port Configuration Mode&lt;BR /&gt;management-port Change TCP port for management&lt;BR /&gt;static-routes Change to Static Route Configuration Mode&lt;BR /&gt;&lt;BR /&gt;&amp;gt; configure network dns&lt;BR /&gt;&lt;BR /&gt;searchdomains Configure DNS search domains&lt;BR /&gt;servers Configure DNS servers&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;configure network dns servers&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;configure network dns servers dnslist ...&lt;BR /&gt; Configure DNS servers&lt;BR /&gt;&lt;BR /&gt;dnslist ... Comma-separated list of DNS servers&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&lt;/PRE&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 07:08:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005738#M1015810</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-27T07:08:54Z</dc:date>
    </item>
    <item>
      <title>Thanks that was very helpful.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005739#M1015811</link>
      <description>&lt;P&gt;Thanks that was very helpful. I now show DNS servers in the resolv.conf and nslookup resolves now. I still am not getting updates however. When I go to updates in the ASA Firepower configuration and pick the rules tab for example then pick "Download new rule update from support site I get this error&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Error&lt;BR /&gt;Connectivity problems. Unable to download rules.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 11:11:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005739#M1015811</guid>
      <dc:creator>jzkkn5</dc:creator>
      <dc:date>2017-04-27T11:11:29Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005740#M1015814</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;Is the FirePOWER module address able to reach the Internet?&lt;/P&gt;
&lt;P&gt;You need that &amp;nbsp;- https connectivity and a NAT rule at a minumum.&lt;/P&gt;
&lt;P&gt;If you have any proxy server, the module address must be exempted from that.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 11:31:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005740#M1015814</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-27T11:31:41Z</dc:date>
    </item>
    <item>
      <title>My setup is as follows</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005741#M1015818</link>
      <description>&lt;P&gt;My setup is as follows&lt;/P&gt;
&lt;P&gt;Outside SL 0 is connected to ISP&lt;/P&gt;
&lt;P&gt;Inside SL 100 is 192.168.10.2 and Firpower module is 192.168.10.4 using 192.168.10.2 as default GW&lt;/P&gt;
&lt;P&gt;I also have a DMZ SL 50 with 192.168.15.0/24&lt;/P&gt;
&lt;P&gt;All networks are NATing out and clients on both inside and DMZ browse to internet just fine. I have both inside and firepower management interfaces plugged into the same Layer 2 switch on the same VLAN. It should be able to communicate as far as I can see on this configuration.&lt;/P&gt;
&lt;P&gt;Thanks again for your time.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 12:06:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005741#M1015818</guid>
      <dc:creator>jzkkn5</dc:creator>
      <dc:date>2017-04-27T12:06:34Z</dc:date>
    </item>
    <item>
      <title>Yes that does sound correct</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005742#M1015822</link>
      <description>&lt;P&gt;Yes that does sound correct and straightforward.&lt;/P&gt;
&lt;P&gt;There is a more detailed troubleshooting technote here:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118791-technote-firesight-00.html&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The document is written for FirePOWER Management center but would apply to a FirePOWER module itself as well as in your case.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;In short, they suggest some command line checks.&lt;/P&gt;
&lt;P&gt;The key check is:&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;STRONG&gt;sudo openssl s_client -connect support.sourcefire.com:443&lt;BR /&gt;GET /&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;You will need to switch to expert mode on your module to run Linux commands.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 12:32:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005742#M1015822</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-27T12:32:12Z</dc:date>
    </item>
    <item>
      <title>Thanks so much. Turns out I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005743#M1015830</link>
      <description>&lt;P&gt;Thanks so much. Turns out I had to reboot the ASA before the DNS resolution started working after the updates to DNS. I am now able to down load updates.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Again Thanks for your help&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 14:52:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005743#M1015830</guid>
      <dc:creator>jzkkn5</dc:creator>
      <dc:date>2017-04-27T14:52:27Z</dc:date>
    </item>
    <item>
      <title>Oh that's right. Sorry I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005744#M1015837</link>
      <description>&lt;P&gt;Oh that's right. Sorry I neglected to mention that.&lt;/P&gt;
&lt;P&gt;There is a command to restart the resolver daemon that allows you do make that change less disruptively.&lt;/P&gt;
&lt;P&gt;Drop into expert mode and then run the following command:&lt;/P&gt;
&lt;PRE class="prettyprint prettyprinted"&gt;&lt;SPAN&gt;&lt;SPAN class="str"&gt;/etc/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;rc&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;d&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;init&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;d&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pun"&gt;/&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN class="pln"&gt;nscd restart&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 27 Apr 2017 16:31:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506x-with-firepower-not-resolving-dns/m-p/3005744#M1015837</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-27T16:31:25Z</dc:date>
    </item>
  </channel>
</rss>

