<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX and DNS Forwarding in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609863#M1023881</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vibhor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please ignore my last update. The command you have posted is working! (I just did not test it correctly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vadim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Mar 2007 07:09:40 GMT</pubDate>
    <dc:creator>vsclear</dc:creator>
    <dc:date>2007-03-08T07:09:40Z</dc:date>
    <item>
      <title>PIX and DNS Forwarding</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609858#M1023876</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is it possible to forward DNS requests addressed to a PIX inside interface out to ISP's DNS?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609858#M1023876</guid>
      <dc:creator>vsclear</dc:creator>
      <dc:date>2019-03-11T09:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and DNS Forwarding</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609859#M1023877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you mean to say that internal hosts are using PIX inside interface as a DNS server IP? Or is it that PIX is acting as a DHCP server for the internal clients?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Mar 2007 16:26:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609859#M1023877</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-07T16:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and DNS Forwarding</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609860#M1023878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I meant that internal PCs use PIX inside interface as a DNS server. In this case, the PIX should forward DNS requests to ISP's &lt;/P&gt;&lt;P&gt;DNS. Question: Can PIX do it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 00:48:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609860#M1023878</guid>
      <dc:creator>vsclear</dc:creator>
      <dc:date>2007-03-08T00:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and DNS Forwarding</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609861#M1023879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Officially, PIX is not designed to do so. But we can make it work by using following commands-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Suppose that ISPs DNS server IP is 4.2.2.2 and PIX inside interface IP is 1.1.1.1. In this case, try following commands:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (outside,inside) udp interface 53 4.2.2.2 53&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now all the UDP port 53 requests, which are DNS requests, when directed to PIX's inside interface IP, PIX will redirect them to udp (53) on the ISP's DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this works for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 00:54:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609861#M1023879</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-03-08T00:54:13Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and DNS Forwarding</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609862#M1023880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vibhor,&lt;/P&gt;&lt;P&gt;Thank you for your help. I have just tried that command in small lab environment:&lt;/P&gt;&lt;P&gt;PC (192.168.2.2/29) --&amp;gt; PIX_inside (192.168.2.1/29) - PIX_outside(192.168.1.2/24) --&amp;gt; 2610_e0/0 (192.168.1.1/24)&lt;/P&gt;&lt;P&gt;I don't have an outside DNS server in the lab; therefore, to test it:&lt;/P&gt;&lt;P&gt;- 2610: &lt;/P&gt;&lt;P&gt;ip http server&lt;/P&gt;&lt;P&gt;ip http port 53&lt;/P&gt;&lt;P&gt;debug ip tcp packet&lt;/P&gt;&lt;P&gt;- PIX: &lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;static (outside, inside) tpc interface 80 192.168.1.1 53&lt;/P&gt;&lt;P&gt;- PC&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://192.168.1.1" target="_blank"&gt;http://192.168.1.1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Debug output on 2610 indicates that http traffic reaches the router; howerver, PIX does not translate port from 80 to 53:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;00:21:41: tcp0: I LISTEN 192.168.1.2:1034 192.168.1.1:80 seq 2926118896&lt;/P&gt;&lt;P&gt;        OPTS 8 SYN  WIN 64512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea how to check what is going on the PIX?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Vadim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 03:34:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609862#M1023880</guid>
      <dc:creator>vsclear</dc:creator>
      <dc:date>2007-03-08T03:34:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX and DNS Forwarding</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609863#M1023881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vibhor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please ignore my last update. The command you have posted is working! (I just did not test it correctly)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you so much!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vadim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2007 07:09:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-forwarding/m-p/609863#M1023881</guid>
      <dc:creator>vsclear</dc:creator>
      <dc:date>2007-03-08T07:09:40Z</dc:date>
    </item>
  </channel>
</rss>

