<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: resolving URL's from DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683542#M1024387</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I've run nslookup. When my dns is set for the outside I can resolve any url. when my dns is set for the inside nslookup can't find url (which makes sense).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Mar 2007 19:50:18 GMT</pubDate>
    <dc:creator>boondocker</dc:creator>
    <dc:date>2007-03-02T19:50:18Z</dc:date>
    <item>
      <title>resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683525#M1024368</link>
      <description>&lt;P&gt;I have a pix firewall (515e) and a windows computer on the DMZ that has it's default DNS pointing to a server on the inside allowing connection to key computers on the inside. I need to connect to the internet from this DMZ computer as well on the outside but unfortunately I can't resolve any URL's. Any ideas? thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 09:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683525#M1024368</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2019-03-11T09:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683526#M1024369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Either use external dns for dmz machines or write an acl allowing dns traffic from dmz to inside dns servers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2007 21:35:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683526#M1024369</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-01T21:35:11Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683527#M1024371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If I use an external dns (set the computers default dns to point to the outside dns server), I will loose dns resolution to the inside computers. I need to resolve dns both ways.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2007 22:15:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683527#M1024371</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-01T22:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683528#M1024373</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How many of the key systems does the server in the DMZ need to talk to. Hopefully not too many &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is a few key systems you could use the local hosts file for these servers and then point your windows server to DNS servers on the Internet for resolution of all other servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not a pretty solution and it depends on how many servers you need to talk to on the inside. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2007 22:30:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683528#M1024373</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-01T22:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683529#M1024374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the replies...unfortunately using hosts files still doesn't work...seems to get confused and net result is that the focus appears to be on the gateway setting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 18:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683529#M1024374</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-02T18:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683530#M1024375</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Host files get checked before resolving to dns server. What do you mean by "seems to get confused and net result is that the focus appears to be on the gateway setting."&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 18:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683530#M1024375</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-02T18:42:08Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683531#M1024376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When I point my dmz computers default gateway to the outside DNS, internet access works fine. With hosts file setup with all my inside hosts I'm having problems connecting to my DC (which is on the inside). When I change my dmz computers default gateway to the inside DNS and disable the hosts file, i cannot connect to the outside internet but I have full access to the DC. It's sounds pretty straight forward and I figured it would work ...not sure if I'm doing something wrong here.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683531#M1024376</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-02T19:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683532#M1024377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By "default gateway" I assume you mean "default dns"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:15:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683532#M1024377</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-02T19:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683533#M1024378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes...typo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:19:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683533#M1024378</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-02T19:19:36Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683534#M1024379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what does your access-list look like that is applied "in interface dmz"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683534#M1024379</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-02T19:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683535#M1024380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My Inside security level = 100&lt;/P&gt;&lt;P&gt;My DMZ security level = 100&lt;/P&gt;&lt;P&gt;My Outside security level = 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit tcp any any eq www &lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any any eq sqlnet &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any any eq 522 &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any any eq 1731 &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any any eq 1503 &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any any eq ldap &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any any eq h323 &lt;/P&gt;&lt;P&gt;access-list OUTSIDE_access_in extended permit tcp any any eq 3389 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:32:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683535#M1024380</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-02T19:32:27Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683536#M1024381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to allow dmz machines to access inside machines, it has to be permitted in your DMZ_access-in acl. For instance, dns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list DMZ_access_in extended permit udp any host &lt;INSIDE_DNS_SERVER_IP&gt; eq 53&lt;/INSIDE_DNS_SERVER_IP&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:34:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683536#M1024381</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-02T19:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683537#M1024382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does my access level of 100 for both dmz and inside not allow free flow of traffic without acl?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:37:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683537#M1024382</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-02T19:37:52Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683538#M1024383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;oh, i skimmed over that. It depends on what code your pix is, 7 will allow it, 6 will not.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:40:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683538#M1024383</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-02T19:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683539#M1024384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;...also, when I'm setup this way I can still connect to all inside computers including my DNS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:40:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683539#M1024384</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-02T19:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683540#M1024385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;...I'm at 7&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683540#M1024385</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-02T19:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683541#M1024386</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So, everything works fine but you can't get to the internet? Are these windows machines? Do you know how to do an nslookup?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683541#M1024386</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-02T19:46:27Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683542#M1024387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I've run nslookup. When my dns is set for the outside I can resolve any url. when my dns is set for the inside nslookup can't find url (which makes sense).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683542#M1024387</guid>
      <dc:creator>boondocker</dc:creator>
      <dc:date>2007-03-02T19:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683543#M1024388</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why would that make sense, you are pointing to an inside dns server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2007 19:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683543#M1024388</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-03-02T19:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: resolving URL's from DMZ</title>
      <link>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683544#M1024389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A couple of things.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While not nessicarily secure (as the above list is not) you can add this and it should fix your problem...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit tcp any any eq domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list dmz_access_in extended permit udp any any eq domain&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Mar 2007 17:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/resolving-url-s-from-dmz/m-p/683544#M1024389</guid>
      <dc:creator>jspringfield</dc:creator>
      <dc:date>2007-03-16T17:44:51Z</dc:date>
    </item>
  </channel>
</rss>

