<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic EzVPN with DNS forwarding in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ezvpn-with-dns-forwarding/m-p/603269#M1054990</link>
    <description>&lt;P&gt;I use my router itself as a DNS forwarder.  Unfortunately when a domain query is requested on the LAN side, the packet is sourced with the ouside interface IP address which is ouside the EzVPN tunnel and thus the reply does not find it's way back.  Can anybody suggest a way to solve this issue please?  Maybe NATing the source packet for UDP and TCP 53 somhow to traverse the EzVPN tunnel?  PS. "ip domain lookup source-interface..." is not taking effect in this EzVPN case.  Please see my attached router config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EzVPN Clinet - Network Extension (this router 871.. IOS 12.4.9)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EzVPN Server - VPN3030  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 09:01:00 GMT</pubDate>
    <dc:creator>hadbihas</dc:creator>
    <dc:date>2020-02-21T09:01:00Z</dc:date>
    <item>
      <title>EzVPN with DNS forwarding</title>
      <link>https://community.cisco.com/t5/network-security/ezvpn-with-dns-forwarding/m-p/603269#M1054990</link>
      <description>&lt;P&gt;I use my router itself as a DNS forwarder.  Unfortunately when a domain query is requested on the LAN side, the packet is sourced with the ouside interface IP address which is ouside the EzVPN tunnel and thus the reply does not find it's way back.  Can anybody suggest a way to solve this issue please?  Maybe NATing the source packet for UDP and TCP 53 somhow to traverse the EzVPN tunnel?  PS. "ip domain lookup source-interface..." is not taking effect in this EzVPN case.  Please see my attached router config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EzVPN Clinet - Network Extension (this router 871.. IOS 12.4.9)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;EzVPN Server - VPN3030  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 09:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ezvpn-with-dns-forwarding/m-p/603269#M1054990</guid>
      <dc:creator>hadbihas</dc:creator>
      <dc:date>2020-02-21T09:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: EzVPN with DNS forwarding</title>
      <link>https://community.cisco.com/t5/network-security/ezvpn-with-dns-forwarding/m-p/603270#M1054998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Might be you can create an Extended Access List that doesnt allw NATing for DNS query which is TCP/UDP 53 and allowing NATing for the services needed.For more information refer the following URL for creating access list.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/iosswrel/ps5187/products_command_reference_chapter09186a008017d1d4.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/iosswrel/ps5187/products_command_reference_chapter09186a008017d1d4.html&lt;/A&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jul 2006 12:15:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ezvpn-with-dns-forwarding/m-p/603270#M1054998</guid>
      <dc:creator>pradeepde</dc:creator>
      <dc:date>2006-07-05T12:15:03Z</dc:date>
    </item>
    <item>
      <title>Re: EzVPN with DNS forwarding</title>
      <link>https://community.cisco.com/t5/network-security/ezvpn-with-dns-forwarding/m-p/603271#M1055002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I don't understand what you mean?  The issue here is that the domain packet is sourced with the outside address (no NATing happens anyway!).  I had actually tried NATing the source address for a UDP/TCP 53 packet to the inside 10.xxx.. address which supposed to solve the issue for the return packet but still can't make it traverse the ezvpn tunnel!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Jul 2006 13:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ezvpn-with-dns-forwarding/m-p/603271#M1055002</guid>
      <dc:creator>hadbihas</dc:creator>
      <dc:date>2006-07-05T13:54:02Z</dc:date>
    </item>
  </channel>
</rss>

