<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS configuration on FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4170820#M1075003</link>
    <description>&lt;P&gt;The DNS servers you configure in the GUI as you shared in your earlier screenshot are for doing DNS lookups for policy-related actions (e.g if there is an access-control policy entry with a FQDN object or similar).&lt;/P&gt;
&lt;P&gt;The DNS server you configure via the management cli is only used for management purposes, not for the data plane or enforcemnt of traffic through it.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Oct 2020 07:56:56 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2020-10-21T07:56:56Z</dc:date>
    <item>
      <title>DNS configuration on FTD</title>
      <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169966#M1074951</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am working on Cisco FTD which are managed by FMC. I ahve conifgured the DNS group:&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;I did an nslookup from the firewall but the firewall doesnt seem to resolve google.com&lt;/P&gt;&lt;P&gt;I ahve route pointing towards the inside interface for 10.0.0.0/8 subnet, and my DNS server also falls under this subnet but it is reachable through the mgmt interface only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now on other vendors I can create a service route for the management interface, but doesnt seem to eb possible for this FTD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I add a management route on the FTD to send this destination dns server traffic out from the menagement interface?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 05:10:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169966#M1074951</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2020-10-20T05:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: DNS configuration on FTD</title>
      <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169968#M1074952</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dns.PNG" style="width: 976px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/86466iE74E08383E571D6F/image-size/large?v=v2&amp;amp;px=999" role="button" title="dns.PNG" alt="dns.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 05:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169968#M1074952</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2020-10-20T05:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: DNS configuration on FTD</title>
      <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169987#M1074953</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;You have to enable dns lookup under the interface configuration to be able&lt;BR /&gt;to perform lookups on the firewall. If the route points to inside, then you&lt;BR /&gt;need to enable dns lookup on the inside.&lt;BR /&gt;&lt;BR /&gt;In the same screenshot, just add the inside interface&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 20 Oct 2020 06:01:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169987#M1074953</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-10-20T06:01:37Z</dc:date>
    </item>
    <item>
      <title>Re: DNS configuration on FTD</title>
      <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169989#M1074954</link>
      <description>&lt;P&gt;HI Mohammad,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DNS server is reachable through Management interface only, i want the lookup to happen through mgmt interface, what do I need to do&amp;nbsp; in that case?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 06:05:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169989#M1074954</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2020-10-20T06:05:14Z</dc:date>
    </item>
    <item>
      <title>Re: DNS configuration on FTD</title>
      <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169992#M1074955</link>
      <description>Understood, in this case you need to create a data interface in the same&lt;BR /&gt;subnet as mgmt and use it to perform lookups. Till the latest version (6.6)&lt;BR /&gt;FTD doesn't support lookup through mgmt interface.&lt;BR /&gt;&lt;BR /&gt;**** please remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Tue, 20 Oct 2020 06:09:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4169992#M1074955</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-10-20T06:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: DNS configuration on FTD</title>
      <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4170109#M1074965</link>
      <description>&lt;P&gt;You can configure the DNS servers for management interface from the command line (CLI) by using the following command (change dns server IP as needed):&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;configure network dns server 8.8.8.8&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;verify using the show network command.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 09:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4170109#M1074965</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-10-20T09:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: DNS configuration on FTD</title>
      <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4170820#M1075003</link>
      <description>&lt;P&gt;The DNS servers you configure in the GUI as you shared in your earlier screenshot are for doing DNS lookups for policy-related actions (e.g if there is an access-control policy entry with a FQDN object or similar).&lt;/P&gt;
&lt;P&gt;The DNS server you configure via the management cli is only used for management purposes, not for the data plane or enforcemnt of traffic through it.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2020 07:56:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4170820#M1075003</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-10-21T07:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: DNS configuration on FTD</title>
      <link>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4981778#M1107099</link>
      <description>&lt;P&gt;hi Marvin&lt;/P&gt;&lt;P&gt;If the Interface is not avalibly from the dropdown there what is the cause for this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have 6 FP2110 FTD's running&amp;nbsp; (12 - 6 in HA mode) - vers. 6.6.1 - 6.6.5 and 7.0.0 - which is managed from a FMC on 7.0.0&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have a common device policy for them where we assign the DNS settings trough - but DNS for fqdn in the ACE's doesnt resolve. When i do a DNS debug i get "DNS: DNS not enabled for interface "&lt;/P&gt;&lt;P&gt;Can you guide me to the cause for this?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Dec 2023 20:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-configuration-on-ftd/m-p/4981778#M1107099</guid>
      <dc:creator>tiwang</dc:creator>
      <dc:date>2023-12-19T20:17:24Z</dc:date>
    </item>
  </channel>
</rss>

