<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178440#M1075469</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;i have done some steps, i have removed my domain contoller IP which is 192.168.2.2 from forwarder, and i have added only 8.8.8.8 in forwarder and also deleted all the root hints and applied and save the settings. now i am able to do nslookup on everything&amp;nbsp; (my internal clients, &lt;A href="http://www.google.com," target="_blank"&gt;www.google.com,&lt;/A&gt; &lt;A href="http://www.hotmail.com" target="_blank"&gt;www.hotmail.com&lt;/A&gt;) a screen shot is attached for your kind consideration. please check and acknowledge and tell me what further i should do to give users internet access without mentioning the 8.8.8.8 in secondary dns ip. i want internet work on client with the primarry dns which is 192.168.2.2 and gateway which is 192.168.2.40 cisco asa. i appreciated your concern.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="123.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/87694i460D48557889210D/image-size/large?v=v2&amp;amp;px=999" role="button" title="123.jpg" alt="123.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 04 Nov 2020 09:00:47 GMT</pubDate>
    <dc:creator>Cash2106</dc:creator>
    <dc:date>2020-11-04T09:00:47Z</dc:date>
    <item>
      <title>Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178066#M1075422</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;i am using Cisco ASA 5520, i am facing an issue, when i am giving IP address on client machine and DNS of 8.8.8.8 in the DNS part then users are able to access the internet, but when i am removing that DNS 8.8.8.8 then users are not able to use the internet,&lt;/P&gt;&lt;P&gt;i have a Domain controller which IP is also configured in client machine to connect then with domain but when i add 8.8.8.8 with the domain controller DNS then users are not able to use domain controller shared resources properly.&lt;/P&gt;&lt;P&gt;the details for the CISCO ASA network is given below for better understanding.&lt;/P&gt;&lt;P&gt;CISCO ASA Inside = 192.168.2.40&lt;/P&gt;&lt;P&gt;Cisco ASA Outside = 172.0.0.16 (for example)&lt;/P&gt;&lt;P&gt;Domain Controller = 192.168.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i want to set it up, if i give then DNS of 192.168.2.2 then internet should work on clients without giving 8.8.8.8.&lt;/P&gt;&lt;P&gt;i have already added a DNS in Cisco ASA through the commands given below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;name-server 192.168.2.2&lt;/P&gt;&lt;P&gt;domain-name DARSPN.LOCAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;with these settings i believe internet should work on client machine after mentioning the given below IP Settings.&lt;/P&gt;&lt;P&gt;IP = 192.168.2.10&lt;/P&gt;&lt;P&gt;Subnet = 255.255.255.0&lt;/P&gt;&lt;P&gt;Gateway = 192.168.2.40&lt;/P&gt;&lt;P&gt;DNS = 192.168.2.2&lt;/P&gt;&lt;P&gt;but on client machine, internet is not working, but whenever i give then DNS 8.8.8.8 then internet start working on the client machines, i want to make it work without giving the 8.8.8.8 DNS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;NAT rule is also configured but still clients are not able to connect through internet&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 16:24:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178066#M1075422</guid>
      <dc:creator>Cash2106</dc:creator>
      <dc:date>2020-11-03T16:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178103#M1075428</link>
      <description>&lt;P&gt;Client can connect the Domain Name Server directly i.e. they connect to SW and SW connect to ASA?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 17:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178103#M1075428</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2020-11-03T17:11:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178128#M1075438</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;i did not get your point, can you explain it to me. what is SW ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and currently my client IP setting on which internet is working is given below for your kind consideration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;IP = 192.168.2.10&lt;BR /&gt;Subnet = 255.255.255.0&lt;/P&gt;&lt;P&gt;Gateway = 192.168.2.40&lt;/P&gt;&lt;P&gt;DNS1 = 192.168.2.2&lt;/P&gt;&lt;P&gt;DNS2 = 8.8.8.8&lt;/P&gt;&lt;P&gt;with the IP Settings give above client can access the internet but when i remove the DNS2 which is 8.8.8.8 then client is not able to use the internet. i dont know how to make it work to give the internet connectivity to client with only one DNS which is 192.168.2.2 or using the same Gateway IP in DNS2 as well.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 17:53:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178128#M1075438</guid>
      <dc:creator>Cash2106</dc:creator>
      <dc:date>2020-11-03T17:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178131#M1075440</link>
      <description>&lt;P&gt;Are you running the DNS service on the domain controller?&amp;nbsp; If you are not running the DNS service you will not be able to connect to the internet using URLs when you configure the domain controller as the DNS server for clients.&lt;/P&gt;
&lt;P&gt;I just want to add, it is not a good practice having the DNS server on the domain controller.&amp;nbsp; DNS should be on a separate server.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 17:58:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178131#M1075440</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-03T17:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178132#M1075441</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;i have a DNS installed on the domain controller, i have resources problem thats why i am using DNS DHCP and AD on one same server,&lt;/P&gt;&lt;P&gt;isnt there anyway i can do these settings.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or another approach is, can i configure it like that in which i can use the Cisco ASA IP which is 192.168.2.40 in the DNS part to make internet working on client side ?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 18:01:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178132#M1075441</guid>
      <dc:creator>Cash2106</dc:creator>
      <dc:date>2020-11-03T18:01:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178134#M1075442</link>
      <description>&lt;P&gt;Is the Server able to resolve domains?&amp;nbsp; for example, if you open the command prompt and enter &lt;STRONG&gt;nslookup google.com&lt;/STRONG&gt; do you get a reply that shows the IP of google.com?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 18:05:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178134#M1075442</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-03T18:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178138#M1075443</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;no i am not able to get proper response when i do nslookup for google.com or any other website, because right now i am not using internet on the domain controller, but even when i allow internet access on domain controller at that time i am still not able to lookup google.com except only the clients which are inside the domain darson.local.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 18:08:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178138#M1075443</guid>
      <dc:creator>Cash2106</dc:creator>
      <dc:date>2020-11-03T18:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178160#M1075447</link>
      <description>&lt;P data-unlink="true"&gt;The issue is that the DNS server doesn't know where to find information when performing lookups. What do you access rules on the ASA look like for access from the DNS server to internet?&amp;nbsp; My guess is that DNS request traffic is being blocked from the DNS towards internet.&lt;/P&gt;
&lt;P data-unlink="true"&gt;Check the rules on the firewall and make sure that at least UDP/53 is allowed from the DNS server towards the internet, then add 8.8.8.8 as a DNS on the server, and test again.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 18:36:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178160#M1075447</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-03T18:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178383#M1075461</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;i have added a UDP port 523 rule in firewall in windows domain controller, and added dns 8.8.8.8 in ip settings, i can access the internet, but i am not able to lookup for google.com, hotmail.com anything, but internet is working on the client, i am trying to add dns forwarder in dns its resolving 8.8.8.8 to dns.google.com but when i am applying the settings its giving me error and after i click on OK button and then apply, after applying when i come to dns forwarder again the 8.8.8.8 entry doesnt show there, i am attaching screen shot please check and acknowledge please.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="dc.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/87677i5D3EB913DA825D73/image-size/large?v=v2&amp;amp;px=999" role="button" title="dc.jpg" alt="dc.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/87676i9F890E5FC9EBF220/image-size/large?v=v2&amp;amp;px=999" role="button" title="DNS1.png" alt="DNS1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DNS2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/87675iC40F4ED2FEA439F7/image-size/large?v=v2&amp;amp;px=999" role="button" title="DNS2.png" alt="DNS2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 07:09:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178383#M1075461</guid>
      <dc:creator>Cash2106</dc:creator>
      <dc:date>2020-11-04T07:09:08Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178398#M1075464</link>
      <description>&lt;P&gt;When I asked about if port UDP/53 was opened for in the firewall, I did not mean the Windows firewall, but instead the ASA firewall.&lt;/P&gt;
&lt;P&gt;However, it sounds like your server is not performing recursive lookup.&amp;nbsp; Try the following troubleshoot steps that I found on Microsoft support site.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows-server/networking/dns/troubleshoot/troubleshoot-dns-server#to-view-the-current-root-hints" target="_blank"&gt;https://docs.microsoft.com/en-us/windows-server/networking/dns/troubleshoot/troubleshoot-dns-server#to-view-the-current-root-hints&lt;/A&gt;&lt;/P&gt;
&lt;H2 id="checking-for-recursion-problems" class="heading-anchor"&gt;Checking for recursion problems&lt;/H2&gt;
&lt;P&gt;For recursion to work successfully, all DNS servers that are used in the path of a recursive query must be able to respond and forward correct data. If they can't, a recursive query can fail for any of the following reasons:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;The query times out before it can be completed.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;A server that's used during the query fails to respond.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;A server that's used during the query provides incorrect data.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Start troubleshooting at the server that was used in your original query. Check whether this server forwards queries to another server by examining the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Forwarders&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab in the server properties in the DNS console. If the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Enable forwarders&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;check box is selected, and one or more servers are listed, this server forwards queries.&lt;/P&gt;
&lt;P&gt;If this server does forward queries to another server, check for problems that affect the server to which this server forwards queries. To check for problems, see&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/windows-server/networking/dns/troubleshoot/troubleshoot-dns-server#check-dns-server-problems" data-linktype="self-bookmark" target="_blank"&gt;Check DNS Server problems&lt;/A&gt;. When that section instructs you to perform a task on the client, perform it on the server instead.&lt;/P&gt;
&lt;P&gt;If the server is healthy and can forward queries, repeat this step, and examine the server to which this server forwards queries.&lt;/P&gt;
&lt;P&gt;If this server does not forward queries to another server, test whether this server can query a root server. To do this, run the following command:&lt;/P&gt;
&lt;DIV id="code-try-7" class="codeHeader" data-bi-name="code-header"&gt;&lt;SPAN class="language"&gt;cmd&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;PRE class="has-inner-focus" tabindex="0"&gt;&lt;CODE class="lang-cmd" style="box-sizing: inherit; font-family: SFMono-Regular, Consolas, 'Liberation Mono', Menlo, Courier, monospace; font-size: 1em; outline-color: inherit; direction: ltr; position: relative; border: 0px; padding: 0px; display: block; line-height: 19px;" data-author-content="nslookup
server &amp;lt;IP address of server being examined&amp;gt;
set q=NS
"&gt;&lt;SPAN&gt;nslookup
server &amp;lt;IP address of server being examined&amp;gt;
&lt;SPAN class="hljs-built_in"&gt;set&lt;/SPAN&gt; q=NS
&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;If the resolver returns the IP address of a root server, you probably have a broken delegation between the root server and the name or IP address that you're trying to resolve. Follow the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/windows-server/networking/dns/troubleshoot/troubleshoot-dns-server#test-a-broken-delegation" data-linktype="self-bookmark" target="_blank"&gt;Test a broken delegation&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;procedure to determine where you have a broken delegation.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;If the resolver returns a "Request to server timed out" response, check whether the root hints point to functioning root servers. To do this, use the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/windows-server/networking/dns/troubleshoot/troubleshoot-dns-server#to-view-the-current-root-hints" data-linktype="self-bookmark" target="_blank"&gt;To view the current root hints&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;procedure. If the root hints do point to functioning root servers, you might have a network problem, or the server might use an advanced firewall configuration that prevents the resolver from querying the server, as described in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://docs.microsoft.com/en-us/windows-server/networking/dns/troubleshoot/troubleshoot-dns-server#check-dns-server-problems" data-linktype="self-bookmark" target="_blank"&gt;Check DNS server problems&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;section. It's also possible that the recursive time-out default is too short.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;H3 id="test-a-broken-delegation" class="heading-anchor"&gt;&amp;nbsp;&lt;/H3&gt;</description>
      <pubDate>Wed, 04 Nov 2020 07:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178398#M1075464</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-04T07:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178440#M1075469</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;i have done some steps, i have removed my domain contoller IP which is 192.168.2.2 from forwarder, and i have added only 8.8.8.8 in forwarder and also deleted all the root hints and applied and save the settings. now i am able to do nslookup on everything&amp;nbsp; (my internal clients, &lt;A href="http://www.google.com," target="_blank"&gt;www.google.com,&lt;/A&gt; &lt;A href="http://www.hotmail.com" target="_blank"&gt;www.hotmail.com&lt;/A&gt;) a screen shot is attached for your kind consideration. please check and acknowledge and tell me what further i should do to give users internet access without mentioning the 8.8.8.8 in secondary dns ip. i want internet work on client with the primarry dns which is 192.168.2.2 and gateway which is 192.168.2.40 cisco asa. i appreciated your concern.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="123.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/87694i460D48557889210D/image-size/large?v=v2&amp;amp;px=999" role="button" title="123.jpg" alt="123.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 09:00:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178440#M1075469</guid>
      <dc:creator>Cash2106</dc:creator>
      <dc:date>2020-11-04T09:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178477#M1075473</link>
      <description>&lt;P&gt;Have you tested to see if the clients now can resolve URLs and browse to websites using 192.168.2.2 DNS server only?&amp;nbsp; You should be able to now.&amp;nbsp; The DNS server needs a global open resolver to lookup URLs that are not locally defined in its DNS records, so you need to have google DNS or some other DNS configured (for exmple Umbrella 208.67.222.222, 208.67.220.220).&amp;nbsp; I would recommend using Umbrella.&lt;/P&gt;
&lt;P&gt;But all in all, you should be good to go now once you have set the clients to receive DHCP assigned IP, DNS, and default gateway&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 10:20:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178477#M1075473</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-04T10:20:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178524#M1075477</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;really appreciated your concern, the issue is resolved now, users are not able to use internet with the DNS 192.168.2.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am sure this worked because i have enable the DNS services in cisco asa&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;dns domain-lookup inside&lt;/P&gt;&lt;P&gt;dns server-group DefaultDNS&lt;/P&gt;&lt;P&gt;name-server 192.168.2.2&lt;/P&gt;&lt;P&gt;domain-name DARSPN.LOCAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and because of these settings internet is working when we are giving 192.168.2.2 in primary dns server. just want to confirm it if i am right or wrong.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;anyway thanks for your concern and support .. really appreciated. you made my life easy ...&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 11:30:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178524#M1075477</guid>
      <dc:creator>Cash2106</dc:creator>
      <dc:date>2020-11-04T11:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASA 5520 Internet Access With Gateway IP as DNS</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178530#M1075478</link>
      <description>&lt;P&gt;Thank you for rating and selecting the answer!&lt;/P&gt;
&lt;P&gt;The DNS configuration on ASA is only locally significant to the ASA.&amp;nbsp; That is, the ASA only uses this for domain lookups that it needs to do itself.&amp;nbsp; So if you need to ping google.com from the ASA, for example, then you would need to have this configuration.&amp;nbsp; So, it will not have any affect on client traffic.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2020 11:37:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-5520-internet-access-with-gateway-ip-as-dns/m-p/4178530#M1075478</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-04T11:37:01Z</dc:date>
    </item>
  </channel>
</rss>

