<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Guest User can't access internal webserver on DMZ in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4756592#M1096905</link>
    <description>&lt;P&gt;You should be looking for a NAT rule for Webserver public and webserver private IPs and add the DNS keyword to this one.&lt;/P&gt;
&lt;P&gt;If you are having trouble identifying which rule it is, you can either post the NAT output here or you can create a "twice NAT" rule between the guest network and the webserver where you NAT the webserver public IP to its private IP and the maintain the guest network IP as original.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jan 2023 09:14:14 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2023-01-18T09:14:14Z</dc:date>
    <item>
      <title>Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755691#M1096842</link>
      <description>&lt;P&gt;Good Day All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm a newbie with Cisco ASA , i have an issue after setting up a guest wifi for my organization.&lt;/P&gt;&lt;P&gt;Here the Topo&lt;BR /&gt;Internal user are on : 10.20.20.0/24 and Guest users are on : 192.168.1.0/24 , DMZ is : 10.30.30.0/24&lt;/P&gt;&lt;P&gt;Internal users use internal DNS and Guest users use google( 8.8.8.8) .&lt;/P&gt;&lt;P&gt;There is a nat ( dynamic PAT ) on the WAN interface of the ASA in place allowing internal users to surf the internet as well as the Guest users.&lt;/P&gt;&lt;P&gt;We have an internal webserver in the DMZ : 10.30.30.57&amp;nbsp;&lt;/P&gt;&lt;P&gt;Internal users go directly to the &lt;A href="http://www.thewebserver.ca" target="_blank" rel="noopener"&gt;www.thewebserver.ca&lt;/A&gt;&amp;nbsp;got resolve to the internal IP and everything is good , my issue start when Guest users are trying to go to the same internal webserver ,then got resolve to the public IP and it does not display the page.&lt;/P&gt;&lt;P&gt;I read about DNS doctoring but as i said i'm not a pro with ASA , can someone help me with that plz.&lt;BR /&gt;I would appreciate .&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Access list are in place as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 23:47:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755691#M1096842</guid>
      <dc:creator>JakeYllus</dc:creator>
      <dc:date>2023-01-16T23:47:34Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755692#M1096843</link>
      <description>&lt;P&gt;Forget to mention . I'm running version 9.16(4)&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 23:51:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755692#M1096843</guid>
      <dc:creator>JakeYllus</dc:creator>
      <dc:date>2023-01-16T23:51:49Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755694#M1096844</link>
      <description>&lt;P&gt;Four&amp;nbsp; interface on the ASA : inside, outside, dmz, guest&lt;/P&gt;&lt;P&gt;Webserver public IP : 200.200.200.3 and private ip : 10.30.30.57&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jan 2023 23:54:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755694#M1096844</guid>
      <dc:creator>JakeYllus</dc:creator>
      <dc:date>2023-01-16T23:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755846#M1096852</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1454109"&gt;@JakeYllus&lt;/a&gt; configure a NAT reflection rule, &lt;A href="https://integratingit.wordpress.com/2021/07/11/ftd-nat-reflection/" target="_self"&gt;here is an example&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 08:13:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755846#M1096852</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2023-01-17T08:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755871#M1096854</link>
      <description>&lt;P&gt;DNS doctoring is quite easy. Just add the "DNS" option to the NAT rule for the Web-server. The only restriction is that this Webserver-NAT rule has to be a static 1:1 NAT rule and not "only" a port forwarding.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 08:49:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755871#M1096854</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2023-01-17T08:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755893#M1096857</link>
      <description>&lt;P&gt;As it has been mentioned by others here, you need to configure DNS doctoring / re-write either by adding the DNS keyword at the end of the NAT statement for the relevant server or via ASDM selecting "Translate DNS replies that match this rule" under the relevant NAT rule.&lt;/P&gt;
&lt;P&gt;Since this re-writes the DNS reply from the public IP to the private IP, you will also need to create an access rule for the guest users that allows access to the private IP of the webserver otherwise they will still not get access.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 09:20:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4755893#M1096857</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-17T09:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4756368#M1096899</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325766"&gt;@Karsten Iwen&lt;/a&gt;&amp;nbsp;!&lt;BR /&gt;Thanks for your help , just for me to understand .&lt;BR /&gt;I have to add the DNS option to the NAT rule that allow the webserver to be accessible from the outside ?&lt;/P&gt;&lt;P&gt;As i said the server is on DMZ so i should look for a rule ( DMZ,OUTSIDE ) ??&lt;BR /&gt;Thanks in advance for you response.&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 05:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4756368#M1096899</guid>
      <dc:creator>JakeYllus</dc:creator>
      <dc:date>2023-01-18T05:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4756540#M1096901</link>
      <description>&lt;P&gt;Exactly. An Example:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Real IP of DMZ-Server: 172.16.1.80&lt;/LI&gt;
&lt;LI&gt;public IP of DMZ-Server: 192.0.2.80, this is the DNS entry for &lt;A href="http://www.company.com" target="_blank"&gt;www.company.com&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;a NAT entry (DMZ,outside) to translate these two IPs with the DNS option&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;A client on the inside (any internal network including guest) asks Google DNS for the IP of &lt;A href="http://www.company.com" target="_blank"&gt;www.company.com&lt;/A&gt;&lt;/LI&gt;
&lt;LI&gt;Google returns the IP 192.0.2.80&lt;/LI&gt;
&lt;LI&gt;The ASA/FTD compares this DNS answer to the NAT entries and finds a translation for the public IP and the DNS option&lt;/LI&gt;
&lt;LI&gt;The ASA/FTD changes the DNS answer from 192.0.2.80 to 172.16.1.80&lt;/LI&gt;
&lt;LI&gt;the client learns that the server has 172.16.1.80 and does the web request.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Another restriction: The client has to use pure DNS, no DNScrypt, DoT, DoH or something.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 07:14:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4756540#M1096901</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2023-01-18T07:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4756592#M1096905</link>
      <description>&lt;P&gt;You should be looking for a NAT rule for Webserver public and webserver private IPs and add the DNS keyword to this one.&lt;/P&gt;
&lt;P&gt;If you are having trouble identifying which rule it is, you can either post the NAT output here or you can create a "twice NAT" rule between the guest network and the webserver where you NAT the webserver public IP to its private IP and the maintain the guest network IP as original.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jan 2023 09:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4756592#M1096905</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-18T09:14:14Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4757193#M1096945</link>
      <description>&lt;P&gt;Thanks again&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;I tried to configure it but give me an error each time, maybe i'm doing it wrong.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JakeYllus_0-1674103598364.jpeg" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/173733iDE0935F620C1C9CB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JakeYllus_0-1674103598364.jpeg" alt="JakeYllus_0-1674103598364.jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;How will it look on GUI ?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 04:49:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4757193#M1096945</guid>
      <dc:creator>JakeYllus</dc:creator>
      <dc:date>2023-01-19T04:49:51Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4757446#M1096951</link>
      <description>&lt;P&gt;If you are looking to configure twice NAT it would look something like the following&lt;/P&gt;
&lt;P&gt;Original Packet&lt;BR /&gt;source interface: Guest&lt;BR /&gt;Source address: 192.168.1.0/24&lt;/P&gt;
&lt;P&gt;destination interface: dmz&lt;BR /&gt;destination address: 200.200.200.3&lt;/P&gt;
&lt;P&gt;Translated Packet&lt;BR /&gt;Source NAT Type: Static&lt;BR /&gt;Source Address: 192.168.1.0/24&lt;/P&gt;
&lt;P&gt;Destination address: 10.30.30.57&lt;/P&gt;
&lt;P&gt;In addition to this you need to configure an access rule for Guest network to access 10.30.30.57&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 09:43:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4757446#M1096951</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2023-01-19T09:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Guest User can't access internal webserver on DMZ</title>
      <link>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4759517#M1097056</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/319690"&gt;@Marius Gunnerud&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;That worked beautifully &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Thanks for your help .&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jan 2023 00:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/guest-user-can-t-access-internal-webserver-on-dmz/m-p/4759517#M1097056</guid>
      <dc:creator>JakeYllus</dc:creator>
      <dc:date>2023-01-23T00:37:18Z</dc:date>
    </item>
  </channel>
</rss>

