<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSR1000v DNS Issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795874#M1098745</link>
    <description>No problem I’m having is that I can’t get the traffic going&lt;BR /&gt;</description>
    <pubDate>Thu, 16 Mar 2023 17:21:52 GMT</pubDate>
    <dc:creator>joematrix77</dc:creator>
    <dc:date>2023-03-16T17:21:52Z</dc:date>
    <item>
      <title>CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795836#M1098742</link>
      <description>&lt;P&gt;I'm having issues with my networks not being able to resolve websites. I'm trying to configure DNS servers on internal segments without putting them on the public network. So basically, port forwarding ideally, I would like to have one DNS server in the DMZ resolving and one internally able to resolve URLs. I can ping outside but can't resolve website urls. 192.168.1.1 is my ISP network gateway. I'm basically asking what is "&lt;SPAN&gt;nat (inside,outside) after-&lt;/SPAN&gt;&lt;SPAN&gt;auto&lt;/SPAN&gt;&lt;SPAN&gt; source dynamic &lt;/SPAN&gt;&lt;SPAN&gt;any &lt;/SPAN&gt;&lt;FONT face="inherit"&gt;interface" &lt;/FONT&gt;equivalent&lt;FONT face="inherit"&gt;&amp;nbsp;command on this router? Am I missing something?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Here's my current config:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt;-server &lt;/SPAN&gt;&lt;SPAN&gt;192.168.1.1#ISP&lt;/SPAN&gt; &lt;SPAN&gt;192.168.0.83#INSIDE&lt;/SPAN&gt; &lt;SPAN&gt;10.4.43.83#DMZ&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; domain &lt;/SPAN&gt;&lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt; xyz.com&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip address&lt;/SPAN&gt; &lt;SPAN&gt;192.168.1.3&lt;/SPAN&gt; &lt;SPAN&gt;255.255.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; outside&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;negotiation &lt;/SPAN&gt;&lt;SPAN&gt;auto&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;no &lt;/SPAN&gt;&lt;SPAN&gt;mop enabled&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;no &lt;/SPAN&gt;&lt;SPAN&gt;mop sysid&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;no &lt;/SPAN&gt;&lt;SPAN&gt;ip address&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;negotiation &lt;/SPAN&gt;&lt;SPAN&gt;auto&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;no &lt;/SPAN&gt;&lt;SPAN&gt;mop enabled&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;no &lt;/SPAN&gt;&lt;SPAN&gt;mop sysid&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.43&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;encapsulation&lt;/SPAN&gt;&lt;SPAN&gt; dot1Q 443&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip address&lt;/SPAN&gt; &lt;SPAN&gt;192.168.43.2&lt;/SPAN&gt; &lt;SPAN&gt;255.255.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; inside&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;standby 1 &lt;/SPAN&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;192.168.43.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cdp enable&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.100&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;encapsulation&lt;/SPAN&gt;&lt;SPAN&gt; dot1Q 100&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip address&lt;/SPAN&gt; &lt;SPAN&gt;192.168.0.2&lt;/SPAN&gt; &lt;SPAN&gt;255.255.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; inside&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;standby 1 &lt;/SPAN&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;192.168.0.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cdp enable&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;3&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ip address&lt;/SPAN&gt; &lt;SPAN&gt;10.1.200.1&lt;/SPAN&gt; &lt;SPAN&gt;255.255.255.0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;negotiation &lt;/SPAN&gt;&lt;SPAN&gt;auto&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;no &lt;/SPAN&gt;&lt;SPAN&gt;mop enabled&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;no &lt;/SPAN&gt;&lt;SPAN&gt;mop sysid&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;router &lt;/SPAN&gt;&lt;SPAN&gt;bgp&lt;/SPAN&gt;&lt;SPAN&gt; 443&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;bgp&lt;/SPAN&gt;&lt;SPAN&gt; router-id &lt;/SPAN&gt;&lt;SPAN&gt;192.168.43.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;bgp&lt;/SPAN&gt; &lt;SPAN&gt;log&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;neighbor&lt;/SPAN&gt;&lt;SPAN&gt;-changes&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;redistribute&lt;/SPAN&gt;&lt;SPAN&gt; connected&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;neighbor&lt;/SPAN&gt; &lt;SPAN&gt;192.168.43.5&lt;/SPAN&gt;&lt;SPAN&gt; remote-as 443&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;neighbor&lt;/SPAN&gt; &lt;SPAN&gt;192.168.43.6&lt;/SPAN&gt;&lt;SPAN&gt; remote-as 443&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; forward-protocol nd&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; http server&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; http &lt;/SPAN&gt;&lt;SPAN&gt;authentication&lt;/SPAN&gt;&lt;SPAN&gt; local&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; http secure-server&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; inside source route-map track-primary-if &lt;/SPAN&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;1 overload&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; inside source list 1 &lt;/SPAN&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.100 overload&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; inside source list 43 &lt;/SPAN&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.43 overload&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; inside source list 100 &lt;/SPAN&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.100 overload&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; inside source list 143 &lt;/SPAN&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.43 overload&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip nat&lt;/SPAN&gt;&lt;SPAN&gt; inside source list 144 &lt;/SPAN&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.43 overload&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; default-&lt;/SPAN&gt;&lt;SPAN&gt;network&lt;/SPAN&gt; &lt;SPAN&gt;192.168.1.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; route &lt;/SPAN&gt;&lt;SPAN&gt;0.0.0.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.0&lt;/SPAN&gt; &lt;SPAN&gt;192.168.1.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; route &lt;/SPAN&gt;&lt;SPAN&gt;0.0.0.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.0&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; route &lt;/SPAN&gt;&lt;SPAN&gt;10.4.43.0&lt;/SPAN&gt; &lt;SPAN&gt;255.255.255.0&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.43 &lt;/SPAN&gt;&lt;SPAN&gt;192.168.43.4&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; route &lt;/SPAN&gt;&lt;SPAN&gt;192.168.0.0&lt;/SPAN&gt; &lt;SPAN&gt;255.255.255.0&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.100 &lt;/SPAN&gt;&lt;SPAN&gt;192.168.0.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; route &lt;/SPAN&gt;&lt;SPAN&gt;192.168.43.0&lt;/SPAN&gt; &lt;SPAN&gt;255.255.255.0&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;2.43 &lt;/SPAN&gt;&lt;SPAN&gt;192.168.43.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; ssh rsa keypair-&lt;/SPAN&gt;&lt;SPAN&gt;name&lt;/SPAN&gt;&lt;SPAN&gt; ssh-key&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt;&lt;SPAN&gt; ssh version 2&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;access-list&lt;/SPAN&gt;&lt;SPAN&gt; standard 1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;10 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;192.168.0.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;access-list&lt;/SPAN&gt;&lt;SPAN&gt; standard 43&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;10 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;192.168.43.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;access-list&lt;/SPAN&gt;&lt;SPAN&gt; standard 44&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;10 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;10.4.43.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;access-list&lt;/SPAN&gt;&lt;SPAN&gt; extended 100&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;10 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;192.168.0.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;20 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;tcp &lt;/SPAN&gt;&lt;SPAN&gt;192.168.0.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; eq domain any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;30 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;udp &lt;/SPAN&gt;&lt;SPAN&gt;192.168.0.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; eq domain any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;access-list&lt;/SPAN&gt;&lt;SPAN&gt; extended 143&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;10 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;192.168.43.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;20 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;tcp &lt;/SPAN&gt;&lt;SPAN&gt;192.168.43.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; eq domain any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;30 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;udp &lt;/SPAN&gt;&lt;SPAN&gt;192.168.43.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; eq domain any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;access-list&lt;/SPAN&gt;&lt;SPAN&gt; extended 144&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;10 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;ip&lt;/SPAN&gt; &lt;SPAN&gt;10.4.43.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;20 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;tcp &lt;/SPAN&gt;&lt;SPAN&gt;10.4.43.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; eq domain any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;30 &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;udp &lt;/SPAN&gt;&lt;SPAN&gt;10.4.43.0&lt;/SPAN&gt; &lt;SPAN&gt;0.0.0.255&lt;/SPAN&gt;&lt;SPAN&gt; eq domain any&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;route-map track-primary-if &lt;/SPAN&gt;&lt;SPAN&gt;permit &lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;match &lt;/SPAN&gt;&lt;SPAN&gt;ip address&lt;/SPAN&gt;&lt;SPAN&gt; 197&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;set &lt;/SPAN&gt;&lt;SPAN&gt;interface&lt;/SPAN&gt; &lt;SPAN&gt;GigabitEthernet&lt;/SPAN&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;control-plane&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;line con 0&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;stopbits&lt;/SPAN&gt;&lt;SPAN&gt; 1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;line vty 0 4&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;login&lt;/SPAN&gt;&lt;SPAN&gt; local&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;transport input&lt;/SPAN&gt;&lt;SPAN&gt; ssh&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;line vty 5 15&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;login&lt;/SPAN&gt;&lt;SPAN&gt; local&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;transport input&lt;/SPAN&gt;&lt;SPAN&gt; ssh&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;!&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ntp server us.pool.ntp.org&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 10:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795836#M1098742</guid>
      <dc:creator>joematrix77</dc:creator>
      <dc:date>2023-03-17T10:23:31Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795861#M1098744</link>
      <description>&lt;P&gt;You should rely on Local DNS Server, Intern that local DNS Server should able to resolved both Local and FQDN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 17:15:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795861#M1098744</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-16T17:15:49Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795874#M1098745</link>
      <description>No problem I’m having is that I can’t get the traffic going&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Mar 2023 17:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795874#M1098745</guid>
      <dc:creator>joematrix77</dc:creator>
      <dc:date>2023-03-16T17:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795938#M1098747</link>
      <description>&lt;P&gt;show us more what is I can’t get the traffic going&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 18:26:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795938#M1098747</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-16T18:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795960#M1098749</link>
      <description>Meaning is in a flat network if I have my domain controller on the inside network it can Traverse the outside and get DNS entries to be able to resolve quarries once I switched from an ASAv to the CRS that functionality just dropped&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Mar 2023 19:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795960#M1098749</guid>
      <dc:creator>joematrix77</dc:creator>
      <dc:date>2023-03-16T19:02:52Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795974#M1098750</link>
      <description>&lt;P&gt;Do you have any debug commands that you would like me to post? I'm just confused as to why this isn't working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 19:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795974#M1098750</guid>
      <dc:creator>joematrix77</dc:creator>
      <dc:date>2023-03-16T19:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795977#M1098751</link>
      <description>&lt;P&gt;192.168.0.83 is on one INSIDE LAN&lt;/P&gt;&lt;P&gt;10.4.43.83 is on one INSIDE LAN&lt;/P&gt;&lt;P&gt;192.168.1.1 is the outside router on the WAN network.&lt;/P&gt;&lt;P&gt;I can ping outside via ip addresses just not FQDN. I am assuming the inside DNS servers aren't receiving the port 53 request.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Mar 2023 19:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4795977#M1098751</guid>
      <dc:creator>joematrix77</dc:creator>
      <dc:date>2023-03-16T19:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796419#M1098762</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;I'm basically asking what is "&lt;/SPAN&gt;&lt;SPAN&gt;nat (inside,outside) after-&lt;/SPAN&gt;&lt;SPAN&gt;auto&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;source dynamic&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;any&amp;nbsp;&lt;/SPAN&gt;&lt;FONT face="inherit"&gt;interface"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN&gt;equivalent&lt;/SPAN&gt;&lt;FONT face="inherit"&gt;&amp;nbsp;command on this router? Am I missing something? Thank you for your help.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 10:27:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796419#M1098762</guid>
      <dc:creator>joematrix77</dc:creator>
      <dc:date>2023-03-17T10:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796837#M1098776</link>
      <description>&lt;P&gt;ip domain lookup &amp;lt;&amp;lt;- this command need to make router run as DNS proxy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 22:35:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796837#M1098776</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-03-17T22:35:47Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796842#M1098777</link>
      <description>&lt;LI-CODE lang="markup"&gt;Meaning is in a flat network if I have my domain controller on the inside network it can Traverse the outside and get DNS entries to be able to resolve quarries once I switched from an ASAv to the CRS that functionality just dropped&lt;/LI-CODE&gt;
&lt;P&gt;ASAv works with the same setup, and when you replace ASAv with CSR1K that not working.&lt;/P&gt;
&lt;P&gt;When you replace with CSR1K, from DNS Server are you able to resolve the DNS ? (can you post the output ?) DNS Server what Root DNS Server is configured ?&lt;/P&gt;
&lt;P&gt;When the Client use your DNS Server (local one)&lt;/P&gt;
&lt;P&gt;can you post nslookup (local and FQDN resolution) what error you getting) ?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 22:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796842#M1098777</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-17T22:58:41Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796853#M1098778</link>
      <description>&lt;P&gt;I had that configured, my problem is I can ping public ip addresses but I can not open websites in a browser which I find really weird.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 23:38:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796853#M1098778</guid>
      <dc:creator>joematrix77</dc:creator>
      <dc:date>2023-03-17T23:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796854#M1098779</link>
      <description>&lt;P&gt;DNS request timed out&lt;/P&gt;&lt;P&gt;Default Server Unknown&lt;/P&gt;&lt;P&gt;#do ping google.com&lt;BR /&gt;Pinging google.com (142.250.217.206) with 18 bytes of data:&lt;/P&gt;&lt;P&gt;PING: no reply from 142.250.217.206&lt;BR /&gt;PING: timeout&lt;BR /&gt;PING: no reply from 142.250.217.206&lt;BR /&gt;PING: timeout&lt;BR /&gt;PING: no reply from 142.250.217.206&lt;BR /&gt;PING: timeout&lt;BR /&gt;PING: no reply from 142.250.217.206&lt;BR /&gt;PING: timeout&lt;/P&gt;</description>
      <pubDate>Sat, 18 Mar 2023 00:12:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796854#M1098779</guid>
      <dc:creator>joematrix77</dc:creator>
      <dc:date>2023-03-18T00:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796857#M1098780</link>
      <description>&lt;LI-CODE lang="markup"&gt;I had that configured, my problem is I can ping public ip addresses but I can not open websites in a browser which I find really weird&lt;/LI-CODE&gt;
&lt;P&gt;That what your issue and we are dealing with - IP pings, but the Browsing side needs DNS Resolution, which is failing.&lt;/P&gt;
&lt;P&gt;For that I have asked some information - if you can provide that information - we can do some testing to resolve it.&lt;/P&gt;
&lt;P&gt;Let me paste again :&lt;/P&gt;
&lt;P&gt;When you replace with CSR1K, from DNS Server are you able to resolve the DNS ? (can you post the output ?) DNS Server what Root DNS Server is configured ?&lt;/P&gt;
&lt;P&gt;When the Client use your DNS Server (local one)&lt;/P&gt;
&lt;P&gt;can you post nslookup (local and FQDN resolution) what error you getting) ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;DNS request timed out

Default Server Unknown&lt;/LI-CODE&gt;
&lt;P&gt;This is not much use here, we are not sure what device is this getting message.&lt;/P&gt;
&lt;P&gt;end devise post ipconfig /all&amp;nbsp; Along with the information I have asked in the post.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 23:46:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4796857#M1098780</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-17T23:46:37Z</dc:date>
    </item>
    <item>
      <title>Re: CSR1000v DNS Issues</title>
      <link>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4802516#M1099051</link>
      <description>&lt;P&gt;I am not sure if you can relate with your problem, but yesterday i had somehow similiar issue DNS was not resolving. So i removed the config from my interfaces for umbrella DNS, and it got resolved. I am suspecting software bug.&amp;nbsp;Cisco IOS XE Software, Version 16.12.01a.&lt;/P&gt;
&lt;P&gt;Before i had same, can ping IPs but not able to reach&amp;nbsp; using FQDN.&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet2&amp;nbsp;&lt;BR /&gt;no umbrella in Azure&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;interface Tunnel100&lt;BR /&gt;no umbrella in iWAN&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="tariqmahmood_0-1679992002720.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/180305iA82691A462CF58F7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="tariqmahmood_0-1679992002720.png" alt="tariqmahmood_0-1679992002720.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Mar 2023 08:27:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/csr1000v-dns-issues/m-p/4802516#M1099051</guid>
      <dc:creator>tarmahmood1</dc:creator>
      <dc:date>2023-03-28T08:27:11Z</dc:date>
    </item>
  </channel>
</rss>

