<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower-DNS Not Resolving in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4830120#M1100236</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; Not sure what you mean. The DNS is not resolving neither to the internal network or external network. I can ping any address through the data interfaces.&lt;/P&gt;&lt;P&gt;But the DNS is not working through the data interfaces (INSIDE or OUTSIDE). It is only working through the Management interface when I do (ping system &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;) or (ping system lab.local)&lt;/P&gt;</description>
    <pubDate>Sun, 07 May 2023 18:02:01 GMT</pubDate>
    <dc:creator>SecurityJumbo</dc:creator>
    <dc:date>2023-05-07T18:02:01Z</dc:date>
    <item>
      <title>Firepower-DNS Not Resolving</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4829917#M1100230</link>
      <description>&lt;P&gt;I have a FMC and HA FTD on HA mode version 7.3.1for both. The DNs server is connected via INSIDE interface only. The Firepower can ping the DNS server as shown below, but the DNS is failed. I configured the DNS and domainsearch. The DNS is not resolving through the INSIDE or OUTSIDE interfaces. The DNS is only resolving through the management interface when I use&amp;nbsp; "ping system xxx" command. I believe there is something else I'm missing. Please can you check and let me know what you think.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SecurityJumbo_0-1683400188058.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/183951iFDB29462BBF3C4E7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SecurityJumbo_0-1683400188058.png" alt="SecurityJumbo_0-1683400188058.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ping 192.168.10.5&lt;BR /&gt;Please use 'CTRL+C' to cancel/abort...&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 192.168.10.5, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;BR /&gt;Success rate is 100 percent (5/5), round-trip min/avg/max = 10/12/20 ms&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt; ping lab.local&lt;/P&gt;&lt;P&gt;ping lab.local&lt;BR /&gt;^&lt;BR /&gt;ERROR: % Invalid Hostname&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt; ping cisco.com&lt;BR /&gt;Please use 'CTRL+C' to cancel/abort...&lt;/P&gt;&lt;P&gt;ping cisco.com&lt;BR /&gt;^&lt;BR /&gt;ERROR: % Invalid Hostname&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt; ping system cisco.com&lt;BR /&gt;PING cisco.com (72.163.4.185) 56(84) bytes of data.&lt;BR /&gt;64 bytes from redirect-ns.cisco.com (72.163.4.185): icmp_seq=1 ttl=238 time=21.4 ms&lt;BR /&gt;^C64 bytes from 72.163.4.185: icmp_seq=2 ttl=238 time=12.8 ms&lt;/P&gt;&lt;P&gt;--- cisco.com ping statistics ---&lt;BR /&gt;2 packets transmitted, 2 received, 0% packet loss, time 5054ms&lt;BR /&gt;rtt min/avg/max/mdev = 12.811/17.087/21.363/4.276 ms&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt;&lt;BR /&gt;&amp;gt; show dns system&lt;BR /&gt;search lab.local&lt;BR /&gt;nameserver 192.168.10.5&lt;BR /&gt;nameserver 8.8.8.8&lt;BR /&gt;nameserver 2603:8080:6100:2984::1&lt;/P&gt;&lt;P&gt;&amp;gt;&lt;BR /&gt;&amp;gt; show network&lt;BR /&gt;===============[ System Information ]===============&lt;BR /&gt;Hostname : FTD1&lt;BR /&gt;Domains : lab.local&lt;BR /&gt;DNS Servers : 192.168.10.5&lt;BR /&gt;8.8.8.8&lt;BR /&gt;2603:8080:6100:2984::1&lt;BR /&gt;DNS from router : enabled&lt;BR /&gt;Management port : 8305&lt;BR /&gt;IPv4 Default route&lt;BR /&gt;Gateway : 192.168.1.1&lt;/P&gt;&lt;P&gt;======================[ eth0 ]======================&lt;BR /&gt;State : Enabled&lt;BR /&gt;Link : Up&lt;BR /&gt;Channels : Management &amp;amp; Events&lt;BR /&gt;Mode : Non-Autonegotiation&lt;BR /&gt;MDI/MDIX : Auto/MDIX&lt;BR /&gt;MTU : 1500&lt;BR /&gt;MAC Address : 50:00:00:11:00:00&lt;BR /&gt;----------------------[ IPv4 ]----------------------&lt;BR /&gt;Configuration : Manual&lt;BR /&gt;Address : 192.168.1.201&lt;BR /&gt;Netmask : 255.255.255.0&lt;BR /&gt;Gateway : 192.168.1.1&lt;BR /&gt;----------------------[ IPv6 ]----------------------&lt;BR /&gt;Configuration : Disabled&lt;/P&gt;&lt;P&gt;===============[ Proxy Information ]================&lt;BR /&gt;State : Disabled&lt;BR /&gt;Authentication : Disabled&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 19:11:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4829917#M1100230</guid>
      <dc:creator>SecurityJumbo</dc:creator>
      <dc:date>2023-05-06T19:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower-DNS Not Resolving</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4829921#M1100231</link>
      <description>&lt;P&gt;&lt;SPAN&gt;ping cisco.com but there is default domain&amp;nbsp;lab.local&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Ping cisco whiutout add domain&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 May 2023 19:32:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4829921#M1100231</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-06T19:32:42Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower-DNS Not Resolving</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4830120#M1100236</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752"&gt;@MHM Cisco World&lt;/a&gt;&amp;nbsp; Not sure what you mean. The DNS is not resolving neither to the internal network or external network. I can ping any address through the data interfaces.&lt;/P&gt;&lt;P&gt;But the DNS is not working through the data interfaces (INSIDE or OUTSIDE). It is only working through the Management interface when I do (ping system &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;) or (ping system lab.local)&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2023 18:02:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4830120#M1100236</guid>
      <dc:creator>SecurityJumbo</dc:creator>
      <dc:date>2023-05-07T18:02:01Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower-DNS Not Resolving</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4830127#M1100237</link>
      <description>&lt;P&gt;Dns in firepower points&lt;/P&gt;
&lt;P&gt;1-Firepower not support dns internal server (as I know until now)&lt;/P&gt;
&lt;P&gt;2-firepower support dns through mgmt for update and license&lt;/P&gt;
&lt;P&gt;3-firepower support dns through IN or Out for any acl use fqdn or remote access.&lt;/P&gt;
&lt;P&gt;That I hope answer you&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 07 May 2023 18:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/4830127#M1100237</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-05-07T18:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower-DNS Not Resolving</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/5232969#M1117996</link>
      <description>&lt;P&gt;Did you get an answer on this? I am experiencing a similar if not the same thing. I had DNS servers configured on the inside interface that were working without issue. I upgraded FMC only to 7.4.2 and now DNS resolution doesn't work on the FTDs. I checked the running-config and it wiped the DNS servers I had configured off the inside interface. I checked FMC, and my DNS Server Group is still configured with IPs and that group is configured in Platform Settings... So... it's configured, but not configured. I open a case with TAC but still waiting to hear back. Just wondering if you had any progress.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 16:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/5232969#M1117996</guid>
      <dc:creator>brettp</dc:creator>
      <dc:date>2024-12-05T16:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower-DNS Not Resolving</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/5233049#M1117999</link>
      <description>&lt;P&gt;You're issue may or may not be the same as mine, but I ultimately fixed it, so I figured I'd post my fix in case anyone else finds this post with a similar situation. FMC was showing my DNS Server Group as good. My DNS Settings in Platform Settings as good. But DNS wasn't resolving. I checked the running-config via diagnostic CLI and noticed that, even the DNS was configured in FMC and supposed deployed, the config was NOT on the FTDs. I first tried removing a DNS server from the group, to initiate a change, but FMC did not see any changes to deploy. I then deleted the DNS Server Group in DNS Platform Settings and simply re-added it. I was then able to deploy the DNS settings, which then appear in the running-config.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Dec 2024 18:39:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/5233049#M1117999</guid>
      <dc:creator>brettp</dc:creator>
      <dc:date>2024-12-05T18:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower-DNS Not Resolving</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/5245778#M1118679</link>
      <description>&lt;P&gt;Can confirm thsi problem and fix as I experienced the same upgrading from 7.2.7 to 7.2.9&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 17:50:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/5245778#M1118679</guid>
      <dc:creator>allen.steckling</dc:creator>
      <dc:date>2025-01-10T17:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower-DNS Not Resolving</title>
      <link>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/5337446#M1123120</link>
      <description>&lt;P&gt;We saw this issue while updating to 7.4.2.1 -&amp;gt; 7.6.2 (1k series) AND 7.6.2 -&amp;gt; 7.6.2.1 (3k series) - after the upgrade the firewall didn't resolve FQDN for ACPs ACEs. To resolve it we did the following via the CLI, "clear dns", then "dns update".&lt;/P&gt;&lt;P&gt;I found the bug &lt;A href="https://bst.cisco.com/bugsearch/bug/CSCwm92310" target="_blank" rel="noopener"&gt;https://bst.cisco.com/bugsearch/bug/CSCwm92310&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 08:44:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-dns-not-resolving/m-p/5337446#M1123120</guid>
      <dc:creator>Michael Bartholomæussen</dc:creator>
      <dc:date>2025-10-10T08:44:46Z</dc:date>
    </item>
  </channel>
</rss>

