<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower 1140 DNS hostname resolution issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867984#M1102331</link>
    <description>&lt;P&gt;DNS UDP port 53 is closed according to above packet tracer,&amp;nbsp;&lt;BR /&gt;there is any ACL apply to INside interface ?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jul 2023 13:03:31 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2023-07-05T13:03:31Z</dc:date>
    <item>
      <title>Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867968#M1102325</link>
      <description>&lt;P&gt;I have Firepower 1140 running ASA code 9.14.1 .&lt;/P&gt;&lt;P&gt;when i ping 8.8.8.8 its happening but when i ping wwwogoogle.com or tools.cisco.com its not pinging.&lt;/P&gt;&lt;P&gt;i have attached the log files along with debug dns as attachment for reference , let me know what i can do&lt;/P&gt;&lt;P&gt;i have configured default DNS for domain lookup outside for dns 8.8.8.8, 4.2.2.2,&amp;nbsp;&lt;SPAN&gt;208.67.222.222 208.67.220.220.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Need some help Since TAC has refused assistance as this is a new deployment.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 12:48:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867968#M1102325</guid>
      <dc:creator>Singh007</dc:creator>
      <dc:date>2023-07-05T12:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867969#M1102326</link>
      <description>&lt;P&gt;attached file for reference&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 12:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867969#M1102326</guid>
      <dc:creator>Singh007</dc:creator>
      <dc:date>2023-07-05T12:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867971#M1102327</link>
      <description>&lt;P&gt;i have tried to ping tools.cisco.com ip&amp;nbsp;72.163.4.38 and its working and attached in the file for reference&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 12:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867971#M1102327</guid>
      <dc:creator>Singh007</dc:creator>
      <dc:date>2023-07-05T12:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867977#M1102328</link>
      <description>&lt;P&gt;you control this FPR with FMC ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 12:55:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867977#M1102328</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-05T12:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867978#M1102329</link>
      <description>&lt;P&gt;i also tried doing packet-tracer for 8.8.8.8 but hitting implicit deny:&lt;/P&gt;&lt;P&gt;packet-tracer input outside udp 103.48.47.20 56789 8.8.8.8 53 detailed&lt;/P&gt;&lt;P&gt;Phase: 1&lt;BR /&gt;Type: INPUT-ROUTE-LOOKUP&lt;BR /&gt;Subtype: Resolve Egress Interface&lt;BR /&gt;Result: ALLOW&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;BR /&gt;Found next-hop 103.48.47.1 using egress ifc outside&lt;/P&gt;&lt;P&gt;Phase: 2&lt;BR /&gt;Type: ACCESS-LIST&lt;BR /&gt;Subtype:&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Implicit Rule&lt;BR /&gt;Additional Information:&lt;BR /&gt;Forward Flow based lookup yields rule:&lt;BR /&gt;in id=0x7fd6b645cb90, priority=501, domain=permit, deny=true&lt;BR /&gt;hits=8, user_data=0x7, cs_id=0x0, reverse, flags=0x0, protocol=0&lt;BR /&gt;src ip/id=103.48.47.20, mask=255.255.255.255, port=0, tag=any&lt;BR /&gt;dst ip/id=0.0.0.0, mask=0.0.0.0, port=0, tag=any,, dscp=0x0&lt;BR /&gt;input_ifc=outside, output_ifc=any&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: outside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;BR /&gt;Drop-reason: (acl-drop) Flow is denied by configured rule, Drop-location: frame 0x000055c94e727680 flow (NA)/NA&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 12:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867978#M1102329</guid>
      <dc:creator>Singh007</dc:creator>
      <dc:date>2023-07-05T12:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867984#M1102331</link>
      <description>&lt;P&gt;DNS UDP port 53 is closed according to above packet tracer,&amp;nbsp;&lt;BR /&gt;there is any ACL apply to INside interface ?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jul 2023 13:03:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4867984#M1102331</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-05T13:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4868750#M1102359</link>
      <description>&lt;P&gt;this is a new implementation, the two other firewalls fpr 1010 is working fine with same DNS config. But this is not working.&lt;/P&gt;&lt;P&gt;This will be managed by ASDM , but currently its working only via CLI&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 08:52:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4868750#M1102359</guid>
      <dc:creator>Singh007</dc:creator>
      <dc:date>2023-07-06T08:52:14Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4868756#M1102360</link>
      <description>&lt;P&gt;Share full config if you use cli&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 09:02:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4868756#M1102360</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-06T09:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4869844#M1102397</link>
      <description>&lt;P&gt;You should specify the inside interface in the packet tracer not the outside one. Also, could you please try to remove the domain name from the DNS group and try again?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 15:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4869844#M1102397</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-07-07T15:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 1140 DNS hostname resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4869867#M1102402</link>
      <description>&lt;P&gt;totally correct He must use INside not OUTside&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 16:48:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-1140-dns-hostname-resolution-issue/m-p/4869867#M1102402</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-07-07T16:48:35Z</dc:date>
    </item>
  </channel>
</rss>

