<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAT64  sending an AAAA record instead of an A record on to IPv4-LA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044024#M1110022</link>
    <description>&lt;P&gt;No. I don't. How can I configure a DNS64 server?&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2024 14:27:07 GMT</pubDate>
    <dc:creator>ralfmeirsman-0</dc:creator>
    <dc:date>2024-03-19T14:27:07Z</dc:date>
    <item>
      <title>NAT64  sending an AAAA record instead of an A record on to IPv4-LAN</title>
      <link>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5043740#M1110016</link>
      <description>&lt;P&gt;Here is the situation:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;(IPv6-LAN) *&amp;nbsp; &amp;nbsp;(IPv4-LAN)&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*******************&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; ping -t &lt;A href="http://www.tijd.be&amp;nbsp;" target="_blank" rel="noopener"&gt;www.tijd.be&amp;nbsp;&lt;/A&gt; &amp;nbsp; -&amp;gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; *&amp;nbsp; NAT64 - Router *&amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;gt; AAAA Record asking for IPV6-address&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*******************&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;resolution&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AAAA record asking for IPv6-resolution&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;should be A record asking for IPv4-resolution&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;*&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;The router sends out an AAAA record instead of an A record. Therefore DNS server comes back with an IPv6 instead of an IPv4.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Configuration is attached. What to do?&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Regards.&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 19 Mar 2024 11:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5043740#M1110016</guid>
      <dc:creator>ralfmeirsman-0</dc:creator>
      <dc:date>2024-03-19T11:14:38Z</dc:date>
    </item>
    <item>
      <title>Re: NAT64  sending an AAAA record instead of an A record on to IPv4-LA</title>
      <link>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5043956#M1110021</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1703964"&gt;@ralfmeirsman-0&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This is the expected behavior. The AAAA queries are not sent by the router, but rather by the workstation on the ipv6 LAN. NAT64 needs to be deployed along with DNS64. DNS64 will receive the AAAA query from the ipv6 LAN and perform a AAAA query. If no AAAA record is available, it will perform a A query and return a synthetic AAAA record (NAT64 prefix + IPv4 address). The router will then use this synthetic IPv6 address to perform the NAT64 translation from IPv6 to IPv4.&lt;/P&gt;
&lt;P&gt;Most DNS servers can be configured as DNS64. Do you have a DNS64?&lt;/P&gt;
&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 13:52:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5043956#M1110021</guid>
      <dc:creator>Harold Ritter</dc:creator>
      <dc:date>2024-03-19T13:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: NAT64  sending an AAAA record instead of an A record on to IPv4-LA</title>
      <link>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044024#M1110022</link>
      <description>&lt;P&gt;No. I don't. How can I configure a DNS64 server?&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 14:27:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044024#M1110022</guid>
      <dc:creator>ralfmeirsman-0</dc:creator>
      <dc:date>2024-03-19T14:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: NAT64  sending an AAAA record instead of an A record on to IPv4-LA</title>
      <link>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044264#M1110034</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1703964"&gt;@ralfmeirsman-0&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;It depends what DNS you use. For instance, if you use BIND, you can refer to the BIND documentation to find out how to configure DNS64.&lt;/P&gt;
&lt;P&gt;If you currently don't have your own DNS server, you could use Google public DNS64 servers.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://developers.google.com/speed/public-dns/docs/dns64" target="_blank" rel="noopener"&gt;https://developers.google.com/speed/public-dns/docs/dns64&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 18:10:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044264#M1110034</guid>
      <dc:creator>Harold Ritter</dc:creator>
      <dc:date>2024-03-19T18:10:40Z</dc:date>
    </item>
    <item>
      <title>Re: NAT64  sending an AAAA record instead of an A record on to IPv4-LA</title>
      <link>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044377#M1110041</link>
      <description>&lt;P&gt;I will certainly try BIND.&lt;/P&gt;&lt;P&gt;However when I use a Google Public DNS64 server as e.g. 2001:4860:4860::6464,it is not able to reach the DNS64 server it self over the NAT64 router. It strips the NAT64 prefix 2001:4860:4860 and searches for IPv4 0.0.100.100 (0 0 : 64 64) .&lt;/P&gt;&lt;P&gt;How can a Public DNS64 be used in this configuration in order to be able to route to 2001:4860:4860::6464 over the IPv4 network?&lt;/P&gt;&lt;P&gt;Regards.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 19:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044377#M1110041</guid>
      <dc:creator>ralfmeirsman-0</dc:creator>
      <dc:date>2024-03-19T19:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: NAT64  sending an AAAA record instead of an A record on to IPv4-LA</title>
      <link>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044397#M1110046</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1703964"&gt;@ralfmeirsman-0&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Sorry I thought you had connectivity to the ipv6 Internet. Accessing the Google public DNS64 servers will only work if you have ipv6 Internet connectivity.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So in your case, you will need to go with a local DNS64 server.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 19:26:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044397#M1110046</guid>
      <dc:creator>Harold Ritter</dc:creator>
      <dc:date>2024-03-19T19:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: NAT64  sending an AAAA record instead of an A record on to IPv4-LA</title>
      <link>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044432#M1110061</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1703964"&gt;@ralfmeirsman-0&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;One more thing. Without ipv6 Internet connectivity, nat64/dns64 will only work towards Internet hosts that only have a A record.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For hosts that have a AAAA record, the dns64 will return the AAAA record with the real ipv6 address. This address will be unreachable as you do not have ipv6 Internet connectivity.&lt;/P&gt;
&lt;P&gt;For hosts that only have a A record, the dns64 will generate a synthetic AAAA record from the A response (nat64 prefix + ipv4 address), which will cause the nat64 device to translate the ipv6 traffic towards that address to ipv4.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 20:24:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nat64-sending-an-aaaa-record-instead-of-an-a-record-on-to-ipv4/m-p/5044432#M1110061</guid>
      <dc:creator>Harold Ritter</dc:creator>
      <dc:date>2024-03-19T20:24:19Z</dc:date>
    </item>
  </channel>
</rss>

