<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic In my opinion, the only way in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-not-resolving-after-launching-vpn-client-using-split-dns/m-p/2993844#M148300</link>
    <description>&lt;P&gt;In my opinion, the only way is to NAT the remote dns server on some dummy ip address and use that ip address for split dns. That way, the anyconnect client will be able to differentiate between the 2 dns servers. Kind of tricky, but should work. NAT needs to be done on the corporate office and split tunnel needs to be modified to send traffic for that dummy ip/network through tunnel.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;-AJ&lt;/P&gt;</description>
    <pubDate>Thu, 22 Dec 2016 10:05:29 GMT</pubDate>
    <dc:creator>Ajay Saini</dc:creator>
    <dc:date>2016-12-22T10:05:29Z</dc:date>
    <item>
      <title>DNS not resolving after launching VPN client using split-DNS from branch office</title>
      <link>https://community.cisco.com/t5/network-security/dns-not-resolving-after-launching-vpn-client-using-split-dns/m-p/2993843#M148299</link>
      <description>&lt;P&gt;We have a hub &amp;amp; spoke network where branch offices are connected to the corporate office via L2L VPN with ASA's on both sides. There are no Domain Controllers at the Branch offices so DHCP is configured on the ASA with the primary DNS server being an Internal DNS server in the corporate office and the secondary is a public DNS server in case the tunnel goes down. Everything seems to be working with this. The corporate ASA also hosts an SSL VPN for remote clients which is using split-tunneling and split-DNS and this works fine when clients connect from outside of the offices.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The problem we're having is if a client needs to launch AnyConnect from one of the branch offices. DNS resolution works for the internal DNS domains configured&amp;nbsp;in the split-DNS but it won't resolve external domains. IP traffic gets routed properly and we can ping any address we need to by IP but we can't resolve DNS to those external domains.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The way things are configured a client in the branch has a primary DNS server located in the corporate network with the address of 10.1.2.3. When the client connects with AnyConnect, his DNS server for that connections would also be 10.1.2.3. With the VPN connected the 10.1.2.3 address would get routed over the SSL VPN. The split-DNS rule tells the client not to use the AnyConnect DNS server but instead use the DNS server attached to the physical network adapter ... it seems like a catch 22. How should I configure this to get external DNS to resolve from the branch offices?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-not-resolving-after-launching-vpn-client-using-split-dns/m-p/2993843#M148299</guid>
      <dc:creator>meydenbauer</dc:creator>
      <dc:date>2019-03-12T08:41:40Z</dc:date>
    </item>
    <item>
      <title>In my opinion, the only way</title>
      <link>https://community.cisco.com/t5/network-security/dns-not-resolving-after-launching-vpn-client-using-split-dns/m-p/2993844#M148300</link>
      <description>&lt;P&gt;In my opinion, the only way is to NAT the remote dns server on some dummy ip address and use that ip address for split dns. That way, the anyconnect client will be able to differentiate between the 2 dns servers. Kind of tricky, but should work. NAT needs to be done on the corporate office and split tunnel needs to be modified to send traffic for that dummy ip/network through tunnel.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;HTH&lt;/P&gt;
&lt;P&gt;-AJ&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2016 10:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-not-resolving-after-launching-vpn-client-using-split-dns/m-p/2993844#M148300</guid>
      <dc:creator>Ajay Saini</dc:creator>
      <dc:date>2016-12-22T10:05:29Z</dc:date>
    </item>
    <item>
      <title>NAT needs to be done on the</title>
      <link>https://community.cisco.com/t5/network-security/dns-not-resolving-after-launching-vpn-client-using-split-dns/m-p/2993845#M148303</link>
      <description>&lt;P&gt;NAT needs to be done on the corporate office and split tunnel needs to be modified to send traffic for that dummy ip/network through tunnel. This will avoid split brain scenario.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Dec 2016 10:54:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-not-resolving-after-launching-vpn-client-using-split-dns/m-p/2993845#M148303</guid>
      <dc:creator>Farhan Mohamed</dc:creator>
      <dc:date>2016-12-24T10:54:38Z</dc:date>
    </item>
  </channel>
</rss>

