<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is your DNS resolving the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748579#M178052</link>
    <description>&lt;P&gt;Is your DNS resolving the domain to same IP?&lt;/P&gt;&lt;P&gt;Try nslookup for the domain from the PC and verify if its same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Share your findings.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 13 Oct 2015 14:22:55 GMT</pubDate>
    <dc:creator>Rishabh Seth</dc:creator>
    <dc:date>2015-10-13T14:22:55Z</dc:date>
    <item>
      <title>How to NAT configuration on ASA 5520 8.4(2)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748573#M178026</link>
      <description>&lt;P&gt;I got some issues with NAT configuration. I have a host server&amp;nbsp;with 2 service: WWW and DNS. I want to access Server&amp;nbsp;via IP address and domain&amp;nbsp;from outside.&amp;nbsp;How to configuration&amp;nbsp;ASA and router??? &amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank's!!!&lt;/P&gt;&lt;P&gt;P/s:&amp;nbsp;my english is not good !!! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://i.imgur.com/kpAutzT.png" target="_blank"&gt;&lt;IMG alt="" src="http://i.imgur.com/kpAutzT.png" style="width: 1189px; height: 841px;" /&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 06:43:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748573#M178026</guid>
      <dc:creator>pokemon284</dc:creator>
      <dc:date>2019-03-12T06:43:50Z</dc:date>
    </item>
    <item>
      <title>Hi,From diagram it looks like</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748574#M178033</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From diagram it looks like you are trying to access 192.168.4.11 from 192.168.0.100.&lt;/P&gt;&lt;P&gt;You need following :&lt;/P&gt;&lt;P&gt;Router:&lt;/P&gt;&lt;P&gt;1:Route for 192.168.4.11.&lt;/P&gt;&lt;P&gt;2: ACL to permit www and DNS traffic.&lt;/P&gt;&lt;P&gt;ASA:&lt;/P&gt;&lt;P&gt;1:Verify the security level or ingress and egress interface. Command: show nameif.&lt;/P&gt;&lt;P&gt;2: Check if traffic is initiated from higher security level or lower.&lt;/P&gt;&lt;P&gt;3: Traffic from higher security to lower will be allowed by default (if there is no explicit ACL applied on that interface.)&lt;/P&gt;&lt;P&gt;4:If traffic is initiated from lower security level then create an ACL to permit www and dos traffic for particular destination and source. In case the traffic is initiated from higher security level and you hav have an existing ACL then add an entry to permit www and DNS traffic.&lt;/P&gt;&lt;P&gt;5. Create route on ASA for 192.168.0.100 for return traffic.&lt;/P&gt;&lt;P&gt;Hope it helps!!!!&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;Mark answer as correct if it helps in resolving your query!!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 05:12:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748574#M178033</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-12T05:12:37Z</dc:date>
    </item>
    <item>
      <title>I config Nat for Web Server</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748575#M178039</link>
      <description>&lt;P&gt;I mean: configuration&amp;nbsp;NAT for 2 services on&amp;nbsp;the same host (192.168.4.11:80 and 192.168.4.11:53).&amp;nbsp;I configed Nat for Web Server with port 80 but i can't config Nat for DNS Server. Can u show me command line???&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Oct 2015 06:59:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748575#M178039</guid>
      <dc:creator>pokemon284</dc:creator>
      <dc:date>2015-10-12T06:59:41Z</dc:date>
    </item>
    <item>
      <title>help me, please!!! :(</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748576#M178041</link>
      <description>&lt;P&gt;help me, please!!! &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 08:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748576#M178041</guid>
      <dc:creator>pokemon284</dc:creator>
      <dc:date>2015-10-13T08:15:32Z</dc:date>
    </item>
    <item>
      <title>What is the issue that you</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748577#M178046</link>
      <description>&lt;P&gt;What is the issue that you are facing?&lt;/P&gt;&lt;P&gt;Are you trying to configure object nat?&lt;/P&gt;&lt;P&gt;If yes then ensure you have one NAT rule per object.&lt;/P&gt;&lt;P&gt;Create two objects for www and dns nat rules.&lt;/P&gt;&lt;P&gt;eg:&lt;/P&gt;&lt;P&gt;Object network www&lt;/P&gt;&lt;P&gt;host 10.1.1.1&lt;/P&gt;&lt;P&gt;nat (inside,outside) static &amp;lt;ip/interface&amp;gt; service tcp 80 80&lt;/P&gt;&lt;P&gt;Object network DNS&lt;/P&gt;&lt;P&gt;host 10.1.1.1&lt;/P&gt;&lt;P&gt;nat (inside,outside) static &amp;lt;ip/interface&amp;gt; service udp 53 53&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also configure appropriate ACL to permit traffic for www and dns.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 09:14:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748577#M178046</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-13T09:14:31Z</dc:date>
    </item>
    <item>
      <title>- In ASA: object network</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748578#M178050</link>
      <description>&lt;P&gt;- In &lt;STRONG&gt;ASA&lt;/STRONG&gt;:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;EM&gt;object network PublicWWW&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;EM&gt;host 192.168.4.11&lt;BR /&gt;&amp;nbsp;nat (dmz,outside) static 10.0.0.3 service tcp www www&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;EM&gt;object network PublicDNS&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;EM&gt;host 192.168.4.11&lt;BR /&gt;&amp;nbsp;nat (dmz,outside) static 10.0.0.4 service udp domain domain&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;EM&gt;access-list WD&amp;nbsp;extended permit tcp any object PublicWWW eq www&lt;BR /&gt;access-list WD&amp;nbsp;extended permit udp any object PublicDNS eq domain&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;EM&gt;access-group WD in in out&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- In &lt;STRONG&gt;Router&lt;/STRONG&gt;:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;EM&gt;ip nat inside source static tcp 10.0.0.3 80 192.168.0.100 80&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;EM&gt;ip nat inside source static udp 10.0.0.4 53 192.168.0.100 53&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then, I&amp;nbsp;access website with IP =&amp;gt; ok&lt;/P&gt;&lt;P&gt;and access website with domain&amp;nbsp;=&amp;gt; no =&amp;gt; Why ???&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 14:17:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748578#M178050</guid>
      <dc:creator>pokemon284</dc:creator>
      <dc:date>2015-10-13T14:17:30Z</dc:date>
    </item>
    <item>
      <title>Is your DNS resolving the</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748579#M178052</link>
      <description>&lt;P&gt;Is your DNS resolving the domain to same IP?&lt;/P&gt;&lt;P&gt;Try nslookup for the domain from the PC and verify if its same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Share your findings.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 14:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748579#M178052</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-13T14:22:55Z</dc:date>
    </item>
    <item>
      <title>Request timed out??? Why???</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748580#M178053</link>
      <description>&lt;P&gt;Request timed out??? Why???&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" src="http://d.f24.photo.zdn.vn/upload/original/2015/10/13/22/43/3188096219_194811050_574_574.jpg" style="width: 720px; height: 304px;" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 15:44:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748580#M178053</guid>
      <dc:creator>pokemon284</dc:creator>
      <dc:date>2015-10-13T15:44:27Z</dc:date>
    </item>
    <item>
      <title>This seems to a issue with</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748581#M178055</link>
      <description>&lt;P&gt;This seems to a issue with your dns. Try checking your dons server. Looks like end client is not able to get name resolution for the domain you are trying to ping.&lt;/P&gt;&lt;P&gt;As long as website is accessible over IP, your ASA NAT config is correct.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;R.Seth&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 15:50:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748581#M178055</guid>
      <dc:creator>Rishabh Seth</dc:creator>
      <dc:date>2015-10-13T15:50:42Z</dc:date>
    </item>
    <item>
      <title>Thank's for your help!!! :D</title>
      <link>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748582#M178056</link>
      <description>&lt;P&gt;Thank's for your help!!! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Oct 2015 16:08:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-nat-configuration-on-asa-5520-8-4-2/m-p/2748582#M178056</guid>
      <dc:creator>pokemon284</dc:creator>
      <dc:date>2015-10-13T16:08:07Z</dc:date>
    </item>
  </channel>
</rss>

