<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Found the issue. The DNS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652263#M195603</link>
    <description>&lt;P&gt;Found the issue. The DNS Inspection was not turned on on first pair... Now I have to do a change request to enabled DNS inspection...&lt;/P&gt;</description>
    <pubDate>Mon, 30 Mar 2015 19:57:46 GMT</pubDate>
    <dc:creator>SIMMN</dc:creator>
    <dc:date>2015-03-30T19:57:46Z</dc:date>
    <item>
      <title>DNS Rewrite/Translate DNS reply issue on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652255#M195595</link>
      <description>&lt;P&gt;I have two pairs of ASA 5510 running 8.4(6) for two different networks. I configured 1-TO-1 NAT rule on each pair for internal server and enabled option "Translate DNS reply". However it seems like the rule is working on one pair but not the other.&lt;/P&gt;&lt;P&gt;Here is semi-detail of the setup (8.8.8.8 is used as DNS server for both setup on client.).&lt;/P&gt;&lt;P&gt;For first pair,&lt;/P&gt;&lt;P&gt;The internal server is @ 172.16.1.100; the client is @ 172.16.2.100. Their default gateway is 172.16.x.1 on the same core switch/router, which will route outbound traffic to ASA lan interface @ 10.1.1.1. The ASA mapped server to 1.2.3.4 on internet with FQDN web1.abc.com.&lt;/P&gt;&lt;P&gt;If I configured 8.8.8.8 as dns server on client and then try to reach web1.abc.com, I still got resolved to 1.2.3.4 instead of 172.16.1.100 as expected with turning on "Translate DNS reply" inside NAT rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the second pair,&lt;/P&gt;&lt;P&gt;The server is @ 172.16.1.100 and connected to ASA dmz interface. The client is @ 172.16.2.100 on the LAN interface. ASA is the default gateway. ASA mapped server to 1.2.3.5 on internet web2.abc.com.&lt;/P&gt;&lt;P&gt;If I configured 8.8.8.8 as dns server on client and then try to reach web2.abc.com, the FQDN is resolved to 172.16.1.100 as expected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I guess will the difference between two setup break the functionality of DNS Rewrite/Translate DNS reply?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:42:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652255#M195595</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2019-03-12T05:42:13Z</dc:date>
    </item>
    <item>
      <title>Hi,Are the NAT and Service</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652256#M195596</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Are the NAT and Service-policy on the ASA device which is not working correctly ?&lt;/P&gt;&lt;P&gt;Can you post the relevant configuration ?&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Fri, 27 Mar 2015 13:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652256#M195596</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-03-27T13:12:32Z</dc:date>
    </item>
    <item>
      <title>Regardless of if the ASA is</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652257#M195597</link>
      <description>&lt;P&gt;Regardless of if the ASA is the default gateway or the L3 switch is the default gateway, the ASA should rewrite the DNS request.&amp;nbsp; If both ASA configuration are exaclty the same, I would look into a possible routing issue on the switch for the first pair.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Sat, 28 Mar 2015 21:14:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652257#M195597</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-03-28T21:14:11Z</dc:date>
    </item>
    <item>
      <title>They are not 100% the same</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652258#M195598</link>
      <description>&lt;P&gt;They are not 100% the same actually. The first pair has client and server connected to the same physical interface while the second pair has client on LAN and server on DMZ physical interfaces.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 11:39:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652258#M195598</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2015-03-30T11:39:12Z</dc:date>
    </item>
    <item>
      <title>Here is the configure I have</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652259#M195599</link>
      <description>&lt;P&gt;Here is the configure I have on the first ASA pair.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;object network 172.16.1.100-1to1-NAT&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;host 172.16.1.100&lt;BR /&gt;&amp;nbsp;nat (LAN,INTERNET) static 1.2.3.4 dns&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the second pair.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;object network 172.16.1.100-1to1-NAT&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;host 172.16.1.100&lt;BR /&gt;&amp;nbsp;nat (DMZ,INTERNET) static 1.2.3.4 dns&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Let me know if further is required.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 11:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652259#M195599</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2015-03-30T11:51:33Z</dc:date>
    </item>
    <item>
      <title>Hi,I think you actually</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652260#M195600</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I think you actually answered the query in your previous post.&lt;/P&gt;&lt;P&gt;As per your description , First Pair , has client and server connected to the same physical interface. If this is the case , the DNS query would never even traverse the ASA device and hence the rewrite will never work.&lt;/P&gt;&lt;P&gt;For it to work , you need to have DNS server and Client behind different interface or in different broadcast domains.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 11:56:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652260#M195600</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-03-30T11:56:26Z</dc:date>
    </item>
    <item>
      <title>I mean the web server not the</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652261#M195601</link>
      <description>&lt;P&gt;I mean the web server not the DNS server.&lt;/P&gt;&lt;P&gt;In both my setup, I use 8.8.8.8 as the DNS server.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 17:42:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652261#M195601</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2015-03-30T17:42:08Z</dc:date>
    </item>
    <item>
      <title>What I meant is if the dhcp</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652262#M195602</link>
      <description>&lt;P&gt;What I meant is if the dhcp setup is the same, in that both use 8.8.8.8 as the dns server then the DNS query will transit the ASA and the ASA should rewrite the DNS reply to the private IP of the server.&amp;nbsp; This means that you will also need to make sure that traffic from the local LAN to the private IP of the server needs to be permitted in the ACL on the LAN interface if that traffic goes through the ASA again to reach the server (if it isnt already permitted that is).&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to select a correct answer and rate helpful posts&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 19:33:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652262#M195602</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2015-03-30T19:33:12Z</dc:date>
    </item>
    <item>
      <title>Found the issue. The DNS</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652263#M195603</link>
      <description>&lt;P&gt;Found the issue. The DNS Inspection was not turned on on first pair... Now I have to do a change request to enabled DNS inspection...&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2015 19:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-translate-dns-reply-issue-on-asa-5510/m-p/2652263#M195603</guid>
      <dc:creator>SIMMN</dc:creator>
      <dc:date>2015-03-30T19:57:46Z</dc:date>
    </item>
  </channel>
</rss>

