<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic There really aren't many in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435174#M267804</link>
    <description>&lt;P&gt;There really aren't many commands on the ASA to 100% confirm it is a DNS problem.&amp;nbsp; However there are a few things you can check...among them the &lt;STRONG&gt;show conn protocol udp port 53&lt;/STRONG&gt; command. A quick way to define if it is DNS or not is to ping the DNS server private IP from the ASA.&lt;/P&gt;&lt;P&gt;You can also from a host machine ping an global DNS server on the internet such as 4.2.2.2 or 8.8.8.8.&amp;nbsp; If you are able to ping that but are unable to browse to the internet using a URL then it is most likely a DNS resolution issue.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
    <pubDate>Sat, 05 Apr 2014 16:05:46 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2014-04-05T16:05:46Z</dc:date>
    <item>
      <title>DNS server lookups  and sh conn in ASA</title>
      <link>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435173#M267803</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Hi Everyone,&lt;/P&gt;&lt;P&gt;We have Internal DNS server that goes to ISP via our Internet &amp;nbsp;ASA for DNS lookups.&lt;/P&gt;&lt;P&gt;Recently physical connection between our Internal DNS server and Internet ASA broke due to bad cabling.&lt;/P&gt;&lt;P&gt;When users try to open website they get message page can not be displayed.&lt;/P&gt;&lt;P&gt;When I did sh conn on internet ASA it was showing number of connections that were established earlier.&lt;/P&gt;&lt;P&gt;I need to know if this happens again what troubleshooting command I should run in ASA to figure out DNS lookup is not working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I run sh conn should I&amp;nbsp; look for some flag that tells me issue is with DNS?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435173#M267803</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T04:02:11Z</dc:date>
    </item>
    <item>
      <title>There really aren't many</title>
      <link>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435174#M267804</link>
      <description>&lt;P&gt;There really aren't many commands on the ASA to 100% confirm it is a DNS problem.&amp;nbsp; However there are a few things you can check...among them the &lt;STRONG&gt;show conn protocol udp port 53&lt;/STRONG&gt; command. A quick way to define if it is DNS or not is to ping the DNS server private IP from the ASA.&lt;/P&gt;&lt;P&gt;You can also from a host machine ping an global DNS server on the internet such as 4.2.2.2 or 8.8.8.8.&amp;nbsp; If you are able to ping that but are unable to browse to the internet using a URL then it is most likely a DNS resolution issue.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2014 16:05:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435174#M267804</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-05T16:05:46Z</dc:date>
    </item>
    <item>
      <title>Also, if you manually set a</title>
      <link>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435175#M267805</link>
      <description>&lt;P&gt;Also, if you manually set a DNS server on the host machine to a public DNS and are able to browse to the internet then...but you are unable to do so using your local DNS server, then you have also identified it as a local DNS problem.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2014 16:09:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435175#M267805</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-05T16:09:27Z</dc:date>
    </item>
    <item>
      <title> During outage when i did</title>
      <link>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435176#M267807</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;During outage when i did nslookup to google.com&lt;/P&gt;&lt;P&gt;it was showing as request time out.&lt;/P&gt;&lt;P&gt;Also when now all is working fine i ran the command&lt;BR /&gt;&lt;STRONG&gt;show conn protocol udp port 53&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;it shows 152 in use.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;So when DNS is not working what should above command show&amp;nbsp; 0 in use?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Also traffic flow for DNS server is&lt;/P&gt;&lt;P&gt;Server ----Sw1---------sw2(server default gateway)--------------Sw1--------ASA.&lt;/P&gt;&lt;P&gt;Sp ping to server should be ok during the outage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As ping is not allowed from the internal Network.&lt;/P&gt;&lt;P&gt;What i did during outage was to ping 4.2.2.2 from edge router and that ping worked fine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2014 16:27:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435176#M267807</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2014-04-05T16:27:56Z</dc:date>
    </item>
    <item>
      <title>There is an issue with using</title>
      <link>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435177#M267809</link>
      <description>&lt;P&gt;There is an issue with using the show conn for troubleshooting DNS issues which i forgot to mention, and that is its default timeout of 1 hour. So eventually the connections will timeout and the output of the show conn protocol udp port 53 will be 0.&amp;nbsp; You can also check to see if the number is gradually decreasing and not increasing.&amp;nbsp; But this way can take a bit of time.&lt;/P&gt;&lt;P&gt;So if ping to the internet works but URLs are not accessible that is a clear indication that there is some kind of issue with DNS.&amp;nbsp; Especially if you statically set the DNS on the client and are then able to reach the URL you try to browse to then you know 100% it is your DNS server.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Please remember to rate and select a correct answer&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2014 17:13:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435177#M267809</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2014-04-05T17:13:02Z</dc:date>
    </item>
    <item>
      <title> Many thanks for explaining </title>
      <link>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435178#M267810</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks for explaining&amp;nbsp; it in so detail.&lt;/P&gt;&lt;P&gt;Best reagrds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2014 20:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-server-lookups-and-sh-conn-in-asa/m-p/2435178#M267810</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2014-04-05T20:16:30Z</dc:date>
    </item>
  </channel>
</rss>

