<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5520 - name resolution in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210164#M349040</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I imagine that you mean you configure an &lt;STRONG&gt;"object-group network &lt;NAME&gt;"&lt;/NAME&gt;&lt;/STRONG&gt; for each rule you configure on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or are you referring to the &lt;STRONG&gt;"name x.x.x.x &lt;NAME&gt;"&lt;/NAME&gt;&lt;/STRONG&gt; which pairs an IP address with a "name" that will very commonly show up on the ASDM side?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Starting from software level 8.4(2) you are able to use a FQDN inside an &lt;STRONG&gt;"object network"&lt;/STRONG&gt;&amp;nbsp; (object network was introduced in 8.3(1))and create rules based on names. For this to work you will also configure ASAs "outside" interface with&amp;nbsp; DNS Domain Lookup so that the ASA can resolve the DNS name to an IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the above is setup and working the ASA will actually update the ACL rule using the FQDN according to the DNS Domain Lookups it does regularly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though to my understanding this has its problems and flaws but just though I'd mention as you can build these rules in newer software compared to your 8.0 version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 29 May 2013 15:30:49 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2013-05-29T15:30:49Z</dc:date>
    <item>
      <title>ASA 5520 - name resolution</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210163#M349039</link>
      <description>&lt;P&gt;&amp;nbsp; I have a simple problem.. We have a pair of ASA&amp;nbsp; running 8.0 (old) version. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The way we create outbound rules is done through ASDM and when we need to open outbound connections to a server in the internet, we create named object with IP address configured manually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But practically , this doesnt work, since&amp;nbsp; the server is a server name which can resolve to multiple addresses. Everytime the server chagnes its IP the ASA rule needs to be updated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a difference if we add rules through CMD prompt as against ASDM where we need to enter IP addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for helping me out..&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210163#M349039</guid>
      <dc:creator>TGF_Cisco</dc:creator>
      <dc:date>2019-03-12T01:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - name resolution</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210164#M349040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I imagine that you mean you configure an &lt;STRONG&gt;"object-group network &lt;NAME&gt;"&lt;/NAME&gt;&lt;/STRONG&gt; for each rule you configure on the ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or are you referring to the &lt;STRONG&gt;"name x.x.x.x &lt;NAME&gt;"&lt;/NAME&gt;&lt;/STRONG&gt; which pairs an IP address with a "name" that will very commonly show up on the ASDM side?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Starting from software level 8.4(2) you are able to use a FQDN inside an &lt;STRONG&gt;"object network"&lt;/STRONG&gt;&amp;nbsp; (object network was introduced in 8.3(1))and create rules based on names. For this to work you will also configure ASAs "outside" interface with&amp;nbsp; DNS Domain Lookup so that the ASA can resolve the DNS name to an IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When the above is setup and working the ASA will actually update the ACL rule using the FQDN according to the DNS Domain Lookups it does regularly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Though to my understanding this has its problems and flaws but just though I'd mention as you can build these rules in newer software compared to your 8.0 version.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 15:30:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210164#M349040</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-29T15:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5520 - name resolution</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210165#M349041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a link to a document here on the CSC that has information about the thing I mentioned above&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-wiki-small" href="https://community.cisco.com/docs/DOC-17014"&gt;https://supportforums.cisco.com/docs/DOC-17014&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 15:34:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210165#M349041</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-05-29T15:34:14Z</dc:date>
    </item>
    <item>
      <title>ASA 5520 - name resolution</title>
      <link>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210166#M349042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The underlying function will be the same, regardless if you use CLI or ASDM. The only solution would be to upgrade to at least version 8.4 where you can use FQDNs in ACLs that are resolved to IP-addresses at runtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 May 2013 15:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5520-name-resolution/m-p/2210166#M349042</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-05-29T15:38:55Z</dc:date>
    </item>
  </channel>
</rss>

