<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firewall DNS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087447#M392095</link>
    <description>&lt;P&gt;&amp;nbsp; Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Wireless Client (172.31.250.x) in corpx segment (Secuirty 91) which are trying to access the webmail which is published over the internet. Email Server is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;located inside segment (security 100) on IP address (192.168.251.137). Clients are able to browse Internet fine but emails and Internal Applications are not working &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;because Public DNS is resolving the PUbic IP addresses of these applications. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want my Wireless Client to access these Internal IP addresses and want to configure the firewall for this DNS issue. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Current configuration for the email Server is this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-out extended permit tcp any host xx.210.84.37 eq https&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;static (inside,outside) xx.210.84.37 192.168.251.137 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,corpx) xx.210.84.37 192.168.251.137 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (corpx) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (corpx) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no access-list on the corpx interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly assist what I am missing. I want the email server to be available for the wireless cients as well as Internet and users over the Internet.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:53:10 GMT</pubDate>
    <dc:creator>wasiimcisco</dc:creator>
    <dc:date>2019-03-12T00:53:10Z</dc:date>
    <item>
      <title>Firewall DNS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087447#M392095</link>
      <description>&lt;P&gt;&amp;nbsp; Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have Wireless Client (172.31.250.x) in corpx segment (Secuirty 91) which are trying to access the webmail which is published over the internet. Email Server is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;located inside segment (security 100) on IP address (192.168.251.137). Clients are able to browse Internet fine but emails and Internal Applications are not working &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;because Public DNS is resolving the PUbic IP addresses of these applications. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want my Wireless Client to access these Internal IP addresses and want to configure the firewall for this DNS issue. &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Current configuration for the email Server is this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-out extended permit tcp any host xx.210.84.37 eq https&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;static (inside,outside) xx.210.84.37 192.168.251.137 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,corpx) xx.210.84.37 192.168.251.137 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nat (corpx) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (corpx) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (inside) 1 interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no access-list on the corpx interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly assist what I am missing. I want the email server to be available for the wireless cients as well as Internet and users over the Internet.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:53:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087447#M392095</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2019-03-12T00:53:10Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall DNS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087448#M392101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need DNS-doctoring:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #ffffff; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;static (inside,outside) xx.210.84.37 192.168.251.137 netmask 255.255.255.255 &lt;STRONG&gt;dns&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's that rule for:&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&lt;SPAN style="font-family: 'courier new', courier; font-size: 10pt;"&gt;static (inside,corpx) xx.210.84.37 192.168.251.137 netmask 255.255.255.255&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you really need that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&amp;nbsp; &lt;BR /&gt;Don't stop after you've improved your network! Improve the world by lending money to the working poor: &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://www.kiva.org/invitedby/karsteni" rel="nofollow"&gt;http://www.kiva.org/invitedby/karsteni&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jan 2013 12:18:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087448#M392101</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-28T12:18:04Z</dc:date>
    </item>
    <item>
      <title>Firewall DNS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087449#M392107</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the above command but no luck. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) xx.210.84.37 192.168.251.137 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have even removed the below mention commnad though the below command was DNS docotoring so that once the request hit on corpx interface it will redirect to inside interface towards the private IP address of exchange.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But both the options are not working. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly assist. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 03:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087449#M392107</guid>
      <dc:creator>wasiimcisco</dc:creator>
      <dc:date>2013-01-29T03:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Firewall DNS</title>
      <link>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087450#M392114</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you clear the DNS caches on your PC?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2013 06:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firewall-dns/m-p/2087450#M392114</guid>
      <dc:creator>Karsten Iwen</dc:creator>
      <dc:date>2013-01-29T06:45:05Z</dc:date>
    </item>
  </channel>
</rss>

