<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Badly Explained ASA Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033702#M400139</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If we're talking a windows as a dns server here, just create a New Zone; Forward Lookup Zones &amp;gt; New Zone... default setting should work for most deployment, so i suggest keep the default. In&amp;nbsp; your case, companyname.com. Then point that zone ip address to the internal address of that server. Create a New Host (A or AAA) under that newly created zone then point it to its corresponding ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 03 Sep 2012 21:17:50 GMT</pubDate>
    <dc:creator>Jon Eyes</dc:creator>
    <dc:date>2012-09-03T21:17:50Z</dc:date>
    <item>
      <title>Badly Explained ASA Question</title>
      <link>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033697#M400134</link>
      <description>&lt;P&gt;Hi there - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have just installed a new ASA and its great except for one little issue. The outside interface IP address has a DNS name in the outside world of office.companyname.com - with our users connecting their IPhones etc to exchange via office.companyname.com/exchange - this all still works when they are outside the network, but from inside the network this server is no longer accessible. If I ping this name from the inside of the network, the IP is resolved but then the ping times out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas??? Hope that makes sense......probably havent explained it too well!! &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:47:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033697#M400134</guid>
      <dc:creator>jdgriffiths</dc:creator>
      <dc:date>2019-03-11T23:47:36Z</dc:date>
    </item>
    <item>
      <title>Badly Explained ASA Question</title>
      <link>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033698#M400135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's a problem of DNS you can have a look either into DNS doctoring (available on ASA) or setting up multiple zones (bind name) on your DNS. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you would have expected office...../exchange to go to internal server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hard to say more without actual config - if in doubt you always have TAC &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;M.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2012 18:51:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033698#M400135</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2012-08-29T18:51:44Z</dc:date>
    </item>
    <item>
      <title>Badly Explained ASA Question</title>
      <link>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033699#M400136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Correct me if im wrong but the way i understand this in generality is your inside host/s is trying to connect to your firewall's outside interface/ip address.&lt;/P&gt;&lt;P&gt;By default ASA doesnt allow it. So you need to enable redirection/U-turning/Hairpinning&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Aug 2012 04:28:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033699#M400136</guid>
      <dc:creator>Jon Eyes</dc:creator>
      <dc:date>2012-08-30T04:28:43Z</dc:date>
    </item>
    <item>
      <title>Badly Explained ASA Question</title>
      <link>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033700#M400137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the replies - we have an internal DNS server - all clients have this is their primary DNS. Would it be possible to create a "redirect" of some kind on the DNS to map requests for office.companyname.com/exchange to the internal name of the server, thus cutting the ASA out of the equation??? No idea how I would do this - not a server dude at all - any help would be appreciated!!! &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2012 19:46:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033700#M400137</guid>
      <dc:creator>jdgriffiths</dc:creator>
      <dc:date>2012-09-03T19:46:32Z</dc:date>
    </item>
    <item>
      <title>Badly Explained ASA Question</title>
      <link>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033701#M400138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you just need some NAT configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share your config and let us know the source IP address and the server's private IP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Felipe.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2012 21:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033701#M400138</guid>
      <dc:creator>lcambron</dc:creator>
      <dc:date>2012-09-03T21:02:47Z</dc:date>
    </item>
    <item>
      <title>Badly Explained ASA Question</title>
      <link>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033702#M400139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If we're talking a windows as a dns server here, just create a New Zone; Forward Lookup Zones &amp;gt; New Zone... default setting should work for most deployment, so i suggest keep the default. In&amp;nbsp; your case, companyname.com. Then point that zone ip address to the internal address of that server. Create a New Host (A or AAA) under that newly created zone then point it to its corresponding ip address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Sep 2012 21:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033702#M400139</guid>
      <dc:creator>Jon Eyes</dc:creator>
      <dc:date>2012-09-03T21:17:50Z</dc:date>
    </item>
    <item>
      <title>Badly Explained ASA Question</title>
      <link>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033703#M400140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Jonjon - worked nicely thank you. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2012 10:33:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/badly-explained-asa-question/m-p/2033703#M400140</guid>
      <dc:creator>jdgriffiths</dc:creator>
      <dc:date>2012-09-10T10:33:16Z</dc:date>
    </item>
  </channel>
</rss>

