<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA DNS Modification is not working on 8.4(3) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008572#M401718</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you also flush the DNS entries within your PC cache?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 24 Jul 2012 01:54:51 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-07-24T01:54:51Z</dc:date>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008569#M401715</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a server (172.16.10.1) inside the LAN and IP of the server has been maped to public IP 41.219.130.10.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Topology&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Server(172.16.10.1)&lt;/P&gt;&lt;P&gt;DNS Server (8.8.8.8)&amp;nbsp; ----- Outside&amp;nbsp; ASA&amp;nbsp; Inside&amp;nbsp; ----------- |&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User (192.168.1.x)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users are using Public DNS Server to resolve the domain. In this case, users will resolve the server domain to public IP address 41.219.130.10 instead of 172.16.10.1 that cause the server is unreachable for the users by default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I enable DNS modification feature on ASA. DNS keyword has been add to static NAT clause. ASA suppose to modify the DNS record to change the public IP to private IP address. But it is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help me to check if my command is right or completed. Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list inside_acl extended permit udp any host 8.8.8.8 eq 53&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-list outside_acl extended permit tcp any host 41.219.130.10&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-group inside_acl in interface inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;access-group inside_acl in interface outside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;object network CARE-SERVER&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; host 172.16.10.1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; nat (inside,outside) static 41.219.130.10 &lt;SPAN style="color: #ff0000;"&gt;dns&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;policy-map global_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt; class inspection_default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect ftp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect h323 h225 &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect h323 ras &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect ip-options &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect netbios &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect rsh &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect rtsp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect skinny&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect sqlnet &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect sunrpc &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect tftp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect sip&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect xdmcp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect icmp &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;&amp;nbsp; inspect http allow-url-policy &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&amp;nbsp; inspect dns &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff;"&gt;service-policy global_policy global&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008569#M401715</guid>
      <dc:creator>rd9978</dc:creator>
      <dc:date>2019-03-11T23:33:49Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008570#M401716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The access-list should be pointing towards the real address instead of the mapped address as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit tcp any host 172.16.10.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2012 17:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008570#M401716</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-07-23T17:15:43Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008571#M401717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks. Jennifer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_acl extended permit tcp any host 172.16.10.1&lt;/P&gt;&lt;P&gt;Yes. I have added this clause. But it is still not working. Seem like ASA does not inpsect DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PNNDC-ASA5520# show service-policy inspect dns &lt;/P&gt;&lt;P&gt;Global policy: &lt;/P&gt;&lt;P&gt;&amp;nbsp; Service-policy: global_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Class-map: inspection_default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Inspect: dns _default_dns_map, packet 0, drop 0, reset-drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dns-guard, count 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol-enforcement, drop 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat-rewrite, count 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't why there is no DNS packet inspected. But DNS inpsection has been enable at Global.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jul 2012 17:37:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008571#M401717</guid>
      <dc:creator>rd9978</dc:creator>
      <dc:date>2012-07-23T17:37:13Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008572#M401718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you also flush the DNS entries within your PC cache?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 01:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008572#M401718</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-07-24T01:54:51Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008573#M401719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes. I have tried at 3 PC and routers also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; But ASA didn't inpsect any DNS packet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 07:46:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008573#M401719</guid>
      <dc:creator>rd9978</dc:creator>
      <dc:date>2012-07-24T07:46:30Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008574#M401720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;And it definitely uses the public DNS server? and the DNS request is actually going through the ASA not other gateway?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you try NSLOOKUP or you try to browse to the URL?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 08:29:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008574#M401720</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-07-24T08:29:45Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008575#M401721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was trying to use public DNS server at the test PCs and routers and all the Internet traffic including DNS only pass through ASA.&lt;/P&gt;&lt;P&gt;I have used nslookup and browse the URL on the PCs.&lt;/P&gt;&lt;P&gt;Also I have used internal routers to test.clear host * and ping domain. It still resolves to public IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to use IOS 8.0 before and there was no issue with this feature. After I upgraded IOS to 8.4(3), this feature did not work and DNS inspection also did not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 09:40:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008575#M401721</guid>
      <dc:creator>rd9978</dc:creator>
      <dc:date>2012-07-24T09:40:33Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008576#M401722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please share your whole configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jul 2012 10:21:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008576#M401722</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-07-24T10:21:19Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008577#M401723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have upgraded ASA platform and use IOS 8.4(4)1. There is no problem now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jul 2012 13:43:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008577#M401723</guid>
      <dc:creator>rd9978</dc:creator>
      <dc:date>2012-07-27T13:43:12Z</dc:date>
    </item>
    <item>
      <title>ASA DNS Modification is not working on 8.4(3)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008578#M401724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the update. It might be a bug with the previous version that you run.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 08:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-modification-is-not-working-on-8-4-3/m-p/2008578#M401724</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-08-03T08:04:05Z</dc:date>
    </item>
  </channel>
</rss>

