<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Within my DHCP Scope I in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893290#M415489</link>
    <description>&lt;P&gt;Within my DHCP Scope I currently have the 2 DNS Servers that my new ISP game me.&lt;/P&gt;
&lt;P&gt;I can post a copy of the config if interested?&lt;/P&gt;
&lt;P&gt;Thanks, Matt&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 10 Mar 2016 12:48:04 GMT</pubDate>
    <dc:creator>mattmartin0607</dc:creator>
    <dc:date>2016-03-10T12:48:04Z</dc:date>
    <item>
      <title>ASA 5505 DNS</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893288#M415486</link>
      <description>&lt;P&gt;Good Morning,&lt;/P&gt;
&lt;P&gt;I am having an issue getting a Cisco ASA 5505 out to the internet via domain. I recently changed over to another ISP and went in and changed the DNS, Gateway &amp;nbsp;IP, and Outside Interface info thinking it would be simple like normal.&lt;/P&gt;
&lt;P&gt;I left all of my NAT, ACLs, and Inside Interface info the same. DHCP is also handed out in this small office from the 5505.&lt;/P&gt;
&lt;P&gt;I have ACL enabled to allow Domain out and can packet trace both TCP and UDP over domain to 8.8.8.8. However I cannot ping google.com. Internet Explorer and Chrome are both not resolving DNS names. Chrome gives me DNS DOMAIN LOOKUP ERROR NXDOMAIN and IE is just normal cannot connect. I also cannot ping google.com from the ASA. PCAPS analysis looks like everything on the ASA is functioning properly and going out to the internet.&lt;/P&gt;
&lt;P&gt;I can ping any outside address by&amp;nbsp;IP, but not by name. Here is the weird part. When I manually change a workstation to use DNS 8.8.8.8 we get out with no problem. If I add 8.8.8.8 into the firewall as my DNS I get the same errors above. I have flushed DNS, Cleared the containers, and disabled all AV protection software.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;From my stance and other googleing that I have done all routing, nating, and ACLS should be setup completely. Reminder that this worked perfectly fine on our old internet connection.&lt;/P&gt;
&lt;P&gt;Any help, idea, or content can be gotten if anyone has any help it would truly be appreciated.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893288#M415486</guid>
      <dc:creator>mattmartin0607</dc:creator>
      <dc:date>2020-02-21T13:45:32Z</dc:date>
    </item>
    <item>
      <title>In your DHCP scope what name</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893289#M415487</link>
      <description>&lt;P&gt;In your DHCP scope what name server are you assigning the clients?&lt;/P&gt;
&lt;P&gt;Hint - You cannot use the ASA as a DNS server, it can only act as a client.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 21:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893289#M415487</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-03-09T21:25:42Z</dc:date>
    </item>
    <item>
      <title>Within my DHCP Scope I</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893290#M415489</link>
      <description>&lt;P&gt;Within my DHCP Scope I currently have the 2 DNS Servers that my new ISP game me.&lt;/P&gt;
&lt;P&gt;I can post a copy of the config if interested?&lt;/P&gt;
&lt;P&gt;Thanks, Matt&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Mar 2016 12:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893290#M415489</guid>
      <dc:creator>mattmartin0607</dc:creator>
      <dc:date>2016-03-10T12:48:04Z</dc:date>
    </item>
    <item>
      <title>That sounds curious.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893291#M415490</link>
      <description>&lt;P&gt;That sounds curious.&lt;/P&gt;
&lt;P&gt;Please post a copy of the config (as an attachment) and I'll have a look at it.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 00:36:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893291#M415490</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-03-11T00:36:27Z</dc:date>
    </item>
    <item>
      <title>The file is attached.</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893292#M415491</link>
      <description>&lt;P&gt;The file is attached.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 13:19:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893292#M415491</guid>
      <dc:creator>mattmartin0607</dc:creator>
      <dc:date>2016-03-11T13:19:33Z</dc:date>
    </item>
    <item>
      <title>That does look quite</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893293#M415492</link>
      <description>&lt;P&gt;That does look quite straightforward and correct as far as I can tell.&lt;/P&gt;
&lt;P&gt;Just to test, I tried those DNS entries myself. I was also unable to resolve any addresses using either one. The hosts do appear to be listening on udp/53.&lt;/P&gt;
&lt;P&gt;So I did a packet capture. When all else fails look at the raw data. Interestingly I see replies coming back from those servers with the "reply code: refused". Open the image below in a new window to see the detail.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This almost always indicates misconfiguration of the DNS servers - i.e &amp;nbsp;a problem on your ISP's end. I'd just use Google public DNS until they can get their act together. :).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/capture_156.png" class="migrated-markup-image" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2016 23:11:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-dns/m-p/2893293#M415492</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-03-11T23:11:43Z</dc:date>
    </item>
  </channel>
</rss>

