<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA DNS for inside clients? (ssl vpn from inside to ouside ip) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dns-for-inside-clients-ssl-vpn-from-inside-to-ouside-ip/m-p/1983912#M439357</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, unfortunately you can't NAT the ASA interface IP Addresses, and also you can't connect cross interfaces, so if you are on the Guest network, you can't connect to the Outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA also does not provide DNS functionality as it is not a DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For guest users, they can only connect to othe Guest-ASA IP, and you would need to add the certificate to the CA Root certificate store on the PC and you won't get the error after adding those.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 04 Aug 2012 16:42:01 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2012-08-04T16:42:01Z</dc:date>
    <item>
      <title>ASA DNS for inside clients? (ssl vpn from inside to ouside ip)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-for-inside-clients-ssl-vpn-from-inside-to-ouside-ip/m-p/1983911#M439356</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;Wo got an ASA5510 (8.2x) with an inside, guest and outside interface.&lt;/P&gt;&lt;P&gt;On the guest interface, we have DHCP function on the ASA.&lt;/P&gt;&lt;P&gt;On the outside, there is web-ssl vpn (dns hostname on a public isp-dns server) configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When an user on the guest net tries to get connected with the web-ssl dns-name, it resolves the public, outside interface-ip , the ASA dropps it.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I know, with static NAT it can be resolved (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://m.techrepublic.com/blog/networking/cisco-asa-and-dns-pain-is-there-a-doctor-in-the-house/1140" rel="nofollow" target="_blank"&gt;http://m.techrepublic.com/blog/networking/cisco-asa-and-dns-pain-is-there-a-doctor-in-the-house/1140&lt;/A&gt;&lt;SPAN&gt;), but on&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;this scenario, we are trying to build a connection from a guest inside IP to the public-ip form the outside ASA interface.&lt;/P&gt;&lt;P&gt;If the guest users try an web-ssl connection on the guest-ASA IP, it works with a certificate error ( because there is no internal DNS on the guest net to resolve the dns name to the guest-interface IP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So how can this be achieved? Can the ASA provide DNS server function? Can a NAT static entry (outside ip to interface guest) solve it?&lt;/P&gt;&lt;P&gt;It's the only solution an inhouse DNS server in the guest-net?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Norbert&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:38:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-for-inside-clients-ssl-vpn-from-inside-to-ouside-ip/m-p/1983911#M439356</guid>
      <dc:creator>alig.norbert</dc:creator>
      <dc:date>2019-03-11T23:38:10Z</dc:date>
    </item>
    <item>
      <title>ASA DNS for inside clients? (ssl vpn from inside to ouside ip)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-for-inside-clients-ssl-vpn-from-inside-to-ouside-ip/m-p/1983912#M439357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, unfortunately you can't NAT the ASA interface IP Addresses, and also you can't connect cross interfaces, so if you are on the Guest network, you can't connect to the Outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA also does not provide DNS functionality as it is not a DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For guest users, they can only connect to othe Guest-ASA IP, and you would need to add the certificate to the CA Root certificate store on the PC and you won't get the error after adding those.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Aug 2012 16:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-for-inside-clients-ssl-vpn-from-inside-to-ouside-ip/m-p/1983912#M439357</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2012-08-04T16:42:01Z</dc:date>
    </item>
    <item>
      <title>ASA DNS for inside clients? (ssl vpn from inside to ouside ip)</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-for-inside-clients-ssl-vpn-from-inside-to-ouside-ip/m-p/1983913#M439358</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Had to put a DNS (IOS Router) in the guest NAT. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Cisco.&lt;/P&gt;&lt;P&gt;Such a service (DNS Server) should be supported on the ASA......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greets,&lt;/P&gt;&lt;P&gt;Norbert&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2012 12:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-for-inside-clients-ssl-vpn-from-inside-to-ouside-ip/m-p/1983913#M439358</guid>
      <dc:creator>alig.norbert</dc:creator>
      <dc:date>2012-08-14T12:00:36Z</dc:date>
    </item>
  </channel>
</rss>

