<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dns on pix in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450065#M530521</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;browsing the servers means? you cant connect via http or via windows network share etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in either case, you need to have an Access-list applied on the dmz interface to allow the desired traffic to reach the inside from dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Nov 2005 00:09:18 GMT</pubDate>
    <dc:creator>nkhawaja</dc:creator>
    <dc:date>2005-11-21T00:09:18Z</dc:date>
    <item>
      <title>dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450060#M530499</link>
      <description>&lt;P&gt;dns_inside----pix-----user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns is at the inside subnet&lt;/P&gt;&lt;P&gt;user is on the dmz&lt;/P&gt;&lt;P&gt;domain controller on the inside subnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;observations;&lt;/P&gt;&lt;P&gt;1. with nat (inside) 0 0 , the user could logon to the domain, but couldnt brouse any machine on the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. with nat (inside) 1 0 0 , user couldnt logon to the domain controller. static command is invoke with the ff detail&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside, dmz) 10.2.2.10 10.1.1.10&lt;/P&gt;&lt;P&gt;10.1.1.10 is the dns&lt;/P&gt;&lt;P&gt;10.2.2.10 is the outside mapped ip&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ping from user to 10.2.2.10 is ok.&lt;/P&gt;&lt;P&gt;10.2.2.10 is configured as dns on windows user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;why cant i have dns service if am using nat?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without nat, why cant i browse the inside network? i could find a computer on the inside using the computer name, thus dns is doing his job. I just cant browse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anyone here could help me pls..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450060#M530499</guid>
      <dc:creator>rpalacio</dc:creator>
      <dc:date>2020-02-21T08:32:19Z</dc:date>
    </item>
    <item>
      <title>Re: dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450061#M530504</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the rule of translation requies you to have static translation if you want connection from dmz to inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so you have to use static translation or nat 0 with access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Nov 2005 19:28:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450061#M530504</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-11-19T19:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450062#M530510</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ive done that, thats why i was able to login to the domain controller inside from a user on the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Nov 2005 20:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450062#M530510</guid>
      <dc:creator>rpalacio</dc:creator>
      <dc:date>2005-11-19T20:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450063#M530513</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;so what is your question/issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Nov 2005 13:55:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450063#M530513</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-11-20T13:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450064#M530519</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the issue is i cant browse the inside network from the dmz...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;inside is where servers are.&lt;/P&gt;&lt;P&gt;dmz is where users are.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 Nov 2005 20:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450064#M530519</guid>
      <dc:creator>rpalacio</dc:creator>
      <dc:date>2005-11-20T20:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450065#M530521</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;browsing the servers means? you cant connect via http or via windows network share etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in either case, you need to have an Access-list applied on the dmz interface to allow the desired traffic to reach the inside from dmz&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Nov 2005 00:09:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450065#M530521</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-11-21T00:09:18Z</dc:date>
    </item>
    <item>
      <title>Re: dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450066#M530525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i cant see any macine on the inside from the network neighborhood. But if i do a search on the machine thru their computer names, it works.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Nov 2005 04:09:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450066#M530525</guid>
      <dc:creator>rpalacio</dc:creator>
      <dc:date>2005-11-21T04:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450067#M530528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;may be it requires WINS setting. or the necessary ports to be opened. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Nov 2005 21:33:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450067#M530528</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2005-11-21T21:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: dns on pix</title>
      <link>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450068#M530531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was able to browse the network even by just having a DNS. Server IPs must not be translated between inside and dmz though i still have to invoke the static command. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont know but its just taking a lot of time to for the pix to discover the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Nov 2005 07:15:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-on-pix/m-p/450068#M530531</guid>
      <dc:creator>rpalacio</dc:creator>
      <dc:date>2005-11-22T07:15:11Z</dc:date>
    </item>
  </channel>
</rss>

