<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX DNS resolution issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430319#M557397</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had already tried this, I think this is an alternative to alias command in the newer versions.But it didn't work.I also tried to fiddle with the DNS entries.In forward lookup zone in Name server entries if am adding 192.168.2.90 as a second entry , I am able to join the domain from outside.But if I am restarting the server the entry goes off and it stops working.I couldnot understand whether it is a microsoft issue or PIX issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Jun 2005 09:26:27 GMT</pubDate>
    <dc:creator>sanjay.sangwan</dc:creator>
    <dc:date>2005-06-07T09:26:27Z</dc:date>
    <item>
      <title>PIX DNS resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430315#M557390</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to login to active directory server on inside from an outside of a PIX.The server works as DNS also.Follwing IP address is mapped&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; static(inside,outside) 192.168.2.90 192.168.1.90&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;AD Server(DNS)= 192.168.1.90&lt;/P&gt;&lt;P&gt;When I am trying to access the DNS from outside on 192.168.2.90 , The internal DNS replies with the 192.168.1.90 as AD domain name and login fails.How can I get the NATED IP as the Domain IP from the DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sanjay&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:11:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430315#M557390</guid>
      <dc:creator>sanjay.sangwan</dc:creator>
      <dc:date>2020-02-21T08:11:25Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430316#M557393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check this page:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094aee.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_tech_note09186a0080094aee.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe this config will work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;alias (outside) 192.168.2.90 192.168.1.90 255.255.255.255&lt;/P&gt;&lt;P&gt;sysopt noproxyarp outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2005 09:49:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430316#M557393</guid>
      <dc:creator>johansens</dc:creator>
      <dc:date>2005-06-06T09:49:58Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430317#M557395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried the above commands but the nslookup still shows the 192.168.1.90 (actual IP) and I am not through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sanjay&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2005 03:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430317#M557395</guid>
      <dc:creator>sanjay.sangwan</dc:creator>
      <dc:date>2005-06-07T03:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430318#M557396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can also try&lt;/P&gt;&lt;P&gt;static(inside,outside) 192.168.2.90 192.168.1.90 dns&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2005 03:56:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430318#M557396</guid>
      <dc:creator>a.alekseev</dc:creator>
      <dc:date>2005-06-07T03:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430319#M557397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had already tried this, I think this is an alternative to alias command in the newer versions.But it didn't work.I also tried to fiddle with the DNS entries.In forward lookup zone in Name server entries if am adding 192.168.2.90 as a second entry , I am able to join the domain from outside.But if I am restarting the server the entry goes off and it stops working.I couldnot understand whether it is a microsoft issue or PIX issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jun 2005 09:26:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430319#M557397</guid>
      <dc:creator>sanjay.sangwan</dc:creator>
      <dc:date>2005-06-07T09:26:27Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430320#M557398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Long time ago, i had the same problem, i asked   a Microsoft technical, and I know that AD+DNS can not run with NAT on Pix.&lt;/P&gt;&lt;P&gt;you can try&lt;/P&gt;&lt;P&gt;static(inside,outside) 192.168.1.90 192.168.1.90&lt;/P&gt;&lt;P&gt;clear xlate&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Jun 2005 07:20:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430320#M557398</guid>
      <dc:creator>leminhkhoi79</dc:creator>
      <dc:date>2005-06-24T07:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430321#M557399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried the following on the PIX and I am through&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static(inside,outside) 192.168.2.90 192.168.1.90 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This command does DNS doctoring through NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 25 Jun 2005 03:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430321#M557399</guid>
      <dc:creator>sanjay.sangwan</dc:creator>
      <dc:date>2005-06-25T03:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: PIX DNS resolution issue</title>
      <link>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430322#M557400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you using a Windows 2003 DNS server? If so there is a known issue with DNS packet size and Windows 2003. To resolve you'll have to increase dns fixup on your pix to a larger packet size. Increasing the size of course requires 6.3 or greater Pix IOS. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Jul 2005 21:15:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-dns-resolution-issue/m-p/430322#M557400</guid>
      <dc:creator>jsalminen</dc:creator>
      <dc:date>2005-07-07T21:15:24Z</dc:date>
    </item>
  </channel>
</rss>

