<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enable dns on cisco asa firewall in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601877#M590337</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Manish, this worked!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Chirag&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 05 Mar 2011 02:00:21 GMT</pubDate>
    <dc:creator>csaxena</dc:creator>
    <dc:date>2011-03-05T02:00:21Z</dc:date>
    <item>
      <title>Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601868#M590324</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to enable dns on my cisco asa firewall on asa versions 5.x/6.x So that i can do ping test to public hostname eg ping &lt;A href="http://www.yahoo.com" target="_blank"&gt;www.yahoo.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I have enabled dns lookup on inside interface and added a dns server which is connected to the inside network where the asa inside interface is connected. However when i do a "ping &lt;A href="http://www.yahoo.com" target="_blank"&gt;www.yahoo.com&lt;/A&gt;" from asdm i got "error %invalid input". Pls advise Thks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 20:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601868#M590324</guid>
      <dc:creator>donnie</dc:creator>
      <dc:date>2019-03-11T20:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601869#M590325</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Don ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS configured on ASA can not be utilized for resolution of yahoo.com or any url on ASA CLI. If you wish ping &lt;A href="https://community.cisco.com/www.yahoo.com" target="_blank"&gt;www.yahoo.com&lt;/A&gt; from ASA, you can use the name command to map url to public IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sure that is not the requirement and you wish to do this as a connectivity test. I suggest to ping public DNS servers like 4.2.2.2 or 8.8.8.8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps. Please reply back if you need any further assistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Chirag&lt;BR /&gt;&lt;SPAN style="font-size: 8pt;"&gt;P.S.: Please mark this thread as answered if you feel your query is answered. Do rate helpful posts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 01:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601869#M590325</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-04T01:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601870#M590326</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a document that could help you understand DNS doctoring:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 02:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601870#M590326</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-04T02:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601871#M590327</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Paul,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess Don i slooking for DNS resoultion on ASA CLI &amp;amp; ASDM. He wishes to resolve url in pings from ASA CLI/ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Chirag&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 02:19:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601871#M590327</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-04T02:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601872#M590328</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Don,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do think that it is possible to configure the ASA to resolve FQDN to ip address , can't find any documentation but you can use following commands :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following example thinks that you are using 4.2.2.2 as DNS server :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;asa(config)#dns domain-lookup outside&lt;/P&gt;&lt;P&gt;asa(config)#dns name-server 4.2.2.2&lt;/P&gt;&lt;P&gt;you see a bunch of options like dns retries etc that you can use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 02:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601872#M590328</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2011-03-04T02:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601873#M590329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Manish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes,&amp;nbsp; even i think that is not possible. The example which you stated shall set 4.2.2.2 as the DNS server and all DNS resolution will be externally using this as the server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chirag&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 04:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601873#M590329</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-04T04:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601874#M590330</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chirag,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The test i need to do is to resolve the ip address of the url link. Once in a while i need to allow my specific site users to have access to certain url and this url may have a different ip address depending on the geographical location that you resolve. Hence i would like to remote into the firewall, resolve from there and add the access rule accordingly. But since the firewall can't resolve names i need to remote into the one of the PCs/server sitting behind the firewall to do resolution to chk the public ip address for the specific url for that geographical location.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hi Manish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I already tried that before posting this question but it fail to work.&lt;/P&gt;&lt;P&gt;I did a dns domain-lookup inside and a dns name-server 192.168.22.1 which is my inside dns server but fail to work&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 05:48:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601874#M590330</guid>
      <dc:creator>donnie</dc:creator>
      <dc:date>2011-03-04T05:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601875#M590332</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Don,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, ok. In that case, this not possible on ASA. You can consider doing a nslookup from a PC in that location for that url and add rules for that particular IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please mark the post answered for future use of others.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Regards,&lt;BR /&gt;Chirag&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;P.S.: Please mark this thread as answered if you feel your query is answered. Do rate helpful posts.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 8pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 06:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601875#M590332</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-04T06:06:10Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601876#M590336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Don,&lt;/P&gt;&lt;P&gt;I did the same config and was able to resolve domain name , there might be rules configured on your inside interface that is stopping for dns server to reply back to the firewall. here's what I did &amp;amp; I have inside interface access to any any :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;av-fw01(config)# dns domain-lookup inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;av-fw01(config)# dns name-server 10.9.106.11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;av-fw01(config)# ping yahoo.com&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 98.137.149.56, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;av-fw01(config)# ping av-netdev01&lt;BR /&gt;Type escape sequence to abort.&lt;BR /&gt;Sending 5, 100-byte ICMP Echos to 10.9.106.100, timeout is 2 seconds:&lt;BR /&gt;!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you should try setting up captures &amp;amp; try some packet-tracer commands and see why the replies are not reaching your firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 17:57:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601876#M590336</guid>
      <dc:creator>manish arora</dc:creator>
      <dc:date>2011-03-04T17:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Enable dns on cisco asa firewall</title>
      <link>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601877#M590337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Manish, this worked!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Chirag&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2011 02:00:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/enable-dns-on-cisco-asa-firewall/m-p/1601877#M590337</guid>
      <dc:creator>csaxena</dc:creator>
      <dc:date>2011-03-05T02:00:21Z</dc:date>
    </item>
  </channel>
</rss>

