<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS Rewrite on PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249978#M610161</link>
    <description>&lt;P&gt;Using static to NAT a private IP to public and have dns rewrite enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1,outside) 66.x.x.211 10.18.62.11 dns netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This 66.x.x.211 address is the address returned for &lt;A class="jive-link-custom" href="http://www.customerX.com" target="_blank"&gt;www.customerX.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to be working OK for A-record resolution.  When a box on the 10 net tries to resolve &lt;A class="jive-link-custom" href="http://www.customerX.com," target="_blank"&gt;www.customerX.com,&lt;/A&gt; 66.x.x.211 is returned but is then rewritten to 10.18.62.11 and sent to the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  This customer swears he was able to do a reverse lookup to 10.18.62.11 and get back a response of &lt;A class="jive-link-custom" href="http://www.customerX.com." target="_blank"&gt;www.customerX.com.&lt;/A&gt;  Is this the case or is he mistaken?  I'm seeing the 11.62.18.16.in-addr.arpa leave the outside interface and so want to know if it was supposed to rewrite this packet to 211.x.x.66.in-addr.arpa and just isn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.  Another possibility is that he may have recently switched to using an internal DNS server on another dmz (192.168.3.199) which doesn't fall under the above static command.  If so I have a new problem that this dmz has a higher security level than the 10 net interface.  If I need to, how do I do dns rewrite between these two dmzs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:30:47 GMT</pubDate>
    <dc:creator>scot.hartman</dc:creator>
    <dc:date>2020-02-21T07:30:47Z</dc:date>
    <item>
      <title>DNS Rewrite on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249978#M610161</link>
      <description>&lt;P&gt;Using static to NAT a private IP to public and have dns rewrite enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1,outside) 66.x.x.211 10.18.62.11 dns netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This 66.x.x.211 address is the address returned for &lt;A class="jive-link-custom" href="http://www.customerX.com" target="_blank"&gt;www.customerX.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems to be working OK for A-record resolution.  When a box on the 10 net tries to resolve &lt;A class="jive-link-custom" href="http://www.customerX.com," target="_blank"&gt;www.customerX.com,&lt;/A&gt; 66.x.x.211 is returned but is then rewritten to 10.18.62.11 and sent to the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  This customer swears he was able to do a reverse lookup to 10.18.62.11 and get back a response of &lt;A class="jive-link-custom" href="http://www.customerX.com." target="_blank"&gt;www.customerX.com.&lt;/A&gt;  Is this the case or is he mistaken?  I'm seeing the 11.62.18.16.in-addr.arpa leave the outside interface and so want to know if it was supposed to rewrite this packet to 211.x.x.66.in-addr.arpa and just isn't.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2.  Another possibility is that he may have recently switched to using an internal DNS server on another dmz (192.168.3.199) which doesn't fall under the above static command.  If so I have a new problem that this dmz has a higher security level than the 10 net interface.  If I need to, how do I do dns rewrite between these two dmzs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:30:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249978#M610161</guid>
      <dc:creator>scot.hartman</dc:creator>
      <dc:date>2020-02-21T07:30:47Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Rewrite on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249979#M610162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is your DNS SERVER? I think it is on DMZ, hence it should have an A record for the private IP ADDRESS of that server. Could you double check that? just make sure what his server has and what server he is using&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Jul 2004 23:13:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249979#M610162</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-07-16T23:13:30Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Rewrite on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249980#M610163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;He was origionally using a DNS server out on the Internet.  I understand that if he's using an internal DNS server, he really "should" just be using split DNS.  That isn't really the question.  When he was resolving off the external DNS server, the requests for the &lt;A class="jive-link-custom" href="http://www.customerX.com" target="_blank"&gt;http://www.customerX.com&lt;/A&gt; came back with the 66 net address but the PIX injected the 10 net address into the reply.  I'm asking if, during a reverse lookup, if the PIX is supposed to inject the 66 net address before it sends it out to the DNS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any insights,&lt;/P&gt;&lt;P&gt;Scot&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jul 2004 14:01:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249980#M610163</guid>
      <dc:creator>scot.hartman</dc:creator>
      <dc:date>2004-07-19T14:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Rewrite on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249981#M610165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS server on the outside makes the life easy. I think the rules for DNS rewrite are same for forward or reverse lookup. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Nadeem&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jul 2004 16:08:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249981#M610165</guid>
      <dc:creator>nkhawaja</dc:creator>
      <dc:date>2004-07-19T16:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Rewrite on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249982#M610167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK, so to clarify.  I have this...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz1,outside) 66.x.x.211 10.18.62.11 dns netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The world sees &lt;A class="jive-link-custom" href="http://www.customerX.com" target="_blank"&gt;www.customerX.com&lt;/A&gt; as 66.x.x.211.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internally, that server is actually NAT'd per the line above to IP 10.18.62.11 on the inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A box that is on the 10.18.62.x network sends a request for &lt;A class="jive-link-custom" href="http://www.customerX.com." target="_blank"&gt;www.customerX.com.&lt;/A&gt;  We, of course, want it to hit 10.18.62.11 instead of the 66.x.x.211 IP, so I am seeing this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client:     Sends DNS request &lt;A class="jive-link-custom" href="http://www.customerX.com" target="_blank"&gt;www.customerX.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;PIX:        Doesn't change this request (fine)&lt;/P&gt;&lt;P&gt;DNS server: Recieves DNS request for &lt;A class="jive-link-custom" href="http://www.customerX.com" target="_blank"&gt;www.customerX.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS server:  Replies with 66.x.x.211&lt;/P&gt;&lt;P&gt;PIX:         Because of dns rewrite, changes this reply to 10.18.62.11 (good)&lt;/P&gt;&lt;P&gt;Client:      Recieves 10.18.62.11 and connects to this internal address instead of 66.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good, works fine.  But for reverse lookups I see:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;client:     Sends reverse-DNS request for 11.62.18.10.in-addr.arpa&lt;/P&gt;&lt;P&gt;PIX:        Doesn't change this request.  Shouldn't it change it to 211.x.x.216.in-addr.arpa?&lt;/P&gt;&lt;P&gt;DNS server: Recieves DNS request for 11.62.18.10.in-addr.arpa which it will, of course, NOT respond to with &lt;A class="jive-link-custom" href="http://www.customerX.com" target="_blank"&gt;www.customerX.com&lt;/A&gt; since the 10net is RFC 1918.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should the PIX grab that reverse for 10.18.62.11 and substitute with the 66.x.x.211 IP before sending it to the DNS server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so, why is it working for the forward lookup but not for the reverse?  Is there an additional setting or possibly a problem with a cache, xlate, etc. of some kind within the PIX.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Scot &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Jul 2004 17:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249982#M610167</guid>
      <dc:creator>scot.hartman</dc:creator>
      <dc:date>2004-07-19T17:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Rewrite on PIX</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249983#M610168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know if the PIX perform substitution for reverse lookups or just for forward lookups?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My rather lengthy information is in the previous posts.  I'd really appreciate any help on this. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;Scot &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Aug 2004 20:21:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite-on-pix/m-p/249983#M610168</guid>
      <dc:creator>scot.hartman</dc:creator>
      <dc:date>2004-08-24T20:21:41Z</dc:date>
    </item>
  </channel>
</rss>

