<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5510 Slow Name Resolution in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509413#M611816</link>
    <description>&lt;P&gt;Greetings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem. We're planning to add an ASA into our network for VPN and firewall purposes. I've hooked the ASA up to the network and so things look a bit like this:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bridged Internet Connection ---&amp;gt;&amp;gt; ASA 5510 ---&amp;gt;&amp;gt; 1841 Router ---&amp;gt;&amp;gt; Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently use a different firewall appliance which is still connected. The problem is, when I switch the route to go out onto the internet to pass through the ASA, DNS resolutions become slow. They work but they are slow and thus browsing is slow. When I set the route back to the other firewall appliance, everything works fine. The resolutions are much quicker than when the traffic is running through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, the DNS server is internal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone share some insight into why this happens? Did I forget something? I've attached the ASA's configuration.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:38:38 GMT</pubDate>
    <dc:creator>Felix Bowman</dc:creator>
    <dc:date>2019-03-11T18:38:38Z</dc:date>
    <item>
      <title>ASA 5510 Slow Name Resolution</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509413#M611816</link>
      <description>&lt;P&gt;Greetings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem. We're planning to add an ASA into our network for VPN and firewall purposes. I've hooked the ASA up to the network and so things look a bit like this:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bridged Internet Connection ---&amp;gt;&amp;gt; ASA 5510 ---&amp;gt;&amp;gt; 1841 Router ---&amp;gt;&amp;gt; Network&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently use a different firewall appliance which is still connected. The problem is, when I switch the route to go out onto the internet to pass through the ASA, DNS resolutions become slow. They work but they are slow and thus browsing is slow. When I set the route back to the other firewall appliance, everything works fine. The resolutions are much quicker than when the traffic is running through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, the DNS server is internal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone share some insight into why this happens? Did I forget something? I've attached the ASA's configuration.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509413#M611816</guid>
      <dc:creator>Felix Bowman</dc:creator>
      <dc:date>2019-03-11T18:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Slow Name Resolution</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509414#M611821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest enabling dns inspection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that doesn't help I would suggest using the capture command to capture packets in and out of the ASA so you can see who delays or drops the dns. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also check the interfaces for duplect or speed mismatches that could cause drops and delays.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope it helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Sep 2010 18:31:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509414#M611821</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-09-10T18:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Slow Name Resolution</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509415#M611824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you. I got the problem solved after doing some packet captures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It turns out that the DNS server was forwarding to two other older DNS servers that we had before. That caused the resolutions to take much longer than they should have which timed out on the client machines.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The captures showing the older DNS servers making resolution requests whenever a lookup request was made from the new DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I appreciate your help on the matter.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 14:17:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509415#M611824</guid>
      <dc:creator>Felix Bowman</dc:creator>
      <dc:date>2010-09-14T14:17:39Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Slow Name Resolution</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509416#M611828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for updating. That way other will benefit in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PK&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 14:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-slow-name-resolution/m-p/1509416#M611828</guid>
      <dc:creator>Panos Kampanakis</dc:creator>
      <dc:date>2010-09-14T14:48:10Z</dc:date>
    </item>
  </channel>
</rss>

