<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS and NAT problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454908#M662856</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure dns doctoring (ie: with the "dns" keyword) on the static statement for the mail server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Example&lt;/STRONG&gt;&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;Mail server private ip: 10.0.0.8&lt;/P&gt;&lt;P&gt;Mail server NATed (public ip) 200.0.0.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 200.0.0.8 10.0.0.8 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before testing it again, please make sure you flush the dns entry on the dmz host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 21 Jun 2010 10:33:03 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-06-21T10:33:03Z</dc:date>
    <item>
      <title>DNS and NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454907#M662838</link>
      <description>&lt;P&gt;&lt;SPAN class="long_text" id="result_box"&gt;&lt;SPAN style="background-color: #e6ecf9; color: #000000;"&gt;Hello, I have a&amp;nbsp; problem with the DNS. Three zones: outside, dmz, inside. &lt;/SPAN&gt;&lt;SPAN&gt;Users of a DMZ-VLAN are using an&amp;nbsp; external DNS server, but they must be able to access the internal mail server (inside). &lt;/SPAN&gt;&lt;SPAN&gt;When trying to resolve the mail server IP, the DNS&amp;nbsp; gives them the public IP, but they have to convert it to an internal IP to access inside server.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I resolve that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454907#M662838</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2019-03-11T18:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: DNS and NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454908#M662856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure dns doctoring (ie: with the "dns" keyword) on the static statement for the mail server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG&gt;Example&lt;/STRONG&gt;&lt;/SPAN&gt;:&lt;/P&gt;&lt;P&gt;Mail server private ip: 10.0.0.8&lt;/P&gt;&lt;P&gt;Mail server NATed (public ip) 200.0.0.8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) 200.0.0.8 10.0.0.8 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before testing it again, please make sure you flush the dns entry on the dmz host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 10:33:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454908#M662856</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-21T10:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: DNS and NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454909#M662876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, but my users are not in inside, they are external wireless users and they are in dmz, dns server is outside and email server is inside.&lt;/P&gt;&lt;P&gt;I think this "static (inside,outside)" command is nothing for a dmz user, or not?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 10:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454909#M662876</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2010-06-21T10:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNS and NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454910#M662929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You advised that external wireless users are connected to the DMZ and dns server is on the outside. So will wireless users resolve dns using the outside dns server, and the dns request and reply actually goes through the ASA from DMZ to outside interface? If the dns resolution goes through the ASA firewall, then my solution previously is the correct solution, exactly the same as the following sample configuration:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the sample configuration:&lt;/P&gt;&lt;P&gt;- Your internal mail server would be the www server in DMZ.&lt;/P&gt;&lt;P&gt;- Both dns server for sample config and your config are on the outside of the ASA.&lt;/P&gt;&lt;P&gt;- Both users, your wireless users, and sample config inside users are on a different interface than the actual server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the DNS resolution does not actually pass through the ASA, then you would need to configure the following:&lt;/P&gt;&lt;P&gt;static (dmz,inside) 10.0.0.8 200.0.0.8 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 11:22:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454910#M662929</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-06-21T11:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: DNS and NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454911#M662954</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 Jun 2010 12:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-and-nat-problem/m-p/1454911#M662954</guid>
      <dc:creator>jmprats</dc:creator>
      <dc:date>2010-06-21T12:22:08Z</dc:date>
    </item>
  </channel>
</rss>

