<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA - DNS &amp; NAT problem in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471857#M697668</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Herve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see requests properly NATed going out but nothing coming back in that's not very likely to be the ASA side at fault.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You can check if the ASA is putting correct destination mac address on those packets but that's basically the extent we can do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Jul 2010 10:21:44 GMT</pubDate>
    <dc:creator>Marcin Latosiewicz</dc:creator>
    <dc:date>2010-07-07T10:21:44Z</dc:date>
    <item>
      <title>ASA - DNS &amp; NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471853#M697657</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have an ASA5510&amp;nbsp; with 3 interfaces : inside, outside,dmz.&lt;/P&gt;&lt;P&gt;In the DMZ, a McAfee Web and Security Appliance acting as a proxy&amp;nbsp; (called srv-proxy, IP=192.168.127.52).&lt;/P&gt;&lt;P&gt;srv-proxy is natted to INTERNET (public IP address).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like the srv-proxy to solve DNS requests on some extern DNS servers (srv-dns-oleane).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the simple configuration to do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,outside) INTERNET srv-proxy netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list acl-dmz_public extended permit udp dmz_public 255.255.255.0 object-group srv-dns-oleane eq domain log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By monitoring with ASDM, I can&lt;/P&gt;&lt;P&gt;opendns2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 53&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; srv-proxy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5594&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Built outbound connection 776 for outside:opendns(opendns2/53) to dmz:srv-proxy/5594(INTERNET/5594)&lt;/P&gt;&lt;P&gt;srv-proxy&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5596&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; opendns2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 53&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list acl-dmz_public permitted udp dmz/srv-proxy(5594)-&amp;gt;outside/opendns2(53) hit-cnt1 first hit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With "show nat" and "show xlate", I can see that the nat isworking.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, on the "srv-proxy", "nslookup &lt;A href="http://www.google.com" target="_blank"&gt;www.google.com&lt;/A&gt;" does't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have an old PIX515E? with the same configuration, it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Herve&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:08:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471853#M697657</guid>
      <dc:creator>herve.leon</dc:creator>
      <dc:date>2019-03-11T18:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DNS &amp; NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471854#M697660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Herve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would check what's going on with a packet capture on DMZ and outside interfaces at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also understand that the two interfaces have different security level?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally if logs on informational level do not show you any dropped packets the packet has traversed, unless dropped on ASP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jul 2010 13:40:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471854#M697660</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-07-06T13:40:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DNS &amp; NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471855#M697664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To add to Marcin's response, I would also check the inspect rules. If you have turned on DNS inspection, that could be affecting the response. If the DNS inspection is turned on, try turning it off and see if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Jul 2010 17:38:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471855#M697664</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-06T17:38:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DNS &amp; NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471856#M697665</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your answers.&lt;/P&gt;&lt;P&gt;With Packet Capture on the outside interface, I can see the DNS request leaving with the translated IP towards the DNS servers.&lt;/P&gt;&lt;P&gt;However, I can't see any packets coming&amp;nbsp; from the DNS servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ASA Monitoring, I have:&lt;/P&gt;&lt;P&gt;srv-proxy -&amp;gt; opendns1 (53)&amp;nbsp;&amp;nbsp;&amp;nbsp; access-list acl_dmz_public permitted udp dmz_public/srv-proxy(23452) -&amp;gt; outside/opendns(53) hit-cnt 1 first hit&lt;/P&gt;&lt;P&gt;opendns1 (53) -&amp;gt; srv-proxy (23452)&amp;nbsp; Built outbound UDP connection 10211 for outside:opendns1/53 to dmz_public:srv-proxy/23452 (INTERNET/23452)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why I can't see the Built outbound connection on Packet Capture ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I turned off DNS inspection but it failed too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Herve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2010 09:19:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471856#M697665</guid>
      <dc:creator>herve.leon</dc:creator>
      <dc:date>2010-07-07T09:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DNS &amp; NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471857#M697668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Herve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see requests properly NATed going out but nothing coming back in that's not very likely to be the ASA side at fault.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;You can check if the ASA is putting correct destination mac address on those packets but that's basically the extent we can do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2010 10:21:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471857#M697668</guid>
      <dc:creator>Marcin Latosiewicz</dc:creator>
      <dc:date>2010-07-07T10:21:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DNS &amp; NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471858#M697670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The packet captures just show the raw packet at the interface level. You should see the requests leaving the firewall. If you are using your ISP DNS server, could you use 4.2.2.2 as the DNS Server and see if the proxy server is resolving DNS names? Also, can the proxy server communicate with internet i.e. can you ping your default gateway from the proxy server? If not, it could be an issue with ISP not sending traffic belonging to INTERNET address back to your firewall. You need to check with the ISP and see if they have proper ARP entry (it should be firewalls MAC for INTERNET address too) in their router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2010 12:54:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471858#M697670</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-07-07T12:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: ASA - DNS &amp; NAT problem</title>
      <link>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471859#M697673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to thank all of you for your answers and particularly Nagaraja.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, I configured my PC with the PIX IP address (INTERNET) and connected it directly to the router. The PC can receive DNS requests.&lt;/P&gt;&lt;P&gt;When I reconnected the PIX to the router. It failed to solve DNS names. I rebooted the router to solve this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, I just removed the PIX and put the new ASA in place, rebooted the router again and everything went right.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It took me a long time to solve this, thinking that it was a misconfiguration of the static NAT on the ASA or something else.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your help,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Herve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 09 Jul 2010 10:01:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-dns-nat-problem/m-p/1471859#M697673</guid>
      <dc:creator>herve.leon</dc:creator>
      <dc:date>2010-07-09T10:01:13Z</dc:date>
    </item>
  </channel>
</rss>

