<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX AND DNS REVERSE LOOKUP PROBLEM(S) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191945#M732625</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No luck eh, well have a look at this doc and hopefully might help you troubleshoot your problem.. sorry no time to look at your problem in greater detail... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/21.html" target="_blank"&gt;http://www.cisco.com/warp/public/110/21.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Apr 2003 14:42:22 GMT</pubDate>
    <dc:creator>jmia</dc:creator>
    <dc:date>2003-04-24T14:42:22Z</dc:date>
    <item>
      <title>PIX AND DNS REVERSE LOOKUP PROBLEM(S)</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191938#M732585</link>
      <description>&lt;P&gt;Ladies and Gentlemen,  Apparently there is no FIX for this Problem(s).  However, If one of you CISCO Ladies or Gentlemen can Figure this out, Please let me know Soonest...  Thank You in advance.&lt;/P&gt;&lt;P&gt;I have a PIX 5 15 w/failover. On one of my Networks, I have People that have to get to a certain .mil site, but when they attempt to hit certain Links off of it, they cant get to it. When I do a Reverse DNS Lookup Check, it tells me that it is unable to translate my IP Address to a host name, which it is reflecting my PAT Address on my PIX. Now, of course, if I get on one of my Outside DNS Servers, I can get to the Links with no problem. Furthermore, I have a DNS Entry on my outside DNS Server for my Global PAT Address, and it still does not translate.  I have tried everything on Cisco's site to fix this situation, to no avail. This is a much needed item, but I also want to keep my network locked down, and yes I know I cant have my cake and eat it too, but any information/guidance on this would be greatly appreciated. &lt;/P&gt;&lt;P&gt;Can someone please help me with this one. I always try to do things myself, but this is one thing that is kicking my tail. Please Help!  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 06:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191938#M732585</guid>
      <dc:creator>rlowe26</dc:creator>
      <dc:date>2020-02-21T06:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AND DNS REVERSE LOOKUP PROBLEM(S)</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191939#M732591</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any chance you can post your config without the real IP/Passwords etc,etc..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2003 10:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191939#M732591</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2003-04-24T10:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AND DNS REVERSE LOOKUP PROBLEM(S)</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191940#M732594</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, give me a few minutes so I can edit the configs in .txt accordingly.  Thanks!  Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2003 10:56:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191940#M732594</guid>
      <dc:creator>rlowe26</dc:creator>
      <dc:date>2003-04-24T10:56:00Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AND DNS REVERSE LOOKUP PROBLEM(S)</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191941#M732602</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, here it is.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;: Saved&lt;/P&gt;&lt;P&gt;: Written by  &lt;/P&gt;&lt;P&gt;PIX Version 6.2(2)&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;/P&gt;&lt;P&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;nameif ethernet2 intf2 security10&lt;/P&gt;&lt;P&gt;enable password encrypted&lt;/P&gt;&lt;P&gt;passwd encrypted&lt;/P&gt;&lt;P&gt;hostname mypix&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;no fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;no fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;no fixup protocol sqlnet 1521&lt;/P&gt;&lt;P&gt;no fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;no fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;no fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;no fixup protocol ils 389&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any echo-reply &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any time-exceeded &lt;/P&gt;&lt;P&gt;access-list 100 permit icmp any any unreachable &lt;/P&gt;&lt;P&gt;access-list 100 permit tcp any host x.x.x.x eq smtp &lt;/P&gt;&lt;P&gt;access-list 100 permit tcp any host x.x.x.x eq bgp &lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging monitor debugging&lt;/P&gt;&lt;P&gt;logging trap debugging&lt;/P&gt;&lt;P&gt;logging history notifications&lt;/P&gt;&lt;P&gt;logging host inside x.x.x.x&lt;/P&gt;&lt;P&gt;interface ethernet0 100full&lt;/P&gt;&lt;P&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;interface ethernet2 auto shutdown&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;mtu intf2 1500&lt;/P&gt;&lt;P&gt;ip address outside x.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address inside x.x.x.x 255.255.255.0&lt;/P&gt;&lt;P&gt;ip address intf2 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;no failover&lt;/P&gt;&lt;P&gt;failover timeout 0:00:00&lt;/P&gt;&lt;P&gt;failover poll 15&lt;/P&gt;&lt;P&gt;failover ip address outside 0.0.0.0&lt;/P&gt;&lt;P&gt;failover ip address inside x.x.x.x&lt;/P&gt;&lt;P&gt;failover ip address intf2 x.x.x.x&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 x.x.x.x netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.x.x x.x.x.x netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;static (inside,outside) x.x.x.x x.x.x.x netmask 255.255.255.255 0 0 &lt;/P&gt;&lt;P&gt;access-group 100 in interface outside&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+ &lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius &lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local &lt;/P&gt;&lt;P&gt;filter activex 80 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0 &lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community xxxxxxxx&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;tftp-server inside x.x.x.x pixconfig&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;sysopt security fragguard&lt;/P&gt;&lt;P&gt;no sysopt route dnat&lt;/P&gt;&lt;P&gt;telnet x.x.x.x 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 30&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;terminal width 80&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I havent implemented my DMZ yet, but I will be doing that this weekend.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have "Service resetoutside"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ron&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2003 11:09:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191941#M732602</guid>
      <dc:creator>rlowe26</dc:creator>
      <dc:date>2003-04-24T11:09:53Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AND DNS REVERSE LOOKUP PROBLEM(S)</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191942#M732607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I presume that your internal clients /PC's are using your outside DNS IP address? also try &amp;lt; sysopt no proxyarp inside &amp;gt; and see what happens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks - &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2003 11:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191942#M732607</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2003-04-24T11:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AND DNS REVERSE LOOKUP PROBLEM(S)</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191943#M732613</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My internal clients are using NAT on the inside.  I have Inside DNS and Outside DNS.  I just tried it.  It didnt work. Ron&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2003 12:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191943#M732613</guid>
      <dc:creator>rlowe26</dc:creator>
      <dc:date>2003-04-24T12:50:02Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AND DNS REVERSE LOOKUP PROBLEM(S)</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191944#M732619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have a forward dns entry for your pix ip address, but how about reverse? Meaning, you have a dns  A record for &lt;A class="jive-link-custom" href="http://www.bob.com," target="_blank"&gt;www.bob.com,&lt;/A&gt; but no reverse record for 1.2.3.4 to &lt;A class="jive-link-custom" href="http://www.bob.com" target="_blank"&gt;www.bob.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2003 14:40:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191944#M732619</guid>
      <dc:creator>mostiguy</dc:creator>
      <dc:date>2003-04-24T14:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: PIX AND DNS REVERSE LOOKUP PROBLEM(S)</title>
      <link>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191945#M732625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ron,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No luck eh, well have a look at this doc and hopefully might help you troubleshoot your problem.. sorry no time to look at your problem in greater detail... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/warp/public/110/21.html" target="_blank"&gt;http://www.cisco.com/warp/public/110/21.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Apr 2003 14:42:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-and-dns-reverse-lookup-problem-s/m-p/191945#M732625</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2003-04-24T14:42:22Z</dc:date>
    </item>
  </channel>
</rss>

