<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: eMail Server in DMZ can't get DNS service from AD/DNS server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255986#M757752</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK to fix the internet access for the email server you need should add the below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow the email server to access the internet, however this will also allow all access to the inside, so you also need to add&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended deny ip any host 172.120.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the complete acl should look like:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended permit icmp any 172.20.100.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list acl-dmz extended permit ip any host 172.120.100.(AD/DNS)&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended deny ip any host 172.120.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 20 Oct 2009 07:53:25 GMT</pubDate>
    <dc:creator>andrew.prince</dc:creator>
    <dc:date>2009-10-20T07:53:25Z</dc:date>
    <item>
      <title>eMail Server in DMZ can't get DNS service from AD/DNS server in Inside</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255979#M757745</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am having trouble to have the Exchange server get Internet access on moving it from the Inside zone to the newly created DMZ. The design is asking to keep the AD which had the DNS server as well, in the Inside network.&lt;/P&gt;&lt;P&gt;I have made static (Inside,DMZ) to have the DNS server appears with its physical IP address to the DMZ (no natting) and for purpose of testing, I did allowed all IP traffic from DMZ to Inside.&lt;/P&gt;&lt;P&gt;Furthermore, I have added DNS for DNS doctoring to the static statement, but problem persists. Plz note the clients in the inside network access internet and the email server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate you expertise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:27:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255979#M757745</guid>
      <dc:creator>ccie16351</dc:creator>
      <dc:date>2019-03-11T16:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: eMail Server in DMZ can't get DNS service from AD/DNS server</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255980#M757746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to ensure the DMZ server has a NAT or PAT to the outside to access the internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Oct 2009 10:31:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255980#M757746</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-19T10:31:24Z</dc:date>
    </item>
    <item>
      <title>Re: eMail Server in DMZ can't get DNS service from AD/DNS server</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255981#M757747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Andrew,&lt;/P&gt;&lt;P&gt;actually it has nat (dmz) and it uses the same global which serves the inside network. I verified Internet access by changing it to DNS of the ISP, it works fine, but the local admin has his own reasons to use the local DNS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Oct 2009 11:33:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255981#M757747</guid>
      <dc:creator>ccie16351</dc:creator>
      <dc:date>2009-10-19T11:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: eMail Server in DMZ can't get DNS service from AD/DNS server</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255982#M757748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK - for every no we are closer to a yes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the full NAT &amp;amp; Access-lists you have configured, remove any sensitive information.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Oct 2009 11:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255982#M757748</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-19T11:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: eMail Server in DMZ can't get DNS service from AD/DNS server</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255983#M757749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Andrew,&lt;/P&gt;&lt;P&gt;I have attached the critical portion of the config. file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 19 Oct 2009 15:37:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255983#M757749</guid>
      <dc:creator>ccie16351</dc:creator>
      <dc:date>2009-10-19T15:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: eMail Server in DMZ can't get DNS service from AD/DNS server</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255984#M757750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK I see the config - remind me again what exactly the problem is, as looking at the config I can see multiple potential issues.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 07:41:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255984#M757750</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-20T07:41:00Z</dc:date>
    </item>
    <item>
      <title>Re: eMail Server in DMZ can't get DNS service from AD/DNS server</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255985#M757751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;the issue is, on moving the eMail server to DMZ it loose access to the web, while the internal user keep accessing the web. Pls note, the AD/DNS is in the inside network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 07:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255985#M757751</guid>
      <dc:creator>ccie16351</dc:creator>
      <dc:date>2009-10-20T07:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: eMail Server in DMZ can't get DNS service from AD/DNS server</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255986#M757752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK to fix the internet access for the email server you need should add the below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will allow the email server to access the internet, however this will also allow all access to the inside, so you also need to add&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended deny ip any host 172.120.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the complete acl should look like:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended permit icmp any 172.20.100.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;access-list acl-dmz extended permit ip any host 172.120.100.(AD/DNS)&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended deny ip any host 172.120.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list acl-dmz extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 07:53:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255986#M757752</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2009-10-20T07:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: eMail Server in DMZ can't get DNS service from AD/DNS server</title>
      <link>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255987#M757753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Andrew, your observation sounds logic. Instead of permit IP any any at DMZ, I will permit the Server's host address to any.&lt;/P&gt;&lt;P&gt;I will try it and post the rating if solved the problem. Until then, please accept my regards. Sam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Oct 2009 08:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/email-server-in-dmz-can-t-get-dns-service-from-ad-dns-server-in/m-p/1255987#M757753</guid>
      <dc:creator>ccie16351</dc:creator>
      <dc:date>2009-10-20T08:14:57Z</dc:date>
    </item>
  </channel>
</rss>

