<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS rewrite in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-rewrite/m-p/1278950#M833925</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your observation is correct. Works as expected or breaks as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use destination nat to get around that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,inside) public-ip dmz-1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will let the inside host access the dmz1 host using public IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Jul 2009 14:00:55 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2009-07-03T14:00:55Z</dc:date>
    <item>
      <title>DNS rewrite</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite/m-p/1278949#M833924</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a 5520 failover pair running 8.0(4). There are physical interfaces connected to inside and outside, two DMZ logical interfaces and a logical interface to a services network.&lt;/P&gt;&lt;P&gt;There is a static translation from outside to a DMZ-I host...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (DMZ-I,outside) externaladdress dmzaddress dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The global policy is enabled on all interfaces with DNS inspection. Our DNS servers of parent organisation are located on our services link.&lt;/P&gt;&lt;P&gt;If I query a dns server located on the outside(internet) I get a dns rewrite response with the DMZ-I address.&lt;/P&gt;&lt;P&gt;When I query DNS servers on our services link the response is not rewritten.&lt;/P&gt;&lt;P&gt;Is this expected behaviour as the static is on a different interface to the DNS response?&lt;/P&gt;&lt;P&gt;If so is there a workaround?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:50:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite/m-p/1278949#M833924</guid>
      <dc:creator>lech_2000</dc:creator>
      <dc:date>2019-03-11T15:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: DNS rewrite</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite/m-p/1278950#M833925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Your observation is correct. Works as expected or breaks as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use destination nat to get around that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (dmz,inside) public-ip dmz-1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will let the inside host access the dmz1 host using public IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jul 2009 14:00:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite/m-p/1278950#M833925</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-07-03T14:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: DNS rewrite</title>
      <link>https://community.cisco.com/t5/network-security/dns-rewrite/m-p/1278951#M833926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for you reply Kusankar, this is further complicated by our proxy server sharing a DMZ address with some sites.&lt;/P&gt;&lt;P&gt;I created a static between the services net and the dmz which is enabling the dns replies to be translated..&lt;/P&gt;&lt;P&gt;static (DMZ-I,SERVICES) externaladdress internaladdress dns&lt;/P&gt;&lt;P&gt;thanks again for your help&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jul 2009 14:46:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-rewrite/m-p/1278951#M833926</guid>
      <dc:creator>lech_2000</dc:creator>
      <dc:date>2009-07-03T14:46:27Z</dc:date>
    </item>
  </channel>
</rss>

