<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure DNS on ASA firewall ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556145#M836150</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please check the following on your configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. You have configured a default route pointing to your ISP router IP&lt;/P&gt;&lt;P&gt;	route outside 0.0.0.0 0.0.0.0 "ISP gw"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You have configured dynamic NAT rules for inside hosts&lt;/P&gt;&lt;P&gt;	global (outside) 1 interface&lt;/P&gt;&lt;P&gt;	nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. You do not have any access-list entries applied to inside interface that&lt;/P&gt;&lt;P&gt;is blocking traffic from inside to internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. You do not have any NAT rule that bypasses the NAT rules in the second&lt;/P&gt;&lt;P&gt;step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After verifying the above steps, if things are still not working, can you&lt;/P&gt;&lt;P&gt;please post your configuration here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 07 Sep 2010 11:40:53 GMT</pubDate>
    <dc:creator>Nagaraja Thanthry</dc:creator>
    <dc:date>2010-09-07T11:40:53Z</dc:date>
    <item>
      <title>How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556143#M836143</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to cisco ASA firewall. As shown on cisco website i have done my basic configuration on ASA. But still i am not able to connect to internet. I think i have some problem in DNS server. Can anyone tell me how to configure DNS on ASA ??&lt;/P&gt;&lt;P&gt;Thanks...&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:36:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556143#M836143</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2019-03-11T18:36:01Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556144#M836145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How is the user getting the IP Address? Is it through DHCP, and which device is the DHCP server? DNS settings are normally configured via the DHCP configuration. If you do not have internal DNS server, you would need to assign DNS servers that have been assigned by your ISP on the DHCP configuration, and/or manually configure the DNS settings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able to access the internet via IP Address?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:37:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556144#M836145</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-09-07T11:37:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556145#M836150</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please check the following on your configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. You have configured a default route pointing to your ISP router IP&lt;/P&gt;&lt;P&gt;	route outside 0.0.0.0 0.0.0.0 "ISP gw"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. You have configured dynamic NAT rules for inside hosts&lt;/P&gt;&lt;P&gt;	global (outside) 1 interface&lt;/P&gt;&lt;P&gt;	nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. You do not have any access-list entries applied to inside interface that&lt;/P&gt;&lt;P&gt;is blocking traffic from inside to internet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. You do not have any NAT rule that bypasses the NAT rules in the second&lt;/P&gt;&lt;P&gt;step.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After verifying the above steps, if things are still not working, can you&lt;/P&gt;&lt;P&gt;please post your configuration here?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:40:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556145#M836150</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-09-07T11:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556146#M836153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lan users are configured manually with ip address. i didnt use DHCP for that. I also use command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns lookup inside&lt;/P&gt;&lt;P&gt;dns name-server&amp;nbsp; (dns server provided by ISP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but still i am not able to connect to internet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am having cisco router at front end. firewall outside address is routers inside address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when i connect through router bypassing firewall i am able to connect to internet..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats the possibal problem ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:43:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556146#M836153</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2010-09-07T11:43:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556147#M836159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;dear Nagaraja,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes i done all these basic configurations..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 days ago all thing are working fine. But today morning no one from LAN not able to connect to internet..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Whats the possibal problem ??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556147#M836159</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2010-09-07T11:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556148#M836163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vinayak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA can not act as a DNS server or proxy DNS or dns caching only server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you configured the Default Route towards the ISP (assume default gateway is 100.100.100.200)&lt;/P&gt;&lt;P&gt;ASA5520(config)# route outside 0.0.0.0 0.0.0.0 100.100.100.200 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the basic config I suppose you have done already on your ASA firewall:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step1: Configure a privileged level password (enable password)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By default there is no password for accessing the ASA firewall, so the first step before doing anything else is to configure a privileged level password, which will be needed to allow subsequent access to the appliance. Configure this under Configuration Mode:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA5520(config)# enable password mysecretpassword&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step2: Configure the public outside interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ASA5520(config)# interface Ethernet0/0&lt;BR /&gt;ASA5520(config-if)# nameif outside&lt;BR /&gt;ASA5520(config-if)# security-level 0&lt;BR /&gt;ASA5520(config-if)# ip address 100.100.100.1 255.255.255.252&lt;BR /&gt;ASA5520(config-if)# no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step3: Configure the trusted internal interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ASA5520(config)# interface Ethernet0/1&lt;BR /&gt;ASA5520(config-if)# nameif inside&lt;BR /&gt;ASA5520(config-if)# security-level 100&lt;BR /&gt;ASA5520(config-if)# ip address 192.168.10.1 255.255.255.0&lt;BR /&gt;ASA5520(config-if)# no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Step 4: Configure PAT on the outside interface&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ASA5520(config)# global (outside) 1 interface&lt;BR /&gt;ASA5520(config)# nat (inside) 1 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure the firewall to assign internal IP and DNS address to hosts using DHCP&lt;/P&gt;&lt;P&gt;ASA5520(config)# dhcpd dns 200.200.200.10&lt;BR /&gt;ASA5520(config)# dhcpd address 192.168.10.10-192.168.10.200 inside&lt;BR /&gt;ASA5520(config)# dhcpd enable inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above basic configuration is just the beginning for making the appliance operational.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;There are many more configuration features that you need to implement to increase the security of your network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Configuring DNS and NAT refer the following:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www1.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_overview.html#wp1079324"&gt;http://www1.cisco.com/en/US/docs/security/asa/asa82/configuration/guide/nat_overview.html#wp1079324&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;In a typical DNS exchange a client sends a URL or hostname to a DNS server in order to determine the IP address of that host. The DNS server receives the request, looks up the name-to-IP-address mapping for that host, and then provides the A-record with the IP address to the client. While this procedure works well in many situations, problems can occur. These problems can occur when the client and the host that the client tries to reach are both on the same private network behind NAT, but the DNS server used by the client is on another public network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;May be you need to Perform DNS Doctoring with the static Command .&lt;/P&gt;&lt;P&gt;Find the reference link here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml#problem"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml#problem&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Without looking at your config can not tell you specifically what command is missing in your config.&lt;/P&gt;&lt;P&gt;If you could send you config to me on my email &lt;A href="mailto:sachinga@hcl.in"&gt;sachinga@hcl.in&lt;/A&gt; or &lt;A href="mailto:sachin.koenig@gmail.com"&gt;sachin.koenig@gmail.com&lt;/A&gt; , I will be able to tell what command is missing so as to get to Internet access. You can change your confidential IP by some example IP addesses or putting 200.200.x.y so as to maintain your security.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Sachin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:52:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556148#M836163</guid>
      <dc:creator>sachinga.hcl</dc:creator>
      <dc:date>2010-09-07T11:52:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556149#M836167</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the DNS server IP you are using? Try using 4.2.2.2 on your PC and&lt;/P&gt;&lt;P&gt;see if you are able to connect to internet. Also, try pinging your default&lt;/P&gt;&lt;P&gt;gateway (Router IP) from the PC to make sure that the traffic is going out&lt;/P&gt;&lt;P&gt;of the firewall and is returning fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 11:56:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556149#M836167</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-09-07T11:56:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556150#M836171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear sachin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for ur reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i already done all these basic configs.. But still problem is same. I also able to ping my routers IP from LAN..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this a right commands :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dns domain-lookup&lt;/P&gt;&lt;P&gt;dns name-server (dns ip rovided by ISP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;are these commands sufficient for DNS ??&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 12:04:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556150#M836171</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2010-09-07T12:04:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556151#M836175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vinayak,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On your PC, what is the DNS setting? Are you pointing to the ASA or are you&lt;/P&gt;&lt;P&gt;pointing to the ISP DNS server? Can you do a NSLOOKUP for a domain and see&lt;/P&gt;&lt;P&gt;if you get a response?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 12:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556151#M836175</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-09-07T12:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556152#M836179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Nagaraja.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I using ISP DNS servers on my PC.&amp;nbsp; everythink working fine till yesterday, but this problem arises today morning.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i do nslookup it shows DNS REQUEST TIME OUT...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 12:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556152#M836179</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2010-09-07T12:11:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556153#M836183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try 4.2.2.2 as DNS server and see if that works. It could be that the ISP&lt;/P&gt;&lt;P&gt;DNS server may be having issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;NT&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 12:14:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556153#M836183</guid>
      <dc:creator>Nagaraja Thanthry</dc:creator>
      <dc:date>2010-09-07T12:14:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure DNS on ASA firewall ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556154#M836187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok , i will try it..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks a lot for help...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Sep 2010 12:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-configure-dns-on-asa-firewall/m-p/1556154#M836187</guid>
      <dc:creator>vinayak</dc:creator>
      <dc:date>2010-09-07T12:16:27Z</dc:date>
    </item>
  </channel>
</rss>

