<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DNS Issue due to translation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378490#M836781</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Remove the "dns" keyword from the static. This should resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The inside hosts are getting resolution from the inside DNS and they are wroking fine.&lt;/P&gt;&lt;P&gt;The outside folks do not need to get the inside IP upon resolving so, remove the dns keyword from the static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Apr 2010 12:00:15 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2010-04-07T12:00:15Z</dc:date>
    <item>
      <title>DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378483#M836774</link>
      <description>&lt;P&gt;Hey Everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am facing a DNS issue due to NAT, i think dns doctoring can solve this but the scenario is a little different so not sure of the exact solution.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is the network diagram. Exchange Server , DNS and Domain Controller are all located on a single physical server which has an IP 172.20.10.100. Both the server and the intenal users reside on the inside subnet. In the DNS the name-to-IP mapping is for example srv.abc.com -&amp;gt; 172.20.10.100. The Inside users have no connectivity issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The server is translated to 192.168.100.20 when accessing the outside network, this is a static translation&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (Inside,Outside) 192.168.100.20 172.20.10.100 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Branch users when they access they try to resolve srv.abc.com get the mapping to 172.20.10.100 which does not allow communication using name as Branch users cannot access 172.20.10.100 but they can access 192.168.100.20.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What needs to be configured on the ASA to resolve this issue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will this work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (Inside,Outside) 192.168.100.20 172.20.10.100 netmask&amp;nbsp; 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zeeshan&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:29:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378483#M836774</guid>
      <dc:creator>Muhammad Zeeshan Sanaullah</dc:creator>
      <dc:date>2019-03-11T17:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378484#M836775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, dns doctoring will work as long as the branch user uses 192.168.100.20 as its dns server for dns resolution.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2010 11:07:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378484#M836775</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-06T11:07:44Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378485#M836776</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="jiveTT-hover-user&amp;nbsp; jive-username-link"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;A class="jiveTT-hover-user&amp;nbsp; jive-username-link" href="https://community.cisco.com/people/halijenn" id="jive-16889021,141,230,171,882,532" onmouseout="" onmouseover=""&gt;halijenn&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It didn't work. I specified the command using dns keyword and flushed the DNS on the Branch host, the host still resolves the name of the server to 172.20.10.100. Is there any other thing which needs to be done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zeeshan Sanaullah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2010 13:07:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378485#M836776</guid>
      <dc:creator>Muhammad Zeeshan Sanaullah</dc:creator>
      <dc:date>2010-04-06T13:07:59Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378486#M836777</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is the user using the public ip address of the HQ dns server for dns resolution? It will only work if the dns request passes through the HQ ASA where the static with "dns" keyword is configured, and the reply goes back through the ASA as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please confirm what DNS server is used at your branch host?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2010 13:17:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378486#M836777</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-06T13:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378487#M836778</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Branch user has 192.168.100.20 configured as the DNS Server. Yes the DNS request passes through the ASA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2010 13:37:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378487#M836778</guid>
      <dc:creator>Muhammad Zeeshan Sanaullah</dc:creator>
      <dc:date>2010-04-06T13:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378488#M836779</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is dns inspection also enabled on the HQ ASA?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2010 03:21:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378488#M836779</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-07T03:21:31Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378489#M836780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DNS Inspection is on ... as shown below&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt; match default-inspection-traffic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;BR /&gt; class inspection_default&lt;BR /&gt;&amp;nbsp; inspect ftp &lt;BR /&gt;&amp;nbsp; inspect h323 h225 &lt;BR /&gt;&amp;nbsp; inspect h323 ras &lt;BR /&gt;&amp;nbsp; inspect netbios &lt;BR /&gt;&amp;nbsp; inspect rsh &lt;BR /&gt;&amp;nbsp; inspect rtsp &lt;BR /&gt;&amp;nbsp; inspect skinny &lt;BR /&gt;&amp;nbsp; inspect sunrpc &lt;BR /&gt;&amp;nbsp; inspect tftp &lt;BR /&gt;&amp;nbsp; inspect xdmcp &lt;BR /&gt;&amp;nbsp; inspect esmtp &lt;BR /&gt;&amp;nbsp; inspect dns &lt;BR /&gt;&amp;nbsp; inspect http&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2010 06:31:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378489#M836780</guid>
      <dc:creator>Muhammad Zeeshan Sanaullah</dc:creator>
      <dc:date>2010-04-07T06:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378490#M836781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Remove the "dns" keyword from the static. This should resolve the issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The inside hosts are getting resolution from the inside DNS and they are wroking fine.&lt;/P&gt;&lt;P&gt;The outside folks do not need to get the inside IP upon resolving so, remove the dns keyword from the static.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2010 12:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378490#M836781</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-04-07T12:00:15Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378491#M836782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;@kusankar&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The actual configuration is without dns keyword. I added dns keyword to see if the issue resolves but it did not.&lt;/P&gt;&lt;P&gt;Outside hosts when they resolve srv.abc.com they get 172.20.10.100 but they should get 192.168.100.20 after dns keyword is entered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@halijenn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ASA OS version is 7.07&amp;nbsp; ... can it be software issue ???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Zeeshan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2010 15:21:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378491#M836782</guid>
      <dc:creator>Muhammad Zeeshan Sanaullah</dc:creator>
      <dc:date>2010-04-07T15:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: DNS Issue due to translation</title>
      <link>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378492#M836783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you temporarily just remove dns inspection and see if this works. If it does then we can exclude dns inspection for this remote network and add dns inspection for all other traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Apr 2010 15:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-issue-due-to-translation/m-p/1378492#M836783</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-04-07T15:30:55Z</dc:date>
    </item>
  </channel>
</rss>

