<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two Domains DNS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258197#M858580</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, there is our network sample configuration that is worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside) Public network IP 202.20.1.0/24 &lt;/P&gt;&lt;P&gt;(Inside) Pivate 192.168.100.0/24&lt;/P&gt;&lt;P&gt;*** Public IP 202.20.1.10 www nat map to private IP 192.168.100.10 www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit tcp any host 202.20.1.10 eq www&lt;/P&gt;&lt;P&gt;!--- Simple access-list that permits HTTP access to the mapped&lt;/P&gt;&lt;P&gt;!--- address of the WWW server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,outside) 202.20.1.10 192.168.100.10 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;!--- PAT and static NAT configuration. The DNS keyword instructs&lt;/P&gt;&lt;P&gt;!--- the security appliance to rewrite DNS records related to this entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group OUTSIDE in interface outside&lt;/P&gt;&lt;P&gt;!--- The Access Control List (ACL) that permits HTTP access&lt;/P&gt;&lt;P&gt;!--- to the WWW server is applied to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect dns MY_DNS_INSPECT_MAP&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;!--- DNS inspection map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns MY_DNS_INSPECT_MAP&lt;/P&gt;&lt;P&gt;!--- DNS inspection is enabled using the configured map.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 19 Jul 2009 08:12:32 GMT</pubDate>
    <dc:creator>pccw258103</dc:creator>
    <dc:date>2009-07-19T08:12:32Z</dc:date>
    <item>
      <title>Two Domains DNS</title>
      <link>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258193#M858573</link>
      <description>&lt;P&gt;Hi, hope someone can help&lt;/P&gt;&lt;P&gt;I have a ASA 5510 with 2 domains connected to separate internal interfaces both NAT'ed to public IPs and one external interface with a public IP everything is working great apart from if one domain sends an email to the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal users on each domain resolve the other domain name to it's public ip. I have setup DNS rewrite but this has not solved the problem, all external users can access both domains.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:56:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258193#M858573</guid>
      <dc:creator>jwright</dc:creator>
      <dc:date>2019-03-11T15:56:35Z</dc:date>
    </item>
    <item>
      <title>Re: Two Domains DNS</title>
      <link>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258194#M858576</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, where do the DNS place at??&lt;/P&gt;&lt;P&gt;Internal Interfaces or Outside interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Jul 2009 04:09:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258194#M858576</guid>
      <dc:creator>pccw258103</dc:creator>
      <dc:date>2009-07-19T04:09:58Z</dc:date>
    </item>
    <item>
      <title>Re: Two Domains DNS</title>
      <link>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258195#M858578</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, where do the DNS place at??&lt;/P&gt;&lt;P&gt;Internal Interfaces or Outside interfaces&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Jul 2009 04:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258195#M858578</guid>
      <dc:creator>pccw258103</dc:creator>
      <dc:date>2009-07-19T04:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Two Domains DNS</title>
      <link>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258196#M858579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Outside interface DNS servers.&lt;/P&gt;&lt;P&gt;thanks &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Jul 2009 07:03:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258196#M858579</guid>
      <dc:creator>jwright</dc:creator>
      <dc:date>2009-07-19T07:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Two Domains DNS</title>
      <link>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258197#M858580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, there is our network sample configuration that is worked fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Outside) Public network IP 202.20.1.0/24 &lt;/P&gt;&lt;P&gt;(Inside) Pivate 192.168.100.0/24&lt;/P&gt;&lt;P&gt;*** Public IP 202.20.1.10 www nat map to private IP 192.168.100.10 www &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list OUTSIDE extended permit tcp any host 202.20.1.10 eq www&lt;/P&gt;&lt;P&gt;!--- Simple access-list that permits HTTP access to the mapped&lt;/P&gt;&lt;P&gt;!--- address of the WWW server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 1 192.168.100.0 255.255.255.0&lt;/P&gt;&lt;P&gt;static (inside,outside) 202.20.1.10 192.168.100.10 netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;!--- PAT and static NAT configuration. The DNS keyword instructs&lt;/P&gt;&lt;P&gt;!--- the security appliance to rewrite DNS records related to this entry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-group OUTSIDE in interface outside&lt;/P&gt;&lt;P&gt;!--- The Access Control List (ACL) that permits HTTP access&lt;/P&gt;&lt;P&gt;!--- to the WWW server is applied to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type inspect dns MY_DNS_INSPECT_MAP&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;!--- DNS inspection map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns MY_DNS_INSPECT_MAP&lt;/P&gt;&lt;P&gt;!--- DNS inspection is enabled using the configured map.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Jul 2009 08:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258197#M858580</guid>
      <dc:creator>pccw258103</dc:creator>
      <dc:date>2009-07-19T08:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: Two Domains DNS</title>
      <link>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258198#M858581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sample network diag&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 19 Jul 2009 08:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258198#M858581</guid>
      <dc:creator>pccw258103</dc:creator>
      <dc:date>2009-07-19T08:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: Two Domains DNS</title>
      <link>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258199#M858582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the example cofig and diagram, I have attached a layout of what I am trying to achieve, if company 1 send an email to company 2 it fails, or browses a web page hosted by the other company. I want the 2 companies to be separate although they are both using the same ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Jul 2009 07:46:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/two-domains-dns/m-p/1258199#M858582</guid>
      <dc:creator>jwright</dc:creator>
      <dc:date>2009-07-20T07:46:12Z</dc:date>
    </item>
  </channel>
</rss>

