<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DNS and static address in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dns-and-static-address/m-p/1217318#M859734</link>
    <description>&lt;P&gt;This morning, as a test, I did the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA internal ip address: 10.20.0.1&lt;/P&gt;&lt;P&gt;Workstation address: 10.20.0.50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set the workstation's DNS server as 10.20.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ASA I did:&lt;/P&gt;&lt;P&gt;static (outside,inside) udp interface 53 4.2.2.1 53 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could browse the web. My question is the fact that I don't own the 4.2.2.1 address, as that's Verizon's DNS server. To Verizon, would that look like 4.2.2.1 is querying their own DNS server? Am I, in effect, spoofing an address that they own, or am I really just forwarding the 53/udp traffic out TO 4.2.2.1 as my public address that's assigned to my ASA's outside interface? Just curious. (I didn't leave this in production.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:33:31 GMT</pubDate>
    <dc:creator>John Blakley</dc:creator>
    <dc:date>2019-03-11T15:33:31Z</dc:date>
    <item>
      <title>DNS and static address</title>
      <link>https://community.cisco.com/t5/network-security/dns-and-static-address/m-p/1217318#M859734</link>
      <description>&lt;P&gt;This morning, as a test, I did the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA internal ip address: 10.20.0.1&lt;/P&gt;&lt;P&gt;Workstation address: 10.20.0.50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set the workstation's DNS server as 10.20.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the ASA I did:&lt;/P&gt;&lt;P&gt;static (outside,inside) udp interface 53 4.2.2.1 53 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I could browse the web. My question is the fact that I don't own the 4.2.2.1 address, as that's Verizon's DNS server. To Verizon, would that look like 4.2.2.1 is querying their own DNS server? Am I, in effect, spoofing an address that they own, or am I really just forwarding the 53/udp traffic out TO 4.2.2.1 as my public address that's assigned to my ASA's outside interface? Just curious. (I didn't leave this in production.)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:33:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-and-static-address/m-p/1217318#M859734</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2019-03-11T15:33:31Z</dc:date>
    </item>
    <item>
      <title>Re: DNS and static address</title>
      <link>https://community.cisco.com/t5/network-security/dns-and-static-address/m-p/1217319#M859736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, you are only translating the destination address. The source address is still whatever you are nating it to. If you were translating to 4.2.2.1 the return traffic would never make it back to you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 May 2009 17:27:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-and-static-address/m-p/1217319#M859736</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2009-05-18T17:27:13Z</dc:date>
    </item>
    <item>
      <title>Re: DNS and static address</title>
      <link>https://community.cisco.com/t5/network-security/dns-and-static-address/m-p/1217320#M859740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I asked Cisco TAC this same question on Saturday though, and they said that it couldn't be done. I'm just wondering if this is something that's safe to leave in place because it provided a VERY nice workaround. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 May 2009 17:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dns-and-static-address/m-p/1217320#M859740</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-05-18T17:29:40Z</dc:date>
    </item>
  </channel>
</rss>

