<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Ping can' Resolve DNS Pix in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124130#M893932</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks I did the debug private to public - here you go for the proper debug. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gabrielle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 07 Nov 2008 14:04:54 GMT</pubDate>
    <dc:creator>cozyk1515</dc:creator>
    <dc:date>2008-11-07T14:04:54Z</dc:date>
    <item>
      <title>Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124120#M893921</link>
      <description>&lt;P&gt;I have a Pix 501 that is for management devices. The Pix is 10.100.0.1 and devices are in the same C class.  These devices can ping any IP address I want yahoo.com, google.com etc. however can't resolve by NAME only IP. IE ping &lt;A class="jive-link-custom" href="http://www.yahoo.com." target="_blank"&gt;www.yahoo.com.&lt;/A&gt; If they can ping the address of yahoo it is getting to the DNS servers. Am I missing something here?  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gabrielle&lt;/P&gt;&lt;P&gt;Network and Sys Admin&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124120#M893921</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2019-03-11T14:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124121#M893923</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Anyone?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 19:13:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124121#M893923</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2008-11-06T19:13:28Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124122#M893924</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gabrielle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would help if you posted config +&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the clients DNS server set to ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 19:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124122#M893924</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T19:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124123#M893925</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;PIX Version 6.3(4)&lt;/P&gt;&lt;P&gt;hostname xxx.xxx&lt;/P&gt;&lt;P&gt;domain-name xxx.com&lt;/P&gt;&lt;P&gt;no fixup protocol dns&lt;/P&gt;&lt;P&gt;fixup protocol ftp 21&lt;/P&gt;&lt;P&gt;fixup protocol h323 h225 1720&lt;/P&gt;&lt;P&gt;fixup protocol h323 ras 1718-1719&lt;/P&gt;&lt;P&gt;fixup protocol http 80&lt;/P&gt;&lt;P&gt;fixup protocol mgcp 5060&lt;/P&gt;&lt;P&gt;fixup protocol pptp 1723&lt;/P&gt;&lt;P&gt;fixup protocol rsh 514&lt;/P&gt;&lt;P&gt;fixup protocol rtsp 554&lt;/P&gt;&lt;P&gt;fixup protocol sip 5060&lt;/P&gt;&lt;P&gt;fixup protocol sip udp 5060&lt;/P&gt;&lt;P&gt;fixup protocol skinny 2000&lt;/P&gt;&lt;P&gt;fixup protocol smtp 25&lt;/P&gt;&lt;P&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;name 10.100.0.13 OSI1&lt;/P&gt;&lt;P&gt;name 10.100.0.14 OSI2&lt;/P&gt;&lt;P&gt;name 10.100.0.28 Calix&lt;/P&gt;&lt;P&gt;name x.x.x.x Calix-Outside&lt;/P&gt;&lt;P&gt;name x.x.x.x OSI-1-Outside&lt;/P&gt;&lt;P&gt;name x.x.x.x OSI-2-Outside&lt;/P&gt;&lt;P&gt;object-group network OSI-TAC&lt;/P&gt;&lt;P&gt;  network-object host 67.132.187.193&lt;/P&gt;&lt;P&gt;  network-object host x.x.x.x&lt;/P&gt;&lt;P&gt;object-group network CALIX_TAC&lt;/P&gt;&lt;P&gt;  network-object host x.x.x.x&lt;/P&gt;&lt;P&gt;  network-object host x.x.x.x&lt;/P&gt;&lt;P&gt;  network-object host x.x.x.x&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp object-group OSI-TAC host OSI-1-Outside eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp object-group OSI-TAC host OSI-1-Outside eq htt&lt;/P&gt;&lt;P&gt;ps&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp object-group OSI-TAC host OSI-1-Outside eq 200&lt;/P&gt;&lt;P&gt;1&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp object-group OSI-TAC host OSI-2-Outside eq www&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host Calix-Outside eq www&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host Calix-Outside eq https&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host Calix-Outside eq 50000&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host Calix-Outside eq telnet&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host OSI-1-Outside eq www&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host OSI-1-Outside eq https&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host OSI-1-Outside eq 2001&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host OSI-2-Outside eq www&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host OSI-2-Outside eq https&lt;/P&gt;&lt;P&gt;access-list outside_in permit tcp host PL-CTC-LAN host OSI-2-Outside eq 2001&lt;/P&gt;&lt;P&gt;access-list 140 permit udp any any eq bootps&lt;/P&gt;&lt;P&gt;access-list 140 permit udp any any eq 547&lt;/P&gt;&lt;P&gt;access-list 110 deny tcp any any eq ftp&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;logging on&lt;/P&gt;&lt;P&gt;logging timestamp&lt;/P&gt;&lt;P&gt;logging buffered warnings&lt;/P&gt;&lt;P&gt;logging trap warnings&lt;/P&gt;&lt;P&gt;logging history warnings&lt;/P&gt;&lt;P&gt;icmp permit x.x.x.x 255.255.255.128 echo-reply outside&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply outside&lt;/P&gt;&lt;P&gt;icmp permit any outside&lt;/P&gt;&lt;P&gt;icmp permit any echo-reply inside&lt;/P&gt;&lt;P&gt;icmp permit any inside&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;/P&gt;&lt;P&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;ip address outside x.x.x.x 255.255.255.128&lt;/P&gt;&lt;P&gt;ip address inside 10.100.0.100 255.255.0.0&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;/P&gt;&lt;P&gt;ip audit attack action alarm&lt;/P&gt;&lt;P&gt;ip local pool pltechpool 10.101.0.1-10.101.0.254 mask 255.255.0.0&lt;/P&gt;&lt;P&gt;pdm history enable&lt;/P&gt;&lt;P&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;/P&gt;&lt;P&gt;nat (inside) 0 access-list nonat&lt;/P&gt;&lt;P&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) Calix-Outside Calix netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) OSI-1-Outside OSI1 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;static (inside,outside) OSI-2-Outside OSI2 netmask 255.255.255.255 0 0&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 x.x.x.x 1&lt;/P&gt;&lt;P&gt;route inside 10.0.0.0 255.255.0.0 10.0.0.52 1&lt;/P&gt;&lt;P&gt;route inside x.x.x.x 255.255.255.252 10.0.0.1 1&lt;/P&gt;&lt;P&gt;timeout xlate 3:00:00&lt;/P&gt;&lt;P&gt;timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h225 1:00:00&lt;/P&gt;&lt;P&gt;timeout h323 0:05:00 mgcp 0:05:00 sip 0:30:00 sip_media 0:02:00&lt;/P&gt;&lt;P&gt;timeout uauth 0:05:00 absolute&lt;/P&gt;&lt;P&gt;aaa-server radius-authport 1812&lt;/P&gt;&lt;P&gt;aaa-server radius-acctport 1813&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;/P&gt;&lt;P&gt;no snmp-server contact&lt;/P&gt;&lt;P&gt;snmp-server community public&lt;/P&gt;&lt;P&gt;no snmp-server enable traps&lt;/P&gt;&lt;P&gt;floodguard enable&lt;/P&gt;&lt;P&gt;sysopt connection permit-ipse&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;dhcprelay server x.x.x.x outside&lt;/P&gt;&lt;P&gt;dhcprelay enable inside&lt;/P&gt;&lt;P&gt;dhcprelay setroute inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 19:30:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124123#M893925</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2008-11-06T19:30:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124124#M893926</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gabrielle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;None of your access-lists are applied to any interface which is okay for this issue, just wanted to check that you noticed this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have setup NAT so your clients on the inside LAN can get out to the Internet and that is why they can connect to the IP addresses of Internet sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But what DNS server does the client have setup - does it have one and if it does can this DNS server resolve Internet names.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it doesn't have one you need one and it needs to be able to either &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) resolve Internet names &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) be able to forward requests onto DNS servers than can do 1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 19:44:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124124#M893926</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T19:44:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124125#M893927</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The DNS servers are able to resolve Internet names It is the DNS servers that I use for all our customers (ISP) it is a Public IP Address not a Private IP.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 19:50:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124125#M893927</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2008-11-06T19:50:25Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124126#M893928</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Right so a client on the inside LAN has the default-gateway set to the pix and has the DNS server set to a DNS server that can resolve Internet names.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you do a debug on the inside interface of the pix and then try to access a webpage by URL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# debug packet inside src &lt;CLIENT ip="" address=""&gt; &lt;/CLIENT&gt;&lt;/P&gt;&lt;P&gt;pix# debug packet inside dst &lt;CLIENT ip="" address=""&gt;&lt;/CLIENT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pix# no debug all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will turn off your debugging. You may need to enter it a couple of times - do a "sh debug" and if there are still entries enter it again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you initiate the connection you should see a DNS request go to the DNS server and the DNS response coming back to the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 19:54:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124126#M893928</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T19:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124127#M893929</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the debug&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 20:27:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124127#M893929</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2008-11-06T20:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124128#M893930</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is the IP address of the DNS server the client is using ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 20:30:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124128#M893930</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T20:30:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124129#M893931</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gabrielle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assuming the DNS server is 216.130.224.4 then this debug shows the client sending out a request on destination port 53 to the DNS server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However your debug shows no traffic coming back at all - did you run both debugs ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug packet inside src 10.100.0.199&lt;/P&gt;&lt;P&gt;debug packet inside dst 10.100.0.199&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need the second debug to capture the return traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2008 21:29:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124129#M893931</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-06T21:29:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124130#M893932</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks I did the debug private to public - here you go for the proper debug. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gabrielle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Nov 2008 14:04:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124130#M893932</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2008-11-07T14:04:54Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124131#M893934</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gabrielle &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What this shows is the client 10.100.0.199 sending out DNS requests to 2 different DNS servers 216.130.224.4 &amp;amp; 216.130.224.5 but nothing coming back. So if you had in your debug &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug packet inside src 10.100.0.99&lt;/P&gt;&lt;P&gt;debug packet inside dst 10.100.0.99&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and you only captured what you have posted then all we can say so far is that the DNS request is arriving at the Pix inside interface from the client. So we need more debugging i'm afraid&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) debug packet outside dst 216.130.224.4 &lt;/P&gt;&lt;P&gt;debug packet outside dst 216.130.224.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you leave the previous debugging on then you should see the packet arrive on the inside interface and then go out of the external inerface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you don't see it go out the external interface then something is happening internal to the pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm assuming that you can run this debug when only one client is trying to access a web page ie. 10.100.0.99 otherwise you will get a lot of output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) If you do see packets leaving the outside interface then remove  the debugging on the outside interface and replace it with &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug packet outside src 216.130.224.4&lt;/P&gt;&lt;P&gt;debug packet outside src 216.130.224.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then try the client again and you should see responses coming back to the outside interface from the DNS servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It sounds like a lot of work but it is very quick usually to do this sort of debugging. In the meantime i'll have another quick look at your config. Can you confirm that you still don't have any acl's applied to any interfaces ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Nov 2008 15:58:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124131#M893934</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-07T15:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124132#M893936</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon Thank you for all of your help.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Nov 2008 19:27:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124132#M893936</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2008-11-07T19:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124133#M893938</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gabrielle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just had a second look at your config. Is there any reason you have the fixup for DNS disabled ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no fixup protocol dns &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is no reason could you try enabling it and retesting ie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Nov 2008 22:51:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124133#M893938</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2008-11-07T22:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can Ping can' Resolve DNS Pix</title>
      <link>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124134#M893940</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Added the Fix up and still the same thing.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Nov 2008 14:07:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-ping-can-resolve-dns-pix/m-p/1124134#M893940</guid>
      <dc:creator>cozyk1515</dc:creator>
      <dc:date>2008-11-12T14:07:24Z</dc:date>
    </item>
  </channel>
</rss>

