<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5510 Loopback configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423286#M923630</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use the dns doctoring feature on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the static translation command for the mail server, just add the "dns" keyword at the end of the statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When internal user requests for dns resolution for the mail server from the external dns server, and the traffic goes through the ASA firewall, once the dns reply return back through the ASA, the ASA will modify the resolution from external ip address to its corresponding private ip address if the "dns" keyword is configured at the end of the mail server static translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 31 Mar 2010 00:59:44 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-03-31T00:59:44Z</dc:date>
    <item>
      <title>ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423284#M923627</link>
      <description>&lt;P&gt;Not sure if loopback is right term but here's the scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Small Business with a 5510. External &lt;A class="kLink" href="http://www.velocityreviews.com/forums/t541624-asa-5510-loopback-configuration.html#" id="KonaLink0" style="text-decoration: underline ! important; position: static;" target="undefined"&gt;&lt;SPAN style="position: static; color: blue;"&gt;&lt;SPAN class="kLink" style="position: relative; border-bottom: 1px solid blue; background-color: transparent; color: blue;"&gt;domain &lt;/SPAN&gt;&lt;SPAN class="kLink" style="position: relative; border-bottom: 1px solid blue; background-color: transparent; color: blue;"&gt;name&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="preLoadWrap" id="preLoadWrap0" style="position: relative;"&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;DIV id="preLoadLayer0" style="position: absolute; z-index: 4000; top: -32px; left: -18px; display: none;"&gt;&lt;IMG class="preloadImg" src="http://kona.kontera.com/javascript/lib/imgs/grey_loader.gif" style="border: medium none; width: 22px; height: 22px;" /&gt;&lt;/DIV&gt; is domain.com, internal AD domain is domain.local. Mail is hosted internally with webmail having an external &lt;A class="kLink" href="http://www.velocityreviews.com/forums/t541624-asa-5510-loopback-configuration.html#" id="KonaLink1" style="text-decoration: underline ! important; position: static;" target="undefined"&gt;&lt;SPAN style="position: static; color: blue;"&gt;&lt;SPAN class="kLink" style="position: relative; color: blue;"&gt;DNS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; (public name) of mail.domain.com&lt;BR /&gt; &lt;BR /&gt; When users on the outside hit mail.domain.com, it's statically set to an internal &lt;A class="kLink" href="http://www.velocityreviews.com/forums/t541624-asa-5510-loopback-configuration.html#" id="KonaLink2" style="text-decoration: underline ! important; position: static;" target="undefined"&gt;&lt;SPAN style="position: static; color: blue;"&gt;&lt;SPAN class="kLink" style="position: relative; color: blue;"&gt;mail &lt;/SPAN&gt;&lt;SPAN class="kLink" style="position: relative; color: blue;"&gt;server&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; and everything&amp;nbsp; works fine. When users are on the internal LAN or wireless, and they&amp;nbsp; put in mail.domain.com it times out instead of going out to grab the&amp;nbsp; external IP of the public &lt;A class="kLink" href="http://www.velocityreviews.com/forums/t541624-asa-5510-loopback-configuration.html#" id="KonaLink3" style="text-decoration: underline ! important; position: static;" target="undefined"&gt;&lt;SPAN style="position: static; color: blue;"&gt;&lt;SPAN class="kLink" style="position: relative; color: blue;"&gt;DNS &lt;/SPAN&gt;&lt;SPAN class="kLink" style="position: relative; color: blue;"&gt;record&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt; and come back&amp;nbsp; in. Internally they can acces the mail server using the private IP or NetBios name of the email server.&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have searched online and found articles suggesting a split dns. Setting an entry for mail.domain.com to point to private address on our internal DNS server. I tried this but we also have a website &lt;A href="https://community.cisco.com/www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt; that is hosted outside our network on our ISP's servers. With that DNS entry in place our in house staff can not access our company's website.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can I configure the ASA so that the traffic flow back correctly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our setup includes:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Windows 2003 Standard SP2 DNS server&lt;/P&gt;&lt;P&gt;Windows 2008 Enterprise SP2 Exchange 2007&lt;/P&gt;&lt;P&gt;CISCO ASA 5510&lt;/P&gt;&lt;P&gt;CISCO 870 ROUTER&lt;/P&gt;&lt;P&gt;CISCO CATALYST 2960&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess I should also mention that everything worked fine with just a simple home brand router (no asa and just an unmanaged switch). But obviously that equipment wasn't practical for our setup.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 11:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423284#M923627</guid>
      <dc:creator>derrick</dc:creator>
      <dc:date>2020-02-21T11:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423285#M923628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check this document, it should help you out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://blogs.interfacett.com/mike-storm/2006/6/29/bidirectional-nat-on-a-cisco-pix-or-asa.html"&gt;http://blogs.interfacett.com/mike-storm/2006/6/29/bidirectional-nat-on-a-cisco-pix-or-asa.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Mar 2010 15:25:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423285#M923628</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2010-03-30T15:25:46Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423286#M923630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can use the dns doctoring feature on the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the static translation command for the mail server, just add the "dns" keyword at the end of the statement.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When internal user requests for dns resolution for the mail server from the external dns server, and the traffic goes through the ASA firewall, once the dns reply return back through the ASA, the ASA will modify the resolution from external ip address to its corresponding private ip address if the "dns" keyword is configured at the end of the mail server static translation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 31 Mar 2010 00:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423286#M923630</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-03-31T00:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423287#M923631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response. But could you eloborate on how to do this? I have very little experience with the ASA and I am not totally sure how to do what you instructed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Apr 2010 20:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423287#M923631</guid>
      <dc:creator>derrick</dc:creator>
      <dc:date>2010-04-02T20:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423288#M923632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure, assuming that the following is the static statement for your webmail server:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,outside) public-ip private-ip netmask 255.255.255.255&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can remove the above and add the "dns" keyword as follows:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;static (inside,outside) public-ip private-ip netmask 255.255.255.255 &lt;SPAN style="color: #ff0000;"&gt;dns&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Apr 2010 22:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423288#M923632</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-02T22:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423289#M923633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what I used:&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface https 192.168.1.11 https netmask 255.255.255.255 dns&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but I'm still not able to access &lt;A href="http://www.domain.com"&gt;www.domain.com&lt;/A&gt; behind the firewall&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Apr 2010 15:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423289#M923633</guid>
      <dc:creator>derrick</dc:creator>
      <dc:date>2010-04-03T15:11:36Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423290#M923634</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When the internal users try to access &lt;A href="https://community.cisco.com/www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;, does dns request go through the firewall? ie: are they using external dns server for dns resolution where the dns request and reply go through the firewall? If yes, then it should work.&lt;/P&gt;&lt;P&gt;If you are using internal dns server, or the dns request does not go through the firewall, then the "dns" keyword will not work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Apr 2010 22:13:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423290#M923634</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-03T22:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423291#M923635</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Derrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; font-size: 10pt;"&gt;On your internal DNS create a zone for your external DNS "domain.com" Then just add any entries that you would like internal users to access, with the appropriate IP addresses.&amp;nbsp; The only issue with this configuration is that if external records pointing to global IP addresses change you will have to manually make the change too.&amp;nbsp; i.e. www (if hosted externally and moves to new provider) This should not be a big deal! &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Host entries would work too, but that's lame!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="line-height: 115%; color: #333333; font-size: 10pt;"&gt;If you do not want to maintain a copy of your external DNS records on your internal DNS, I suggest you carefully read the &lt;A href="https://community.cisco.com/thread/2010979"&gt;blog entry from Collin Clark’s post.&lt;/A&gt; and setup Bidirectional NAT.&lt;BR /&gt;&lt;BR /&gt;You may also need to setup &lt;A href="http://ckdake.com/content/2009/hairpinning-with-a-cisco-asa.html"&gt;U-Turn (Hairpinning)&lt;/A&gt;&amp;nbsp; &lt;STRONG&gt;same-security-traffic permit intra-interface&lt;/STRONG&gt; depending on the placement of devices.&lt;BR /&gt;&lt;BR /&gt;A diagram of your topology would be helpful!&amp;nbsp; ASA config too!&amp;nbsp; Be careful to sanitize it first!&amp;nbsp; &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;I really like just adding the External zone to internal DNS, your setup sounds a lot like many of my customers.&amp;nbsp; Keeping the ASA configuration simple might be a good idea unless your up for the challenge!&amp;nbsp; Remember you have to maintain this not me, nor anyone else!&lt;/P&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 10pt;"&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 03 Apr 2010 23:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423291#M923635</guid>
      <dc:creator>mciszek</dc:creator>
      <dc:date>2010-04-03T23:07:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423292#M923636</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Workstations are setup to use the internal DNS server and also an external DNS server hosted by our ISP. The mail.domain.com and &lt;A href="https://community.cisco.com/www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt; are being resolved by the external DNS server. I have no entries on our DNS server that resolve those two urls.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2010 13:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423292#M923636</guid>
      <dc:creator>derrick</dc:creator>
      <dc:date>2010-04-06T13:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423293#M923637</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response. I've tried setting up a domin.com zone on our internal DNS server. I'm able to access mail.domain.com internaly but not &lt;A href="https://community.cisco.com/www.domain.com" target="_blank"&gt;www.domain.com&lt;/A&gt;. I have an a record pointing &lt;A href="http://www.domain.com"&gt;www.domain.com&lt;/A&gt; to the public ip of the site but is there anything else I need to do to get this working? The way I setup the zone was by creating a new zone under "Forward Lookup Zones" the type of zone I used was "Primary zone". I attached what you requested with my reply. The zip file is password protected I will send you a private message with that password. Thanks again -Derrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2010 14:54:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423293#M923637</guid>
      <dc:creator>derrick</dc:creator>
      <dc:date>2010-04-06T14:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423294#M923638</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess I didn't wait long enough after making those changes to the DNS server. I came back from lunch and it's working fine now. Thanks again for the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2010 17:33:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423294#M923638</guid>
      <dc:creator>derrick</dc:creator>
      <dc:date>2010-04-06T17:33:57Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5510 Loopback configuration</title>
      <link>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423295#M923639</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Derrick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You could have done an "&lt;STRONG&gt;ipconfig /flushdns&lt;/STRONG&gt;" on the workstations and ran the Mircosoft DNS management tool from a workstation or server, clicked on "View" then made sure the "Advanced" option was checked.&amp;nbsp; Under the Cached Entries find your domain and delete any entries that may be invalid.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad you made this work!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 06 Apr 2010 20:35:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5510-loopback-configuration/m-p/1423295#M923639</guid>
      <dc:creator>mciszek</dc:creator>
      <dc:date>2010-04-06T20:35:16Z</dc:date>
    </item>
  </channel>
</rss>

