<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Visiting website on DMZ from inside using public dns in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857736#M973459</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You actually have 2 options. You can do dns doctoring or destination nat. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination Nat&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.something.com" target="_blank"&gt;www.something.com&lt;/A&gt; = 1.1.1.1&lt;/P&gt;&lt;P&gt;private dmz address = 10.1.1.1&lt;/P&gt;&lt;P&gt;static (dmz,inside) 1.1.1.1 10.1.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS Doctoring&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 18 Oct 2007 12:34:36 GMT</pubDate>
    <dc:creator>acomiskey</dc:creator>
    <dc:date>2007-10-18T12:34:36Z</dc:date>
    <item>
      <title>Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857734#M973455</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there are tons of threads like this, but all of them concerns going from inside to inside.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, our problem is that we want to be able visit &lt;A class="jive-link-custom" href="http://www.something.com" target="_blank"&gt;www.something.com&lt;/A&gt; from computers on the inside interface. &lt;A class="jive-link-custom" href="http://www.something.com" target="_blank"&gt;www.something.com&lt;/A&gt; translates to a public ip on the ASA which translates to a dmz ip address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that the only way out of this is by using a static NAT command, I just can't figure out the syntax, or where to place it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully someone out there can help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Rasmus&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 11:27:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857734#M973455</guid>
      <dc:creator>blueoceanventure</dc:creator>
      <dc:date>2019-03-11T11:27:14Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857735#M973457</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This should help. It worked for me with servers in the DMZ.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://blogs.interfacett.com/mike-storm/2006/6/29/bidirectional-nat-on-a-cisco-pix-or-asa.html" target="_blank"&gt;http://blogs.interfacett.com/mike-storm/2006/6/29/bidirectional-nat-on-a-cisco-pix-or-asa.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH and please rate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2007 12:29:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857735#M973457</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-10-18T12:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857736#M973459</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You actually have 2 options. You can do dns doctoring or destination nat. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Destination Nat&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.something.com" target="_blank"&gt;www.something.com&lt;/A&gt; = 1.1.1.1&lt;/P&gt;&lt;P&gt;private dmz address = 10.1.1.1&lt;/P&gt;&lt;P&gt;static (dmz,inside) 1.1.1.1 10.1.1.1 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DNS Doctoring&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a00807968c8.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2007 12:34:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857736#M973459</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-10-18T12:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857737#M973460</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can't do DNS doctoring, 'cause we have internal DNS servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'l go for destination NAT. Thanks a bunch!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Rasmus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2007 13:13:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857737#M973460</guid>
      <dc:creator>blueoceanventure</dc:creator>
      <dc:date>2007-10-18T13:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857738#M973461</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now, I've setup destination NAT like your example. The funny thing is that it only works for some of our dmz sites.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should I add the "DNS rewite" features on these destination NAT rules?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it matter which dns servers the dmz servers uses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Rasmus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2007 08:30:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857738#M973461</guid>
      <dc:creator>blueoceanventure</dc:creator>
      <dc:date>2007-10-24T08:30:36Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857739#M973463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should work for any server in the dmz. Do you want to post a clean config? Also, which destination nat statements are not working?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Oct 2007 12:31:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857739#M973463</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-10-24T12:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857740#M973465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;THe firewall has not been put live yet. I've only connected it a couple of nights, to check status on variuos issues. This makes it difficult to test new configurations quickly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, I discovered that the web servers that had this problem, all used external DNS servers. I've corrected this, so that they use the internal dns servers (like the rest of the web servers that actually work).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I haven't had time to test this yet, but would it make sense, that this might be the issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Rasmus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2007 07:54:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857740#M973465</guid>
      <dc:creator>blueoceanventure</dc:creator>
      <dc:date>2007-10-25T07:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857741#M973467</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not really. Just to recap, you are using destination nat to use the public ip addresses of the webservers from the inside right? If this is the case, the dns servers defined on the webservers should having nothing to do with it. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Oct 2007 12:24:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857741#M973467</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2007-10-25T12:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857742#M973468</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think I've solved it. The servers had multiple IP addresses, and Anti-Spoofing was enabled on the DMZ interface. I'll test this later.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the meantime, I've discovered that now that I've made this destination-NAT-thing, I cannot connect with RemoteDesktop (or any other protocol) to the private dmz addresses. How do I do that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to be able to browse the public dmz websites, but at the same time be able to rdp to the private address. Is this even possible? If so, how?&lt;/P&gt;&lt;P&gt;If not, what do everybody else do? I can't be the only one with this need...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rasmus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2007 14:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857742#M973468</guid>
      <dc:creator>blueoceanventure</dc:creator>
      <dc:date>2007-10-30T14:42:09Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857743#M973470</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can still do destination NAT, just for a specific port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Stealing Adams example &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;www.something.com = 1.1.1.1&lt;/P&gt;&lt;P&gt;private dmz address = 10.1.1.1&lt;/P&gt;&lt;P&gt;static (dmz,inside) tcp 1.1.1.1 80 10.1.1.1 80 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With that port you can browse to 1.1.1.1:80 and RDP to 10.1.1.1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2007 14:47:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857743#M973470</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2007-10-30T14:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: Visiting website on DMZ from inside using public dns</title>
      <link>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857744#M973471</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You are my hero &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a bunch!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rasmus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Oct 2007 15:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/visiting-website-on-dmz-from-inside-using-public-dns/m-p/857744#M973471</guid>
      <dc:creator>blueoceanventure</dc:creator>
      <dc:date>2007-10-30T15:04:49Z</dc:date>
    </item>
  </channel>
</rss>

