07-12-2022 03:11 AM
i have installed firepower on my ASA 5516 as SFR module,
i am using ASDM to manage rules ,
any idea how to block internet access on my domain controller, and please note that this domain controller is the DNS server.
I tried deny any any on DCs IP addresses than I allowed port 53 and didn't work .
Solved! Go to Solution.
07-12-2022 04:09 AM
Check below guide of configuration.
make sure you are sending all traffic via FP module using ASA service policy
07-12-2022 03:23 AM
Is this FW also facing Internet and you do NAT ?
on your DC DNS Server, what DNS server external configured ?
so your rule should allow
Source : your local DNS
Destination : 8.8.8.8 4.4.4.4
service 53 allow.
example :
07-12-2022 03:29 AM
hello,
can you please share the config from firepower and not ASA as i redirected all traffic to firepower
07-12-2022 04:09 AM
Check below guide of configuration.
make sure you are sending all traffic via FP module using ASA service policy
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide