cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
852
Views
10
Helpful
3
Replies

deny internet access on our domain controller

VOLUS
Level 1
Level 1

i have installed firepower on my ASA 5516 as SFR module, 

i am using ASDM to manage rules ,

any idea how to block internet access on my domain controller, and please note that this domain controller is the DNS server. 

I tried deny any any on DCs IP addresses than I allowed port 53 and didn't work .

1 Accepted Solution

Accepted Solutions

Check below guide of configuration.

https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/getting_started_with_access_control_policies.html

make sure you are sending all traffic via FP module using ASA service policy

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

View solution in original post

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

Is this FW also facing Internet and you do NAT ?

on your DC DNS Server, what DNS server external configured ?

so your rule should allow

 

Source : your local DNS

Destination : 8.8.8.8 4.4.4.4

service 53 allow.

example :

https://www.cisco.com/c/en/us/td/docs/security/asa/asa914/configuration/firewall/asa-914-firewall-config/access-umbrella.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

hello, 

can you please share the config from firepower and not ASA as i redirected all traffic to firepower 

Check below guide of configuration.

https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/getting_started_with_access_control_policies.html

make sure you are sending all traffic via FP module using ASA service policy

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB