07-29-2016 05:54 AM - edited 03-12-2019 01:04 AM
Hi
I have ASA 5505 with software 9.2.4. I have one computer and its IP address is 192.168.1.200 and I have an internal domain controller with address 192.168.0.25.
I wanted that this pc can do name resolution using this internal controller.
So i have created access list that states source is 192.168.1.200 destination is 192.168.0.25 and service is tcp/udp domain. this PC is in DMZ zone and domain controller is inside interface.
so i created access list to allow that trafic. But it didnt work
But after i have replaced tcp/udp-domain service with ip then it started working.
But I know this is not right way to do it since now all ports are open which I dont want
Is there any way to configure DNS access from DMZ to inside to do DNS name resolution
I would use ASDM
Solved! Go to Solution.
08-02-2016 12:42 PM
08-02-2016 12:42 PM
Hi,
Could you please show how are the acls built?
08-03-2016 07:50 AM
Hi
I am all good now. Out of the box ASA 5505 has everything configured for internet access and access to lower security interface. But once I configured first access list then everything stopped working
Once I created proper access lists everything is in business now DNS file share internet etc
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide