cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
283
Views
0
Helpful
2
Replies

ASA 5505 DNS Query

Hi

I have ASA 5505 with software 9.2.4. I have one computer and its IP address is 192.168.1.200 and I have an internal domain controller with address 192.168.0.25.

I wanted that this pc can do name resolution using this internal controller.

So i have created access list that states source is 192.168.1.200 destination is 192.168.0.25 and service is tcp/udp domain. this PC is in DMZ zone and domain controller is inside interface.

so i created access list to allow that trafic. But it didnt work

But after i have replaced tcp/udp-domain service with ip then it started working.

But I know this is not right way to do it since now all ports are open which I dont want

Is there any way to configure DNS access from DMZ to inside to do DNS name resolution

I would use ASDM

1 Accepted Solution

Accepted Solutions

Hi,

Could you please show how are the acls built?

View solution in original post

2 Replies 2

Hi,

Could you please show how are the acls built?

Hi

I am all good now. Out of the box ASA 5505 has everything configured for internet access and access to lower security interface. But once I configured first access list then everything stopped working

Once I created proper access lists everything is in business now DNS file share internet etc

Review Cisco Networking for a $25 gift card