cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
586
Views
0
Helpful
5
Replies

ASA 5510 Internet Access problem

Muhammadhabib1
Level 1
Level 1

dears 

i'm new in ASA configuration, my scenario is i want to access to internet through ASA 5510 Firewall now i can browse Google site by ip address in URL i'm put the Google IP address and i get the page, but when i put the Google link in browser i cannot get the page, can any one advice me 

thanks 

 

 

5 Replies 5

Jouni Forss
VIP Alumni
VIP Alumni

Hi,

 

The most obvious reason would be problem with DNS in some way.

 

  • Have you checked the DNS configurations on the host? Are they using valid IP addresses?
  • Have you checked that nothing is blocking DNS querys from the host to the DNS server?
  • If using internal DNS server is its configurations correct and is its querys to external servers working?
  • Are you using DNS servers that you are allowed to use? What I mean by this are you using the DNS servers of your ISP or perhaps Googles DNS servers? In some cases I have seen migrated networks using old operator DNS which results in the old ISP blocking those DNS queries.

 

In Windows you can go to the Start Menu and there choose Run and insert nslookup to the field and then write www.google.com in command prompt that opened. See what server the host is using and if it gives a reply.

 

- Jouni

thanks Jouni for replay 

for DNS configurations i didn't configure the dns, frankly I do not know how to configure the dns, can you please help me in this, also in nslookup when i put the Google link it cannot resolve the ip address of Google site

thanks

 

Hi,


Just to clarify, do you have DNS configured on the network interface card of the PC or are you perhaps using DHCP on the PC and is it getting a DNS server through it?

 

These naturally have to be in order for you to be able to use DNS to resolve the actual IP address of sites etc.

 

The ASA does not require any DNS related configurations for the clients other than that you have to make sure you have allowed DNS traffic from the clients to the DNS servers they are using.

 

- Jouni

Hi,

No, i dont have any DNS configured on the network,the firewall connect directly to the internet and the pc that connected to the firewall also directly by static IP in Inside and outside interface

thanks 

 

Hi,

 

Well you should naturally go to the network interface card configurations and add the required DNS servers. You should be able to do it in the same place where you configured the IP address and mask for your computer.

 

If you dont want to configure each host staticly you could always configure DHCP server on the ASA.

 

- Jouni

Review Cisco Networking for a $25 gift card