cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1290
Views
0
Helpful
2
Replies

ASA DNS for inside clients? (ssl vpn from inside to ouside ip)

alig.norbert
Level 4
Level 4

Hi there,

Wo got an ASA5510 (8.2x) with an inside, guest and outside interface.

On the guest interface, we have DHCP function on the ASA.

On the outside, there is web-ssl vpn (dns hostname on a public isp-dns server) configured.

When an user on the guest net tries to get connected with the web-ssl dns-name, it resolves the public, outside interface-ip , the ASA dropps it.

I know, with static NAT it can be resolved (http://m.techrepublic.com/blog/networking/cisco-asa-and-dns-pain-is-there-a-doctor-in-the-house/1140), but on

this scenario, we are trying to build a connection from a guest inside IP to the public-ip form the outside ASA interface.

If the guest users try an web-ssl connection on the guest-ASA IP, it works with a certificate error ( because there is no internal DNS on the guest net to resolve the dns name to the guest-interface IP).

So how can this be achieved? Can the ASA provide DNS server function? Can a NAT static entry (outside ip to interface guest) solve it?

It's the only solution an inhouse DNS server in the guest-net?

Thanks,

Norbert

1 Accepted Solution

Accepted Solutions

Jennifer Halim
Cisco Employee
Cisco Employee

No, unfortunately you can't NAT the ASA interface IP Addresses, and also you can't connect cross interfaces, so if you are on the Guest network, you can't connect to the Outside interface.

ASA also does not provide DNS functionality as it is not a DNS server.

For guest users, they can only connect to othe Guest-ASA IP, and you would need to add the certificate to the CA Root certificate store on the PC and you won't get the error after adding those.

View solution in original post

2 Replies 2

Jennifer Halim
Cisco Employee
Cisco Employee

No, unfortunately you can't NAT the ASA interface IP Addresses, and also you can't connect cross interfaces, so if you are on the Guest network, you can't connect to the Outside interface.

ASA also does not provide DNS functionality as it is not a DNS server.

For guest users, they can only connect to othe Guest-ASA IP, and you would need to add the certificate to the CA Root certificate store on the PC and you won't get the error after adding those.

Had to put a DNS (IOS Router) in the guest NAT.

For Cisco.

Such a service (DNS Server) should be supported on the ASA......

Greets,

Norbert

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: