08-04-2012 03:51 AM - edited 03-11-2019 04:38 PM
Hi there,
Wo got an ASA5510 (8.2x) with an inside, guest and outside interface.
On the guest interface, we have DHCP function on the ASA.
On the outside, there is web-ssl vpn (dns hostname on a public isp-dns server) configured.
When an user on the guest net tries to get connected with the web-ssl dns-name, it resolves the public, outside interface-ip , the ASA dropps it.
I know, with static NAT it can be resolved (http://m.techrepublic.com/blog/networking/cisco-asa-and-dns-pain-is-there-a-doctor-in-the-house/1140), but on
this scenario, we are trying to build a connection from a guest inside IP to the public-ip form the outside ASA interface.
If the guest users try an web-ssl connection on the guest-ASA IP, it works with a certificate error ( because there is no internal DNS on the guest net to resolve the dns name to the guest-interface IP).
So how can this be achieved? Can the ASA provide DNS server function? Can a NAT static entry (outside ip to interface guest) solve it?
It's the only solution an inhouse DNS server in the guest-net?
Thanks,
Norbert
Solved! Go to Solution.
08-04-2012 09:42 AM
No, unfortunately you can't NAT the ASA interface IP Addresses, and also you can't connect cross interfaces, so if you are on the Guest network, you can't connect to the Outside interface.
ASA also does not provide DNS functionality as it is not a DNS server.
For guest users, they can only connect to othe Guest-ASA IP, and you would need to add the certificate to the CA Root certificate store on the PC and you won't get the error after adding those.
08-04-2012 09:42 AM
No, unfortunately you can't NAT the ASA interface IP Addresses, and also you can't connect cross interfaces, so if you are on the Guest network, you can't connect to the Outside interface.
ASA also does not provide DNS functionality as it is not a DNS server.
For guest users, they can only connect to othe Guest-ASA IP, and you would need to add the certificate to the CA Root certificate store on the PC and you won't get the error after adding those.
08-14-2012 05:00 AM
Had to put a DNS (IOS Router) in the guest NAT.
For Cisco.
Such a service (DNS Server) should be supported on the ASA......
Greets,
Norbert
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide