08-04-2012 03:51 AM - editado 03-11-2019 04:38 PM
Hi there,
Wo got an ASA5510 (8.2x) with an inside, guest and outside interface.
On the guest interface, we have DHCP function on the ASA.
On the outside, there is web-ssl vpn (dns hostname on a public isp-dns server) configured.
When an user on the guest net tries to get connected with the web-ssl dns-name, it resolves the public, outside interface-ip , the ASA dropps it.
I know, with static NAT it can be resolved (http://m.techrepublic.com/blog/networking/cisco-asa-and-dns-pain-is-there-a-doctor-in-the-house/1140), but on
this scenario, we are trying to build a connection from a guest inside IP to the public-ip form the outside ASA interface.
If the guest users try an web-ssl connection on the guest-ASA IP, it works with a certificate error ( because there is no internal DNS on the guest net to resolve the dns name to the guest-interface IP).
So how can this be achieved? Can the ASA provide DNS server function? Can a NAT static entry (outside ip to interface guest) solve it?
It's the only solution an inhouse DNS server in the guest-net?
Thanks,
Norbert
¡Resuelto! Ir a solución.
el 08-04-2012 09:42 AM
No, unfortunately you can't NAT the ASA interface IP Addresses, and also you can't connect cross interfaces, so if you are on the Guest network, you can't connect to the Outside interface.
ASA also does not provide DNS functionality as it is not a DNS server.
For guest users, they can only connect to othe Guest-ASA IP, and you would need to add the certificate to the CA Root certificate store on the PC and you won't get the error after adding those.
el 08-04-2012 09:42 AM
No, unfortunately you can't NAT the ASA interface IP Addresses, and also you can't connect cross interfaces, so if you are on the Guest network, you can't connect to the Outside interface.
ASA also does not provide DNS functionality as it is not a DNS server.
For guest users, they can only connect to othe Guest-ASA IP, and you would need to add the certificate to the CA Root certificate store on the PC and you won't get the error after adding those.
el 08-14-2012 05:00 AM
Had to put a DNS (IOS Router) in the guest NAT.
For Cisco.
Such a service (DNS Server) should be supported on the ASA......
Greets,
Norbert
Descubra y salve sus notas favoritas. Vuelva a encontrar las respuestas de los expertos, guías paso a paso, temas recientes y mucho más.
¿Es nuevo por aquí? Empiece con estos tips. Cómo usar la comunidad Guía para nuevos miembros