cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2393
Views
10
Helpful
4
Replies

ASA multiple dns server groups not work

Sergey Prishchepa
Spotlight
Spotlight

Hello!

I make multiple dns server groups for ASA5525 asa991-smp-k8.bin like this:

 

 

dns domain-lookup outside
dns domain-lookup inside
!
dns server-group DefaultDNS
name-server 192.168.1.1
name-server 192.168.1.2
domain-name dns1.com
!
dns server-group DNS2
name-server 192.168.2.1
name-server 192.168.2.2
domain-name dns2.com

Dns server-group DefaultDNS work fine, but dns server-group DNS2 does not work.

sh dns host host2.dns2.com
Name: host2.dns2.com (unresolved)

host2.dns2.com exists and nslookup is working from the network inside.


What is the problem?

 

1 Accepted Solution

Accepted Solutions

I assume you have the wrong expectation on what the server-groups do. For each given function, only one server-group is used. The ASA uses the DefaultDNS group. The aim of having a second or more of these groups is to have different functions use different servers.

Example:

The ASA itself used DefaultDNS. But you host a clientless VPN-portal for two different customers. For each customer, you can configure one DNS-group so that they can access their internal resources.

View solution in original post

4 Replies 4

I assume you have the wrong expectation on what the server-groups do. For each given function, only one server-group is used. The ASA uses the DefaultDNS group. The aim of having a second or more of these groups is to have different functions use different servers.

Example:

The ASA itself used DefaultDNS. But you host a clientless VPN-portal for two different customers. For each customer, you can configure one DNS-group so that they can access their internal resources.

OK. If I add all servers for different domains in Default DNS, will it work?

No, you have to solve this problem on the DNS-server. That server needs to resolve dns2.com or forward the request to the right name server.

Thanks a lot!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card