03-01-2013 06:27 AM - edited 03-11-2019 06:08 PM
Hi All,
Can someone tell me why you cannot set up a NAT rule on the ASAs with the destination address being a FQDN?
I want to allow some internal addresses to bypass our proxy to go to an external address and thought this would be the best way to do it, but the FQDN opetion isn't there.
Many thanks
Alex
03-01-2013 07:00 AM
Hi,
Do you have some device in front of the ASA controlling which traffic goes through proxy or how is the NAT going to be used?
Dont seem you can use a "object network" with "fqdn" in NAT configurations as you say though I have never even tried before.
- Jouni
03-01-2013 08:37 AM
Hi Jouni,
Many thanks for your quick reply.
We use a BlueCoat proxy device for all our web traffic and this is what I want to bypass which I can do if I put in an ACL and corresponding NAT rule allowing me to do so, but only for a host, a range of addresses of a network, but not FQDN.
I was curious as to why the FQDN option isn't there.
We have nothing in front of the ASA controlling which traffic goes through the proxy.
Thanks
Alex
03-01-2013 09:00 AM
Hi,
Are we talking about a configuration where the ASA has a "wccp" configuration that determines which traffic is handled with the Bluecoat?
Wouldnt it then be possible to evade the host and its certain destination from proxy by configuring a "deny ip" statement in the "wccp" ACL used?
I might have misunderstood the situation and I dont deal with that much with proxy setup while we do have a few ASA + Irontport setups where ASA uses "wccp"
- Jouni
03-01-2013 09:09 AM
Hi,
I don't believe we use wccp, however, I'm new to ASAs, so I'm not 100% sure.
I think we're getting beyond the realms of my original question of why you can't use a FQDN when NATting.
Thanks for your responses.
Alex
03-01-2013 01:15 PM
Even though you can configure FQDNs inside the objects you can't use them in a nat configuration, the ASA won't let you do it, he will even tell you that it's not supported.
You can try it and confirm it. Nothing will happen.
07-20-2017 06:37 AM
Can you confirm if this is still the case for NAT to DST FQDN? or are there any versions of software that can do this?
or Did you find a workaround?
thanks in advance
10-04-2018 04:59 PM
ASA still does not support to NAT based on FQDN, the closest would be to configure the NAT rule and route the traffic with PBR, however, you need to keep the list of public IPs that the domain resolves to.
12-18-2018 06:19 AM
Hello,
Please confirm if the feature of NAT to dynamic IPs or NAT to FQDN is supported in Cisco Firepower Firewalls. If not, then please suggest workaround for the same.
02-08-2023 03:15 AM
It seems is now possible if you upgrade to 9.17+, as per
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide