cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
223
Views
0
Helpful
6
Replies

cisco asa network nat dns replies

hi,

I need to NAT one subnet to another from inside to outside, but also to NAT DNS replies for some of the hosts in original subnet. Set of host that needs to be dns_replies_nated is dynamic. Is this possible?

 

br

6 Replies 6

Sheraz.Salim
VIP Alumni
VIP Alumni

Doctor NAT not work for dynamic it work only for static.

MHM

but is it possible for whole subnet?

To answer you 

When we use DNS ?

If I have server inside and clients outside try to access it and these clients use DNS server which is also inside then we use dns doctor' the FW will NAT reply of DNS from private to public which accpet by outside clients.

So we use DNS doctor for server which use single IP by using static NAT.

MHM

I know, but I need to translate subnet_inside to subnet_outside ... clients use dns to resolve destinations from subnet_ouside. I need to NAT those servers to subnet_inside. List of servers is not fixed so I hoped asa can DNS doctor all resources from subnet_outside that are seen in dns replies

I dont try before' but if it work then ASA cli will accpet add DNS to end of NAT' if not accept it will show you error message.

MHM

Review Cisco Networking for a $25 gift card