04-22-2025 12:08 AM
hi,
I need to NAT one subnet to another from inside to outside, but also to NAT DNS replies for some of the hosts in original subnet. Set of host that needs to be dns_replies_nated is dynamic. Is this possible?
br
04-22-2025 02:50 AM - edited 04-22-2025 02:53 AM
DNS doctoring is enabled per NAT rule using the dns keyword, e.g
object network MY_HOST
host 192.168.1.5
nat (inside,outside) static 10.10.10.5 dns
https://www.petenetlive.com/KB/Article/0001113
04-22-2025 03:16 AM
Doctor NAT not work for dynamic it work only for static.
MHM
04-23-2025 04:24 AM
but is it possible for whole subnet?
04-23-2025 04:52 AM
To answer you
When we use DNS ?
If I have server inside and clients outside try to access it and these clients use DNS server which is also inside then we use dns doctor' the FW will NAT reply of DNS from private to public which accpet by outside clients.
So we use DNS doctor for server which use single IP by using static NAT.
MHM
04-23-2025 04:56 AM
I know, but I need to translate subnet_inside to subnet_outside ... clients use dns to resolve destinations from subnet_ouside. I need to NAT those servers to subnet_inside. List of servers is not fixed so I hoped asa can DNS doctor all resources from subnet_outside that are seen in dns replies
04-23-2025 07:25 AM
I dont try before' but if it work then ASA cli will accpet add DNS to end of NAT' if not accept it will show you error message.
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide