cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2025
Views
0
Helpful
17
Replies

DMZ web server; traffic gets in, can't get out.

shortnathan
Level 1
Level 1

Hi,

I have a webserver in the dmz which is accessible from the outside. However, I am unable to access interenet from the web server. Help!

17 Replies 17

See attached.

ASA allows the traffic, nothing is wrong.

Actually I doubt that 12.xx.xx.71 is a valid DNS server

12.xx.xx.90 is your interface IP and 12.xx.xx.71 is an IP that is in your range with 255.255.255.224 mask

I recommend you using another public DNS. For example

67.138.54.100

In TCP/IP properties of your server, set 67.138.54.100 as preferred DNS server. And in ASA, do the following modification

object-group network ISP_DNS

network-object host 67.138.54.100

Regards

It's confusing because of the scrubbed config, the second and third octets of the DNS server are different from those of my /27. The DNS server has been verified working, our domain controllers are all using it from the inside interface.

Review Cisco Networking for a $25 gift card