10-30-2023 09:41 PM
Hello all,
None of the zones are able to resolve DNS. I can ping 8.8.8.8 from LAN and DMZ but cannot ping google.com.
The DNS policy under policies > DNS is default
DNS server group under Objects > Object Management has all the ISP provided DNS servers
DNS under Devices > Platform settings has "Enable DNS name resolution by device" enabled and the server group added to it. "Interface Objects" has all the objects added to the list.
I can ping google.com from Devices > Threat Defense CLI
How can I ensure that the the DNS works from devices in LAN and DMZ?
Thanks
Solved! Go to Solution.
11-04-2023 09:30 AM
from Nexus do traceroute check if the packet hit FTD or not ?
Thanks A Lot
MHM
11-06-2023 06:52 AM
The migration ignored a few NAT rules and that caused the issue. I did thorough check between the ASA and the FTD and found the missing NAT rules. Added them to the FTD and name resolution started working.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide