cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
803
Views
0
Helpful
8
Replies

dns on pix

rpalacio
Level 1
Level 1

dns_inside----pix-----user

dns is at the inside subnet

user is on the dmz

domain controller on the inside subnet

observations;

1. with nat (inside) 0 0 , the user could logon to the domain, but couldnt brouse any machine on the inside.

2. with nat (inside) 1 0 0 , user couldnt logon to the domain controller. static command is invoke with the ff detail

static (inside, dmz) 10.2.2.10 10.1.1.10

10.1.1.10 is the dns

10.2.2.10 is the outside mapped ip

ping from user to 10.2.2.10 is ok.

10.2.2.10 is configured as dns on windows user.

why cant i have dns service if am using nat?

Without nat, why cant i browse the inside network? i could find a computer on the inside using the computer name, thus dns is doing his job. I just cant browse.

anyone here could help me pls..

thanks a lot.

8 Replies 8

nkhawaja
Cisco Employee
Cisco Employee

hi,

the rule of translation requies you to have static translation if you want connection from dmz to inside.

so you have to use static translation or nat 0 with access-list

thanks

Nadeem

ive done that, thats why i was able to login to the domain controller inside from a user on the DMZ.

so what is your question/issue?

the issue is i cant browse the inside network from the dmz...

inside is where servers are.

dmz is where users are.

nkhawaja
Cisco Employee
Cisco Employee

browsing the servers means? you cant connect via http or via windows network share etc.

in either case, you need to have an Access-list applied on the dmz interface to allow the desired traffic to reach the inside from dmz

i cant see any macine on the inside from the network neighborhood. But if i do a search on the machine thru their computer names, it works.

nkhawaja
Cisco Employee
Cisco Employee

may be it requires WINS setting. or the necessary ports to be opened.

hello,

It was able to browse the network even by just having a DNS. Server IPs must not be translated between inside and dmz though i still have to invoke the static command.

I dont know but its just taking a lot of time to for the pix to discover the network.

Review Cisco Networking for a $25 gift card