
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-16-2018
07:57 AM
- last edited on
02-21-2020
11:35 PM
by
cc_security_adm
I know in ASA's, under the DHCP server settings for a particular interface, you can set the DNS servers that are handed out. Can this be done in FTD? Reason I ask is my client current has two guest wireless networks. One that just uses the WLC web-auth and the other will use ISE. The current prod guest wireless uses public DNS servers for resolution. However, for the other guest wireless using ISE, I need it to use internal DNS servers so it can resolve the internal DNS servers for the redirect. However, in the FTD DHCP server settings there isn't a way to do set DNS servers for the DHCP server settings assigned to a particular interface. I checked an ASA config and the command is:
dhcpd dns 1.1.1.1 1.1.1.2 interface int_name
I tried do use the above command in FlexConfig, but I got an error when I deployed the policy. Any ideas?
TIA,
Dan
Solved! Go to Solution.
- Labels:
-
NGFW Firewalls
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-16-2018 08:29 PM
Sorry i misunderstood your question.
What you're trying to do isn't possible on FTD.
There's also a bug id (feature enhancement request for that) :
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg68863/?referring_site=bugquickviewclick
Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-16-2018 06:50 PM
Are you using FDM or FMC?
Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-16-2018 07:22 PM
FMC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-16-2018 07:36 PM
Take a look on that documentation:
Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-16-2018 08:00 PM
Francesco,
Thank you for the response. However, I have seen that config guide, but it does not solve my issue. The client has two DHCP scopes. The one uses the public DNS servers listed in the Override Auto Configured Settings. What I need is for the second scope to use their internal DNS servers to resolve ISE on from the DMZ to the internal network. On the ASA's, you can assign each interface that has DHCP running on it specific DNS servers. I need to find a way to do the same in FMC for FTD. Flexconfig does not work for this setting.
Dan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-16-2018 08:29 PM
Sorry i misunderstood your question.
What you're trying to do isn't possible on FTD.
There's also a bug id (feature enhancement request for that) :
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg68863/?referring_site=bugquickviewclick
Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-17-2018 06:38 AM
Francesco,
Thank you for the link to the bugID for the feature request. I will pass this onto my client.
Dan
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
01-17-2018 06:40 AM
Thanks
Francesco
PS: Please don't forget to rate and select as validated answer if this answered your question
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-09-2020 04:14 PM
Too bad that FDM isn't included in the Feature Request. I'm no longer using FMC and never wish to go back to it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-02-2020 05:42 AM
Is there a way to escalate this with Cisco engineering? It's truly a break/fix, not a new feature.
