01-16-2018
07:57 AM
- last edited on
02-21-2020
11:35 PM
by
cc_security_adm
I know in ASA's, under the DHCP server settings for a particular interface, you can set the DNS servers that are handed out. Can this be done in FTD? Reason I ask is my client current has two guest wireless networks. One that just uses the WLC web-auth and the other will use ISE. The current prod guest wireless uses public DNS servers for resolution. However, for the other guest wireless using ISE, I need it to use internal DNS servers so it can resolve the internal DNS servers for the redirect. However, in the FTD DHCP server settings there isn't a way to do set DNS servers for the DHCP server settings assigned to a particular interface. I checked an ASA config and the command is:
dhcpd dns 1.1.1.1 1.1.1.2 interface int_name
I tried do use the above command in FlexConfig, but I got an error when I deployed the policy. Any ideas?
TIA,
Dan
Solved! Go to Solution.
01-16-2018 08:29 PM
Sorry i misunderstood your question.
What you're trying to do isn't possible on FTD.
There's also a bug id (feature enhancement request for that) :
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg68863/?referring_site=bugquickviewclick
01-16-2018 06:50 PM
01-16-2018 07:22 PM
FMC
01-16-2018 07:36 PM
Take a look on that documentation:
01-16-2018 08:00 PM
Francesco,
Thank you for the response. However, I have seen that config guide, but it does not solve my issue. The client has two DHCP scopes. The one uses the public DNS servers listed in the Override Auto Configured Settings. What I need is for the second scope to use their internal DNS servers to resolve ISE on from the DMZ to the internal network. On the ASA's, you can assign each interface that has DHCP running on it specific DNS servers. I need to find a way to do the same in FMC for FTD. Flexconfig does not work for this setting.
Dan
01-16-2018 08:29 PM
Sorry i misunderstood your question.
What you're trying to do isn't possible on FTD.
There's also a bug id (feature enhancement request for that) :
https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvg68863/?referring_site=bugquickviewclick
01-17-2018 06:38 AM
Francesco,
Thank you for the link to the bugID for the feature request. I will pass this onto my client.
Dan
01-17-2018 06:40 AM
02-09-2020 04:14 PM
Too bad that FDM isn't included in the Feature Request. I'm no longer using FMC and never wish to go back to it.
03-02-2020 05:42 AM
Is there a way to escalate this with Cisco engineering? It's truly a break/fix, not a new feature.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide