11-24-2014 01:58 AM - edited 03-07-2019 09:37 PM
I am implementing a design similar to the example in this document.
I also found the following document that goes into more details.
I have configured the ASA as per the example and all traffic is routing and passing from inside to inside through the ASA. However DNS traffic is “not” and seems to be being dropped by the ASA.
Has anyone seen this before or know why this may be happening?
Thanks,
11-24-2014 03:21 AM
What's your topology and what exactly do you want to achive? There is almost always a technically better solution than hairpinning your traffic through the ASA.
11-25-2014 11:48 AM
Hi Karsten,
Thanks for your reply,
I have a small layer two network, that has a number of remote site connecting into it through an ASA. All local servers have the ASA as their default gateway.
We are in the process of replacing the firewall and migrating all sites to the new firewall. This will take some time and the existing ASA must be kept in place while the migration takes place.
Once all site have been moved across the gateway address will then move.
As I said above all seems to be working, except DNS.
I hope that makes sense.
Regards,
Andrew
11-25-2014 04:03 PM
Hello
Are you using public or internal DNS
Can you post the ASA config?
res
Paul
11-26-2014 08:21 AM
Hi,
I am using an internal DNS.
The config is the same as the example above.
Regards,
Andy
11-26-2014 09:14 AM
What kind of switch is it? perhaps it can be reconfigured for L3. That would make things more easy.
Your actual config would help, if it's really configured as in the example, it should work.
11-29-2014 11:52 AM
Hi Karsten and Paul,
Thanks so much for you help and input.
Sorry for late reply, I solved the issue the other day.
The link above does work perfectly, it was a global inspect DNS command stopping DNS communications. (Inside to inside only)
Thanks again,
Andrew
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide