?
Solved

How can I route requests to a server on an internal lan through an external dns?

Posted on 2004-04-27
8
Medium Priority
?
272 Views
Last Modified: 2010-04-17
We have a 10.x.x.x internal scope running trhough a cisco pix firewall to a 2600 router to the internet.  We have web applications running from our website and from two other servers on our internal lan.  If using a dns server external to our lan, we can resolve the internal web through an alias command in the pix.  Unfortunately,  I cannot access the other two servers which are usually access through ip address.  Access from the outside in works fine, but we cannot resolve the external ip address back to the internal nat in the pix. All other sites are accessible except the two that need resolution to the ip address.  A Cisco TAC engineer said that a static route may need to be put in for the particular ip address at the router.  Does this sound like a possibility?  Any ideas?  We have created a workaround by providing two seperate links on our web... one to the inside ip address and one to the outside but would like to be able to allow the inside scope to resolve to the same link as the external.
0
Comment
Question by:BrianClements
  • 3
  • 2
6 Comments
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10930576
Are you saying that name resolution of the external addresses doesn't work from the inside? Or that you can't talk to the inside web servers from the outside? You need to clarify your question please. I can help you with DNS or routing issues, but I don't understand your problem right now.
0
 

Author Comment

by:BrianClements
ID: 10931572
I apologize for my wording.  We have 3 internal servers that need to be accessed inside and outside.  These are 10.10.1.83,84, and 85.  Our web resolves to 10.10.1.83, and after adding an alias command to our pix we could resolve the name to the internal number using an external dns server from inside the network.  The problem comes when we need to access the other two servers which have no internet name to resolve to.  10.10.1.84 is NAT to 66.109.42.164, and we cannot ping 66.109.42.164.  the alias command only seems to work when name resolution is used. We can only access it from our internal number of 10.10.1.84 which forces us to use two links on our web.  We are unable to ping any of the external numbers that our internal numbers NAT to.  What we would like is to be able to route the external link back to the internal ips.
0
 
LVL 11

Accepted Solution

by:
PennGwyn earned 500 total points
ID: 10931784
The traditional fix has been to put a DNS on the internal network that only serves internal clients, and returns local addresses rather than global addresses.

As of BIND 9, this doesn't require a separate box; you can configure it to return different results depending on the source of the DNS query.

0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10931788
On the PIX, have you tried using
ip host [hostname] 66.109.42.164

I'm honestly not that familiar with PIX, but this works in IOS and I'm guessing on the PIX. It's just the IOS equivalent of a local host table, and maybe that will let the alias command work.

Are the 2 servers with the problem translating to the same public IP subnet as the one that's working? Can you ping their public IPs from the outside, or is the problem only on the inside?
0
 
LVL 28

Assisted Solution

by:mikebernhardt
mikebernhardt earned 500 total points
ID: 10931892
It sounds like the source of the problem is that you have links on your page to IP addresses rather than host names, and those IPs aren't reachable from the inside.

If my ip host suggestion doesn't work, why don't you just put them in your external DNS? If you're making them accessible from the outside, you might as well give them names too.
0
 

Author Comment

by:BrianClements
ID: 10932603
thank you all...Ill try these resolutions tomorrow.
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question