Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

How can I route requests to a server on an internal lan through an external dns?

Posted on 2004-04-27
8
257 Views
Last Modified: 2010-04-17
We have a 10.x.x.x internal scope running trhough a cisco pix firewall to a 2600 router to the internet.  We have web applications running from our website and from two other servers on our internal lan.  If using a dns server external to our lan, we can resolve the internal web through an alias command in the pix.  Unfortunately,  I cannot access the other two servers which are usually access through ip address.  Access from the outside in works fine, but we cannot resolve the external ip address back to the internal nat in the pix. All other sites are accessible except the two that need resolution to the ip address.  A Cisco TAC engineer said that a static route may need to be put in for the particular ip address at the router.  Does this sound like a possibility?  Any ideas?  We have created a workaround by providing two seperate links on our web... one to the inside ip address and one to the outside but would like to be able to allow the inside scope to resolve to the same link as the external.
0
Comment
Question by:BrianClements
  • 3
  • 2
8 Comments
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10930576
Are you saying that name resolution of the external addresses doesn't work from the inside? Or that you can't talk to the inside web servers from the outside? You need to clarify your question please. I can help you with DNS or routing issues, but I don't understand your problem right now.
0
 

Author Comment

by:BrianClements
ID: 10931572
I apologize for my wording.  We have 3 internal servers that need to be accessed inside and outside.  These are 10.10.1.83,84, and 85.  Our web resolves to 10.10.1.83, and after adding an alias command to our pix we could resolve the name to the internal number using an external dns server from inside the network.  The problem comes when we need to access the other two servers which have no internet name to resolve to.  10.10.1.84 is NAT to 66.109.42.164, and we cannot ping 66.109.42.164.  the alias command only seems to work when name resolution is used. We can only access it from our internal number of 10.10.1.84 which forces us to use two links on our web.  We are unable to ping any of the external numbers that our internal numbers NAT to.  What we would like is to be able to route the external link back to the internal ips.
0
 
LVL 11

Accepted Solution

by:
PennGwyn earned 125 total points
ID: 10931784
The traditional fix has been to put a DNS on the internal network that only serves internal clients, and returns local addresses rather than global addresses.

As of BIND 9, this doesn't require a separate box; you can configure it to return different results depending on the source of the DNS query.

0
PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10931788
On the PIX, have you tried using
ip host [hostname] 66.109.42.164

I'm honestly not that familiar with PIX, but this works in IOS and I'm guessing on the PIX. It's just the IOS equivalent of a local host table, and maybe that will let the alias command work.

Are the 2 servers with the problem translating to the same public IP subnet as the one that's working? Can you ping their public IPs from the outside, or is the problem only on the inside?
0
 
LVL 28

Assisted Solution

by:mikebernhardt
mikebernhardt earned 125 total points
ID: 10931892
It sounds like the source of the problem is that you have links on your page to IP addresses rather than host names, and those IPs aren't reachable from the inside.

If my ip host suggestion doesn't work, why don't you just put them in your external DNS? If you're making them accessible from the outside, you might as well give them names too.
0
 

Author Comment

by:BrianClements
ID: 10932603
thank you all...Ill try these resolutions tomorrow.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen some questions on problems with SSH/telnet access to Cisco routers that may occur despite the fact that from a PC connected to your LAN, Internet connectivity is in place and users can access Internet sites without any issues.  There are…
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question