Improve company productivity with a Business Account.Sign Up

x
?
Solved

Allow DNS lookups with Cisco ACL

Posted on 2006-11-20
2
Medium Priority
?
359 Views
Last Modified: 2008-01-09
I currently use ACL's on my Cisco 2600 series router to block as much of what I don't want as possible.  The lines that pertain to my web server are:

access-list 116 permit tcp any host <my web IP> eq www
access-list 116 permit tcp any host <my web IP> eq 443
...followed by a "deny all"  at the end.  

Now, however, I need to allow this web server to access a few other web sites, and it appears that my only issue is that I can't get results from my ISP's DNS server.  I thought this line should do it:

access-list 116 permit udp any host <my web IP> eq domain

I can access a site by using a specific IP address, but I still can't resolve any domain names.  How do I alllow DNS with ACL's?

Thanks!
0
Comment
Question by:DBrecht
2 Comments
 
LVL 43

Accepted Solution

by:
JFrederick29 earned 750 total points
ID: 17981013
Close.  Change it to this:

access-list 116 permit udp any eq domain host <my web IP>
0
 
LVL 2

Expert Comment

by:shekharbasnet
ID: 17985774
Or if you need a more tighter rule:

access-list 116 permit udp host <dns IP> eq domain host <my web IP>
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
Tired of waiting for your show or movie to load?  Are buffering issues a constant problem with your internet connection?  Check this article out to see if these simple adjustments are the solution for you.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

606 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question