[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now

x
?
Solved

ASA-DNS Packet process

Posted on 2011-09-23
4
Medium Priority
?
443 Views
Last Modified: 2012-05-12
Hi,

I have Cisco ASA 5510 Firewall.
My System Is in ASA Inside Network with Private IP
My DNS is in Outside interface with Public IP

my  queries are

If my PC requests any Cisco URL how the Packet process from ASA to DNS and back from DNS - ASA and to My PC-Cisco Site.

If DNS is inside then if i request for Cisco URL then how the Packet process from ASA to DNS and back from DNS - ASA and to My PC-Cisco Site.

Do i need to static NAT to my inside  DNS to pubic IP or Forwarding to Public DNS is a solution ?

Regards
ramu

 

0
Comment
Question by:RAMU CH
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 18

Expert Comment

by:jmeggers
ID: 36587253
If  the name-server is outside with a public IP and the destination is outside as well, then the request will be NATed at the ASA, the response will come back and then the host will have the real IP.  

If the name-server is inside and the destination is outside, the request will go directly to the server and no NAT is needed.  The server will respond with the public IP of the destination.  

The complication is when the destination is NATed, such as an FTP server in your DMZ.  The outside DNS server will only know the FTP server by its public address, but inside hosts will reach the FTP server on its private address.  In that case, address translation must happen going through the ASA.  See the section on DNS and NAT in the ASA configuration guide at http://www.cisco.com/en/US/docs/security/asa/asa83/configuration/guide/nat_overview.html#wp1090556.

0
 
LVL 1

Author Comment

by:RAMU CH
ID: 36591411
The DOC: is about DNS reply modification..

If my DNS reply  comes back with Public IP  address , do in need a access-list for the Inbound rule from DNS to My local host

For DNS traffic which port i need to allow for Inbound / outbound traffic in PIX/ASA
Why DNS is a UDP traffic because it will send the reply acknowledgements ?

Regards
Ramu
0
 
LVL 35

Accepted Solution

by:
Ernie Beek earned 2000 total points
ID: 37023774
Here is a nice article about DNS and setting up DNS inspection: http://www.cisco.com/web/about/security/intelligence/dns-bcp.html
0
 
LVL 1

Author Closing Comment

by:RAMU CH
ID: 37111986
Thnaks
0

Featured Post

Important Lessons on Recovering from Petya

In their most recent webinar, Skyport Systems explores ways to isolate and protect critical databases to keep the core of your company safe from harm.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This past year has been one of great growth and performance for OnPage. We have added many features and integrations to the product, making 2016 an awesome year. We see these steps forward as the basis for future growth.
Considering cloud tradeoffs and determining the right mix for your organization.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

649 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question