Local DNS entry in Firewall

Posted on 2012-09-05
Last Modified: 2012-09-20
Dear All,

We have a new DNS (AD) server, and I was wondering if I need to add this entry into the Firewall as a local server?
Question by:lloydabberton
    LVL 18

    Expert Comment

    by:Sushil Sonawane
    It's totally depend on you.

    It's good practice to add local dns server entry in firewall but last server.


    Preferences of dns entry

    1) First dns server : ISP DNS IP address
    2) Second dns server : ISP DNS IP Address
    3) Third dns server : Your local dns server.
    LVL 57

    Accepted Solution

    Quick answer is NO - unless you want the ASA to resolve internal DNS? A Better option is to set it to resolve public domain names, then (After version 8.4 you can use domain names in your Access-lists).

    dns domain-lookup outside
    DNS server-group DefaultDNS
        name-server {ISP-DNS-IP-One}
        name-server {ISP-DNS-IP-Two}
        domain-name {your-internal-domain-name}
    LVL 16

    Expert Comment

    if you are tlaking about FW WAN than, i would suggest NO....
    on teh firewall WAN keep ISP DNS.

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    How your wiki can always stay up-to-date

    Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
    - Increase transparency
    - Onboard new hires faster
    - Access from mobile/offline

    Suggested Solutions

    Title # Comments Views Activity
    Router RV016 Cisco configuration 3 42
    L2/L3 Switch configuration 4 93
    replace module of Catalyst 6509 4 46
    Cisco 2921 WIC card 2 35
    If you have an ASA5510 then this sort of thing would be better handled with a CSC Module, however on an ASA5505 thats not an option, and if you want to throw in a quick solution to stop your staff going to facebook during work time, then this is the…
    Network traffic routing plays key role in your network, if you have single site with heavy browsing or multiple sites, replicating important application data from your Primary Default Gateway ,you have to route your other network traffic from your p…
    Excel styles will make formatting consistent and let you apply and change formatting faster. In this tutorial, you'll learn how to use Excel's built-in styles, how to modify styles, and how to create your own. You'll also learn how to use your custo…
    In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

    737 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    20 Experts available now in Live!

    Get 1:1 Help Now