Link to home
Start Free TrialLog in
Avatar of MichaelBalack
MichaelBalackFlag for Singapore

asked on

Can't access to this firewall with public hostname, why?

This is using Cisco ASA 5505 firewall. There are 2 interfaces, one being the WAN, and another is LAN. This firewall is working fine, with the only problem being users in Internal LAN can't access a hosted web server by public hostname. For example, an internal web server having an Private IP 10.24.1.x, with firewall port forwarding aaa.bbb.ccc.15 mapped to www.abc.com. For this web server, user can access www.abc.com from any where via the Internet. However, if user is back to work in office, he/she will find that accessing to www.abc.com is simply not successful. If they access by private IP, then, no problem.

Appreciate if you have can help to solve the "mystery". Please see attached ASA Config file.
EE---cisco-ASA-5505config.txt
ASKER CERTIFIED SOLUTION
Avatar of Systech Admin
Systech Admin
Flag of India image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
please allow port 53 in firewall and then check again
Assuming the users and the web server are both on 10.24.1.x?

You would need to create  a split DNS record on your internal DNS servers for www.abc.com that points to its 10.24.1.x address, This is quite common see

Windows - Setting Up Split DNS

Pete
Or depending on the version your firewall is running perform 'DNS doctoring' add the DNS keyword to the NAT statement like so

Post version 8.3

object network obj-Web-Server
host 10.24.1.x
nat (inside,outside) static aaa.bbb.ccc.15  dns
Avatar of MichaelBalack

ASKER

Hi Mohammed and PeteLong,

Thanks for the suggestions and guidance. I will arrange to be onsite to look into the problem.
I'll update you guys about the status.
Hi Mohammed and PeteLong,

Sorry to drag the problem for such long. However, I will be onsite to look into the problem tomorrow morning, will update you guys by then.

Good luck to me.
Thanks expert - Gaurav, use of this method to resolve to its internal IP. It works