Also did a security policy, but it does not show up in the access list.
No.
Yes. The problem is the config on the Cisco.
Regards, Lars.
C
chris
Nothing to do with allowing inbound DNS queries to your server!
If you are port forwarding from your external IP address to the DNS server then I think that you are supposed to use the keyword "interface" rather than the external IP address.
If it doesn't show up in the access list then the chances are that it isn't in there, therefore no traffic to your server!
L
Lars Bonnesen
"chris" skrev i en meddelelse news: snipped-for-privacy@karoo.co.uk...
What is it used for then?
I have severel IP addresses. If I use "interface" - how can the Cisco then know which IP address to use?
You are right - but why does it not show up? The policy is created in ASDM and I did an "apply" - and I still can see them in ASDM. Could it be that the Cisco does not allow it to be created because some proxy is doing the DNS job?
Regards, Lars.
L
Lars Bonnesen
"Lars Bonnesen" skrev i en meddelelse news:44376350$0$849$ snipped-for-privacy@dread14.news.tele.dk...
But is it listed with the public IP - I was looking for a private IP, because the policy in ASDM was created from any outside to localIP inside.
Why isn't it working?
Regards, Lars.
C
chris
DNS resolution for the Pix.
Becuase you are specifying the *internal* IP address in the static. The "interface" keyword is for when you are port forwarding from the *external* interface IP address.
ie. if I have a web server on 192.168.10.1 and a mail server on 192.168.10.2 then I might use ..
Requets to the external IP address on port 80 would go to .1 and requests to the same external IP address on port 25 would go to .2
Chris.
C
chris
Because traffic from the outside will be sent to the public IP, not the private one!
Maybe the IP's are wrong? Maybe the DNS server isn't set up to accept external queries? Maybe the access list isn't applied to the interface?
You really need to look at the logging on the firewall when you try external access to the DNS server. if traffic is being dropped by the ACL then you'll see that in the logs.
What's the IP address of your external interface?
Chris.
L
Lars Bonnesen
"chris" skrev i en meddelelse news: snipped-for-privacy@karoo.co.uk...
My god, how dumb I am.... I didn't allow outgoing DNS lookup to that address from the LAN I am sitting on (another one). The Cisco config is working correctly.
Sorry for the inconvienience and thank you for trying...
C
chris
Glad to hear that it's working. The answer is usually something simple ;-)
Chris.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.