Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Access-list FTP - use FQDN instead of IP address

Status
Not open for further replies.

Antelope

MIS
Aug 6, 2003
138
0
0
US
I want to allow ftp access to ftp.symantec.com so my anti-virus server can pull the updates but ftp.symantec.com has many records in DNS. When I try this:

access-list outbound permit tcp host server host ftp.symantec.com eq 21

It says IP address not found (assume it looks in name list)


What am I missing?
 
name 216.200.68.153 ftp.symantec.com.

Or, you could just use the IP address in the rule. ftp.symantec.com only resolves to one IP address.

ftp.symantec.com. 30 IN CNAME ftp.symantec.speedera.net.
ftp.symantec.speedera.net. 30 IN A 216.200.68.153

Chris.

**********************
Chris A.C, CCNA, CCSA
**********************
 
Do an nslookup a couple times and you will get a bunch of different answers.
 
Ah yes, the CNAME resolves to a few IP addresses. Well then, put a rule in for each one or create a network object group.

Chris.

**********************
Chris A.C, CCNA, CCSA
**********************
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top