Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ASA Dns on DMZ

Status
Not open for further replies.

Mikecl

MIS
Oct 7, 1999
51
GB
Hi,

I have an IPSEC tunnel from a remote site that accesses a particular host on the dmz. That host now also requires Internet access (not necessaeraily at the same time)

object-group service webservices tcp-udp
port-object eq www
port-object eq 443
port-object eq domain
exit
access-list dmz_nat_outbound extended permit tcp host Mantis_Pc any object-group webservices. I have configured this and I can access using the IP address but not using dns. the PC is pointing at an external dns server but I cant resolve any names.
2 questions will adding internet access for ths PC break the VPN?
How can I allow dns quesries only from named hosts out to the Internet dns server?
I looked at dns doctoring but that does not seem to apply.

Thanks
 
so if you do a sh access-list dmz_nat_outbound does it show udp/domain (dns) being allowed outbound??

I hate all Uppercase... I don't want my groups to seem angry at me all the time! =)
- ColdFlame (vbscript forum)
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top