I have opened up ports 53 tcp and udp on the outside, inside, and dmz interface and still I cannot resolve off of the DNS server in the DMZ - TAC support was not much help - has anyone run across this problem?
Yes I am having the same problem. I have a pix 515r and a dmz with a win2k server on it. I can't seem to get dns either. I opened the same ports plus one other but was unsucessful. I also am having a routing issue where the dmz can see only the subnet directly connected to the trusted interface on the pix. We have multiple private subnets back there, but I cannot ping the dmz from them and I can ping the opposite way as well.
Opening up port 53 isn't enough. Remember that when you make a request to the DNS server in your DMZ the destination port is 53 but the source port (your client) will be greater than 1023. If you have applied any access lists to your inside interface then there will be a implicit deny at the end. If you are not allowing UDP ports greater than 1023 back in then the replies to your request will be blocked.
Can you post the entire config (edited) ?
Chris.
************************
Chris Andrew, CCNA
chrisac@gmx.co.uk
************************
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.