professorguy
MIS
I have 2 internal caching DNS machines which must get DNS requests out. I did this:
..
access-list acl_outside extended permit udp any host 192.168.7.250 eq domain
access-list acl_outside extended permit udp any host 192.168.7.251 eq domain
...
access-list acl_inside extended permit udp host 192.168.7.250 any eq domain
access-list acl_inside extended permit udp host 192.168.7.251 any eq domain
...
And there's also the standard policy_map stuff:
inspect dns map1 (with parameter message-length max 512).
But there are DNS problems on the inside: I can visit websites that my internal DNS servers have cached, but new ones can be seen only by IP.
What else needs to happen?
..
access-list acl_outside extended permit udp any host 192.168.7.250 eq domain
access-list acl_outside extended permit udp any host 192.168.7.251 eq domain
...
access-list acl_inside extended permit udp host 192.168.7.250 any eq domain
access-list acl_inside extended permit udp host 192.168.7.251 any eq domain
...
And there's also the standard policy_map stuff:
inspect dns map1 (with parameter message-length max 512).
But there are DNS problems on the inside: I can visit websites that my internal DNS servers have cached, but new ones can be seen only by IP.
What else needs to happen?