Cisco ASA Series Cli Configuration Manual page 776

Software version 9.0 for the services module
Hide thumbs Also See for ASA Series:
Table of Contents

Advertisement

DNS and NAT
a static rule between the inside and DMZ, then you also need to enable DNS reply modification on this
rule. The DNS reply will then be modified two times.In this case, the ASA again translates the address
inside the DNS reply to 192.168.1.10 according to the static rule between inside and DMZ.
Figure 1-23
3
DNS Reply Modification 1
209.165.201.10
4
DNS Reply Modification 2
10.1.3.14
Cisco ASA Series CLI Configuration Guide
1-30
DNS Reply Modification, DNS Server, Host, and Server on Separate Networks
1
DNS Query
2
ftp.cisco.com?
DNS Reply
209.165.201.10
10.1.3.14
192.168.1.10
5
DNS Reply
192.168.1.10
DNS Server
Static Translation 1
on Outside to:
209.165.201.10
Outside
Static Translation 2
on Inside to:
Security Device
192.168.1.10
DMZ
Translation
Inside
192.168.1.10
FTP Request
192.168.1.10
User
Chapter 1
Information About NAT
ftp.cisco.com
10.1.3.14
7
10.1.3.14
6

Advertisement

Table of Contents
loading

Table of Contents