5-24
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 NAT Examples and Reference
DNS and NAT
If the user needs to access ftp.cisco.com using the real address, then no further configuration is required.
If there is also a static rule between the inside and DMZ, then you also need to enable DNS reply
modification on this rule. The DNS reply will then be modified two times.In this case, the ASA again
translates the address inside the DNS reply to 192.168.1.10 according to the static rule between inside
and DMZ.
Figure 5-19
DNS Reply Modification, DNS Server, Host, and Server on Separate Networks
DNS Reply Modification, DNS Server on Host Network
The following figure shows an FTP server and DNS server on the outside. The ASA has a static
translation for the outside server. In this case, when an inside user requests the address for ftp.cisco.com
from the DNS server, the DNS server responds with the real address, 209.165.20.10. Because you want
inside users to use the mapped address for ftp.cisco.com (10.1.2.56) you need to configure DNS reply
modification for the static translation.
DN
S
S
erver
O
u
t
s
ide
In
s
ide
U
s
er
1
2
3
5
6
DN
S
Reply Modific
a
tion 1
209.165.201.10
10.1.
3
.14
7
Tr
a
n
s
l
a
tion
10.1.
3
.14
4
DN
S
Reply Modific
a
tion 2
10.1.
3
.14
DN
S
Reply
209.165.201.10
DN
S
Reply
DN
S
Q
u
ery
ftp.ci
s
co.com?
FTP Re
qu
e
s
t
A
S
A
ftp.ci
s
co.com
10.1.
3
.14
S
t
a
tic Tr
a
n
s
l
a
tion 1
on O
u
t
s
ide to:
209.165.201.10
S
t
a
tic Tr
a
n
s
l
a
tion 2
on In
s
ide to:
192.168.1.10
192.168.1.10
192.168.1.10
192.168.1.10
192.168.1.10
DMZ
Содержание ASA 5512-X
Страница 5: ...P A R T 1 Service Policies and Access Control ...
Страница 6: ......
Страница 50: ...3 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 3 Access Rules History for Access Rules ...
Страница 51: ...P A R T 2 Network Address Translation ...
Страница 52: ......
Страница 126: ...5 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 5 NAT Examples and Reference DNS and NAT ...
Страница 127: ...P A R T 3 Application Inspection ...
Страница 128: ......
Страница 255: ...P A R T 4 Connection Settings and Quality of Service ...
Страница 256: ......
Страница 288: ...12 14 Cisco ASA Series Firewall CLI Configuration Guide Chapter 12 Quality of Service History for QoS ...
Страница 303: ...P A R T 5 Advanced Network Protection ...
Страница 304: ......
Страница 339: ...P A R T 6 ASA Modules ...
Страница 340: ......
Страница 398: ...17 28 Cisco ASA Series Firewall CLI Configuration Guide Chapter 17 ASA CX Module History for the ASA CX Module ...