Dns Rewrite With Three Nat Zones - Cisco 7604 Configuration Manual

Catalyst 6500 series switch and cisco 7600 series router firewall services module configuration guide using the cli
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

DNS Inspection
hostname(config)# access-group 101 in interface outside
This configuration requires the following A-record on the DNS server:
server.example.com. IN A 209.165.200.225

DNS Rewrite with Three NAT Zones

Figure 22-5
transparently with a DNS server with minimal configuration. For configuration instructions for scenarios
like this one, see the
Figure 22-5
server.example.com IN A 209.165.200.225
In
Figure
interface of the FWSM. A web client with the IP address 10.10.10.25 is on the inside interface and a
public DNS server is on the outside interface. The site NAT policies are as follows:
When a host or client on any interface accesses the DMZ web server, it queries the public DNS server
for the A-record of server.example.com. The DNS server returns the A-record showing that
server.example.com binds to address 209.165.200.225.
When a web client on the outside network attempts to access http://server.example.com, the sequence of
events is as follows:
1.
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
22-22
illustrates a more complex scenario: how DNS inspection allows NAT to operate
"Configuring DNS Rewrite with Three NAT Zones" section on page
DNS Rewrite with Three NAT Zones
DNS server
10.99.99.2
22-5, a web server, server.example.com, has the real address 192.168.100.10 on the DMZ
The outside DNS server holds the authoritative address record for server.example.com.
Hosts on the outside network can contact the web server with the domain name server.example.com
through the outside DNS server or with the IP address 209.165.200.225.
Clients on the inside network can access the web server with the domain name server.example.com
through the outside DNS server or with the IP address 192.168.100.10.
The host running the web client sends the DNS server a request for the IP address of
server.example.com.
Chapter 22
Outside
FWSM
DMZ
192.168.100.1
Inside
10.10.10.1
Web client
10.10.10.25
Applying Application Layer Protocol Inspection
22-23.
Web server
192.168.100.10
OL-20748-01

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7609-s76137606-sCatalyst 6500 series7600 series

Table of Contents