RE: DNS and NAT

From: Nir Wittenberg (nwittenberg@msncomm.com)
Date: Tue May 11 2004 - 19:09:47 GMT-3


Alexei,

I think your link to the sample config would have worked. I ended up
having the customer put a secondary IP address of the global IP on the
WWW server and putting a static route on the SOHO router pointing to the
internal address of the WWW server as a next hop for it's global ip
which DNS is returning to the local clients.

Thanks everyone for you replies.

-----Original Message-----
From: asadovnikov [mailto:asadovnikov@comcast.net]
Sent: Monday, April 19, 2004 10:55 PM
To: Nir Wittenberg; ccielab@groupstudy.com
Subject: RE: DNS and NAT

Here is a link which describes how this feature of IOS works
        
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_configuration_e
xamp
le09186a0080093f30.shtml

I am not positive though that it will be applicable in your case.

Best regards,
Alexei

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
Nir Wittenberg
Sent: Tuesday, April 20, 2004 12:46 AM
To: Sean; ccielab@groupstudy.com
Subject: RE: DNS and NAT

I do have a static translation for the WWW server and the DNS servers
are translating to the NATed global address. Can you give me an example
of how it is possible to change the DNS reply payload?

-----Original Message-----
From: Sean [mailto:forum@xkey.org]
Sent: Friday, April 16, 2004 7:02 PM
To: Nir Wittenberg; ccielab@groupstudy.com
Subject: RE: DNS and NAT

Yes, the IOS NAT can change the DNS reply payload, and change the global
IP to local IP, but only when static NAT is configured on Router.

Also there is a keyword that you can use to turn off the feature
starting IOS 12.3 or 12.2T
 

-----Original Message-----
From: nobody@groupstudy.com [mailto:nobody@groupstudy.com] On Behalf Of
Nir Wittenberg
Sent: Friday, April 16, 2004 4:55 PM
To: ccielab@groupstudy.com
Subject: DNS and NAT

Is there a solution within IOS to intercept DNS resolution? My issue is
that I have hosts and a WWW server on the same segment. All are being
NATed. The DNS servers sits outside of the Network/NAT and tells the
rest of the enterprise the way to get to the WWW server use this global
IP which has a static translation to the WWW server. The issue is that
when the local host do a DNS lookup they are getting the global IP
rather than the local IP.

I know the PIX can do this with the dns and alias keywords but I am
looking for an IOS solution.

Thanks,
Nir
CCIE 12261



This archive was generated by hypermail 2.1.4 : Wed Jun 02 2004 - 11:12:10 GMT-3