collapse

Search


User Info

 
 
Welcome, Guest. Please login or register.
Did you miss your activation email?

Author Topic: Cisco ASA DNS  (Read 23891 times)

Offline Pankz

  • Cisco Newbie
  • *
  • Posts: 2
  • Reputation: 0
  • Certification: N/A
Cisco ASA DNS
« on: February 23, 2018, 06:02:09 AM »
One of my user need my help in getting access to URL hosted in AWS from this PC and i provided the access in Cisco ASA (FQDN access)...but he is facing Intermittent connectivity issue and after some troubleshooting we came to the conclusion that the URL is getting resolved to multiple IP's (TTL value is 30 Sec) and at the same moment ASA is unable to resolve the current IP's and hence connection is still pointed towards old IP.

I believe this is some thing related to ASA DNS cache time value.

Did anyone here faced the same issue??

Offline MC

  • Global Moderator
  • Cisco Guru
  • *****
  • Posts: 401
  • Reputation: 606
  • CCIE x3 (RS,Sec,SP)
  • Certification: CCIE
Re: Cisco ASA DNS
« Reply #1 on: February 26, 2018, 09:51:47 PM »
Does your user have the ASA as the DNS server? If so, can you point it to another internal or public DNS server?

Offline Pankz

  • Cisco Newbie
  • *
  • Posts: 2
  • Reputation: 0
  • Certification: N/A
Re: Cisco ASA DNS
« Reply #2 on: February 28, 2018, 03:47:17 AM »
Thanks MC for reverting.

No, the user PC is configured with our internal DNS servers.
« Last Edit: February 28, 2018, 03:57:19 AM by Pankz »

Offline MC

  • Global Moderator
  • Cisco Guru
  • *****
  • Posts: 401
  • Reputation: 606
  • CCIE x3 (RS,Sec,SP)
  • Certification: CCIE
Re: Cisco ASA DNS
« Reply #3 on: February 28, 2018, 07:53:27 PM »
In that case, the ASA should have no influence on the TTL. You can try to turned off DNS inspection on the ASA too.

 

Related Topics

  Subject / Started by Replies Last post
3 Replies
23645 Views
Last post August 21, 2014, 04:02:34 PM
by rthurber
2 Replies
24565 Views
Last post February 09, 2015, 10:54:52 AM
by ozone007
1 Replies
21643 Views
Last post October 26, 2017, 09:33:07 PM
by MC
0 Replies
34302 Views
Last post December 23, 2017, 12:51:41 PM
by ggseide@gmail.com
Cisco and Microsoft PKI

Started by Exonix Security

1 Replies
17811 Views
Last post July 16, 2018, 06:16:21 PM
by MC

SimplePortal 2.3.7 © 2008-2024, SimplePortal