Welcome to ISAserver.org

Forums | Register | Login | My Profile | Inbox | RSS RSS icon | My Subscription | My Forums | Address Book | Member List | Search | FAQ | Ticket List | Log Out

DMZ outbound DNS not working

Users viewing this topic: none

Logged in as: Guest
  Printable Version
All Forums >> [ISA 2006 Firewall] >> DMZ >> DMZ outbound DNS not working Page: [1]
Login
Message << Older Topic   Newer Topic >>
DMZ outbound DNS not working - 16.Jan.2007 10:06:10 AM   
RaVanS

 

Posts: 3
Joined: 16.Jan.2007
Status: offline
We have a three-legged (external, internal and DMZ) ISA 2006 configuration. We configured the servers inside the DMZ to use an external DNS because we don't want DMZ servers to use our internal DNS server.
The problem is that our DMZ servers are unable to use this DNS. Browsing the internet works however when I use the ip address of an external website. I get an DNS error when I use a URL instead of the ip address.
I created a rule for DNS outbound from DMZ. The ISA monitor tells me:
dns - port 53 - initiated connection
and after a while
dns - port 53 - denied connection

Does someone know why I get this denied connection? I use the same external DNS for DNS forwarding from the internal network segment and I works fine.
Thanks a lot.
Post #: 1
RE: DMZ outbound DNS not working - 22.Jan.2007 11:16:38 AM   
tshinder

 

Posts: 47420
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi RaVan,

What is the Network Rule from DMZ to external?

What is the Access Rule allowing DMZ clients access to external DNS servers?

Are the DMZ servers SecureNAT clients?

Thanks!
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to RaVanS)
Post #: 2
RE: DMZ outbound DNS not working - 24.Jan.2007 2:35:47 AM   
RaVanS

 

Posts: 3
Joined: 16.Jan.2007
Status: offline
Hi Tom,

Thanks for the response to my question. I already solved my issues

I found out that ISA just routes traffic from external to DMZ. I was using private range ip adresses in the DMZ. Because there is no NAT happening it did not work.

So I have to options:

Let ISA use NAT to translate private ip adressen to public addresses and ViceVersa
Configure the NICs of the hosts in the DMZ to use public addresses.

Could you please explain what would be the best option.

Thanks

(in reply to tshinder)
Post #: 3
RE: DMZ outbound DNS not working - 24.Jan.2007 9:07:30 AM   
tshinder

 

Posts: 47420
Joined: 10.Jan.2001
From: Texas
Status: offline
Hi RaVan,

I think the best option is to bind your public addresses to the ISA Firewall's external interface and then use NAT from DMZ --> External.

HTH,
Tom

_____________________________

Thomas W Shinder, M.D.
Sr. Consultant/Technical Writer
Prowess Consulting http://www.prowessconsulting.com/
Blog: http://blogs.isaserver.org/shinder/

GET THE NEW ISA 2006 Book!: http://tinyurl.com/2gpoo8

(in reply to RaVanS)
Post #: 4

Page:   [1] << Older Topic    Newer Topic >>
All Forums >> [ISA 2006 Firewall] >> DMZ >> DMZ outbound DNS not working Page: [1]
Jump to:

New Messages No New Messages
Hot Topic w/ New Messages Hot Topic w/o New Messages
Locked w/ New Messages Locked w/o New Messages
 Post New Thread
 Reply to Message
 Post New Poll
 Submit Vote
 Delete My Own Post
 Delete My Own Thread
 Rate Posts