cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
436
Views
0
Helpful
3
Replies

NAT Inconsistencies

mironduplessis
Level 1
Level 1

Hi,

I am running a 2821 Router running 12.4(23) and I am having some odd experiences with nat.

Basically i want the clients on one subnet to be natted for everything except DNS traffic.

The natting works correctly if im just testing basic nat. however when I add an access list it is inconsistent. I added an access list which has basically a deny statements matching any udp/tcp traffic on port 53 and a permit statement for all IP.

When i clear the nat translations and do an NSLookup on a client on the subnet the first few queries are not natted.However they then randomly start to be natted, and the translations shows udp translations on port 53

Anyone have any ideas.

regards

Miron

3 Replies 3

Giuseppe Larosa
Hall of Fame
Hall of Fame

Hello Miron,

clients DNS queries are done on UDP port 53 only.

TCP port 53 is used for zone transfers between DNS servers.

Are you using an internal DNS server or your clients point directly to an ISP DNS ?

Hope to help

Giuseppe

Hey Giuseppe,

We are using an internal DNS Server. However the issue is not with DNS it is with the nating not being consistent.

Regards

Miron

archari
Cisco Employee
Cisco Employee

can u share the ACL's u used and the relevant nat configs on the interfaces?

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card