NAT DNS payload replacement. Very funny, Cisco.

Answered Question
Nov 22nd, 2012
User Badges:

ip nat inside source list bunch_of_hosts pool some_pool overload

ip nat inside source static 10.10.10.10 91.91.91.91 no-payload



there is a DNS record:


some_host.some.domain     IN     A     91.91.91.91


from host in bunch_of_hosts list:


$ dig some_host.some.domain @8.8.8.8


;;ANSWER SECTION:

some_host.some.domain     IN     A     10.10.10.10


Who's idea was that? How to disable it??



Clarification: DNS server, hosting some.domain is NOT inside our network. It's completely different organisation and thir DNS gives the right answer when asked outside this NAT setup.

Correct Answer by Peter Paluch about 4 years 6 months ago

Hello,


Can you try using these commands? They should stop IOS rewriting the DNS contents as part of its NAT ALG.


no ip nat service alg tcp dns

no ip nat service alg udp dns


Best regards,

Peter

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Muhammad Thanveer Thu, 11/22/2012 - 03:59
User Badges:
  • Silver, 250 points or more

Dear Utair,


Am I correct If I ask you, do you need to remove nating?

I am sorry if I am wrong, can you please elaborate?


Regards
Thanveer
"Everybody is genius. But if you judge a fish by its ability to climb a tree, it will live its whole life believing that it is a stupid."

Utair Corporation Thu, 11/22/2012 - 19:05
User Badges:

I need to disable payload inspection and modification for this NAT statement:

ip nat inside source list bunch_of_hosts pool some_pool overload

Because right now DNS replies for A record, containing 91.91.91.91 address gets modified by router to 10.10.10.10.

johnlloyd_13 Thu, 11/22/2012 - 06:44
User Badges:
  • Blue, 1500 points or more

hi,


you'll need to contact your DNS hosting provider to correct your zone file records.


if you're not sure, check using WHOIS database.

Correct Answer
Peter Paluch Fri, 11/23/2012 - 05:53
User Badges:
  • Cisco Employee,

Hello,


Can you try using these commands? They should stop IOS rewriting the DNS contents as part of its NAT ALG.


no ip nat service alg tcp dns

no ip nat service alg udp dns


Best regards,

Peter

Actions

This Discussion

Related Content