11-08-2016 02:01 PM - edited 03-12-2019 01:30 AM
Hi
Is there any way to create a access group from a DNS query online.
Want my AV to update allowing there update name (update.av.com) but as DNS names public IPS change all the times I cannot create a access group with thousands of IP's.
Seen some talk on access lists but was wondering if it can be done with access groups as well so that the access group is populated by the latest nslookup and the access list with assigned ports allows the updates to pc/s
Any help appreciated
11-08-2016 02:26 PM
Hi Neil,
Yes, you can. Please go through the below link for details:
https://supportforums.cisco.com/document/66011/using-hostnames-dns-access-lists-configuration-steps-caveats-and-troubleshooting
Hope this helps!
Regards,
Kanwal
Note: Please mark answers if they are helpful.
11-08-2016 11:23 PM
Hi
and thanks for the info but I get a error on the command to create the object on the q of fqdn
IASA(config)# object network AV-UPDATES
IASA(config-network)# fqdn v4 update.av.com
any ideas?
11-09-2016 04:09 AM
Hi Neil,
It works fine for me.
ciscoasa(config-network-object)# fqdn v4 update.av.com
ciscoasa(config-network-object)# exit
ciscoasa(config)# sh run object
object network obj_any
subnet 0.0.0.0 0.0.0.0
object network AV-UPDATES
fqdn v4 update.av.com
I notice "IASA(config-network)#" it should be config-network-object. What is the version running on your ASA?
Regards,
Kanwal
Note: Please mark answers if they are helpful.
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: