CISCO Configuring DNS
Imagine having to remember IP addresses such as 192.168.200.3 instead of a domain name such as www.google.com. One IP address we could probably remember, but times this by the amount of the websites you visit daily and now remember IP addresses for EACH one... I certainly could not. This is where Domain Name System (DNS) assists us in using human-readable names instead of computer understood IP addresses. DNS is ultimately going to do this translation automatically so the computer knows where we are directing it.
Lab setup
- GNS3 as the network emulation software.
- I have my PC (host1).
- A CISCO router on IOSv 15.7 (Router - Cisco Modelling Labs Personal $199).
- One additional PC (host2) which is going to host a webserver.
- A CISCO layer 2 switch (Switch).
- A NAT node representing external connectivity to the internet.
- Additional learning: Internal DNS server using free software DNSMASQ.
IP Schema
The IP schema for this lab will be 10.10.10.0/24. This will give us 254 usable addresses (256 - broadcast address - network address). The subnet mask will be 255.255.255.0.
DNS Configuration
In this lab we want to configure the following DNS options:
- The routers internal facing interface is to be IP addressed with 10.10.10.254.
- The routers external facing interface is to be set to DHCP which will allow it to receive an IP address from my host machine.
- The router is to provide a primary DNS service to the internal network, with unknown requests being further forwarded for resolution (this would be your home router in reality).
- Host2 (the webserver) will use IP address 10.10.10.200 and will be hosting a simple webpage. The router is to hold a DNS record pointing to this webserver; the domain name is to be slash-root.com
- When we enter http://slash-root.local in a browser on host1, it will use the router as its primary DNS to resolve the domain name to IP address and display the website.
Router Configuration
The routers interfaces are configured with IP addresses:
data:image/s3,"s3://crabby-images/fc3c7/fc3c7aa264be5c09bb1142a036525a38c3f82655" alt="inside interface"
The inside interface Gi0/0 is configured with an internal address within the selected schema; in this case 10.10.10.254.
data:image/s3,"s3://crabby-images/05fad/05fada07ac8d8dabfed241a74f84a0f5fde26e1c" alt="outside interface"
The outside interface, the interface representing connectivity to my ISP is set to DHCP to receive an external IP from my ISP. I know in this case it is a private network address, but just imagine this being a public IP assigned by your ISP. At this stage trying to PING the outside world will fail as domain-lookup has not been enabled:
data:image/s3,"s3://crabby-images/a0a19/a0a19adfbcca48911f3f627ad16c138fa04c6c04" alt="dnserror"
To enable DNS, simply enter:
data:image/s3,"s3://crabby-images/80727/80727b304c0932dc97e7a5beb12c0af3d62ea6b0" alt="enabledns"
Trying to PING the outside world (www.google.com in this case) now yields results.
data:image/s3,"s3://crabby-images/72c3b/72c3b95213de73c77b832ab34ee747d96005b55a" alt="ping success"
Something to bear in mind at this stage, my recursive nameserver in this instance is the DNS settings provided by my DHCP on the external interface. This can be seen here:
data:image/s3,"s3://crabby-images/1bab8/1bab82a6113bf3ff9501cc36fd01624a4cd7f501" alt="dnssettings"
If we wanted to change our recursive nameserver to something different, we can using the following process:
data:image/s3,"s3://crabby-images/75c9f/75c9fbaaed2e3e3118bc22fcbf8060376ac0174a" alt="changenameserver"
What we have done here; first we have removed the DHCP provided nameserver of 192.168.122.1 and then added 8.8.8.8 (Googles DNS service), confirmed the change by viewing our DNS settings and then ensuring it
is working by using PING to an external domain (wwww.slash-root.com). At this stage we can now enable a DNS service to serve our internal network:
Configuring the hosts and fixing issues
The next step is to configure host1 and host2 to use our router as their default-gateway and DNS server:
data:image/s3,"s3://crabby-images/f0e8a/f0e8a39bf4ce8119d940fc97fccbf331d68f937d" alt="host1dns"
Once configured we can attempt to PING the default-gateway and then an external domain name to ensure our DNS service is working correctly.
data:image/s3,"s3://crabby-images/95266/95266e6fa6edb7c064ccf0dece138347ee11478d" alt="dnsissue1"
You will notice we could PING the default-gateway (our router) but we could not PING an external domain name. The issue we have run into here is; when our router receives a packet from host1 with the source IP address of 10.10.10.1 (private address) it refuses to route it any further without explicit instruction. The solution is address translation (Overload in CISCO speak).
You will notice we could PING the default-gateway (our router) but we could not PING an external domain name. The issue we have run into here is; when our router receives a packet from host1 with the source
IP address of 10.10.10.1 (private address) it refuses to route it any further without explicit instruction. The solution is address translation (Overload in CISCO speak).
The first step is to identify which interfaces are inside and outside; we do this using the following commands:
data:image/s3,"s3://crabby-images/e25b1/e25b157c0eeaa6a9efa745b3c5306c41c6b723c0" alt="natinterfaces"
Here we have said the internal interface Gi0/0 (the one connected to our LAN) is the NAT inside. We've also said interface Gi0/1 is the NAT outside. To link this together we now run the following commands:
data:image/s3,"s3://crabby-images/8fce4/8fce4761cdc2bf59337448d99c5a9b2054b55fc4" alt="overload"
All this command is doing, is first creating a list of IPs we want to include in this address translation (10.10.10.0/24) and then applying this address translation from the inside to the outside interface Gi0/1. Once executed
we save the configuration, restart the hosts and test our DNS service again:
data:image/s3,"s3://crabby-images/e8e44/e8e444fc970db1bcbf6d9832b114f640e738ef1e" alt="host1success"
If you are interested in seeing the actual translations this is performing, you can view them by running the following command:
show ip nat translations
The next step as per the specification for this lab is to create an internal webserver on host2 and map a domain name to its IP address so host1 can access it using this name. To this we first need to IP address and create a simple
webserver on host2:
data:image/s3,"s3://crabby-images/4d599/4d5990abf2552d2f65c447e0686c58740085badd" alt="pythonwebserver"
The above command is run on host2; it simply starts a very simple Python webserver on the port desigated. The file it is hosting is index.html I created as below:
data:image/s3,"s3://crabby-images/cdb44/cdb447d243c4509c11f8fa0e78f59eb21d476d2d" alt="simpleindex"
Just a reminder, the Python simple webserver will serve the files in its executed directory. As a check at this point, lets try and access the webserver now running on host2 using a browser on host1.
data:image/s3,"s3://crabby-images/a9614/a9614c6909b65ffa8358d19b92ec3802bd2afe35" alt="host1access"
It all seems good so far, however, if we were to try and access http://slash-root.local now in our browser, it would fail. Basically, our recursive nameserver doesn't know where slash-root.local is (what IP address to point us to!).
To add a record to our DNS service running on our router, all we need to do is the following:
data:image/s3,"s3://crabby-images/7f6b8/7f6b8f4f01cc8b369313e548bac5cc47fc6fc51b" alt="addrecord"
At this stage, lets just do a quick PING check from our router to slash-root.local to ensure its correct:
data:image/s3,"s3://crabby-images/bf1e2/bf1e25740613b93a00754d9a9b19d858cf6d5a16" alt="pingcheck"
Finally, lets now try to access http://slash-root.local using a browser on host1:
data:image/s3,"s3://crabby-images/a9be6/a9be654ce750b05820f96a340efb375bc3487520" alt="slashrootlocal"
When accessing slash-root.local in our browser, host1 will make a DNS query for slash-root.local, because we've added a record to point that domain name to the address 10.10.10.200 (host2), host1 can make a successful connection to the webserver using
a memorable domain name rather than host2's IP address.
As a final point, we would not normally run our internal DNS solution on our CISCO router, these are usually separate machines dealing purely with DNS.
Enquiries
Email: [email protected]
Copyright © 2023 - slash-root.com