Wireless guest have no connectivity in the DMZ

Hi,
I am deploying a new wireless setup with two 2504 controllers, one for the corporate ssid and one for guest segment.
The anchor controller used for web-authentication has 1 leg in the inside network (10.x.x.x) and 1 leg in the dmz 192.168.100.x (to ASA 5515 v9.0) on the 192.168.100.0 /24 range.
The ASA has internal and external context.
The Mobility tunnel is up.
The ASA is doing DHCP, and the hosts receive IP addresses and (public) DNS 173.194.67.94.
Problem is the hosts cannot do DNS lookup and thus no redirection to the web-portal.
The ASA shows no denies. When I ping the DNS from the Anchor controller, I see the following.
Jul 11 2013 07:44:17: %ASA-6-302020: Built outbound ICMP connection for faddr 173.194.67.94/0 gaddr 10.101.114.172/815 laddr 10.101.114.172/815
Jul 11 2013 07:44:19: %ASA-6-302021: Teardown ICMP connection for faddr 173.194.67.94/0 gaddr 10.101.114.172/815 laddr 10.101.114.172/815
A packet sniffer shows that hosts connected send DNS requests and never get anything back.
How should approach this issue from here?

Hi,
after some changes, the WLC can now reach the public DNS server.
However, the hosts cannot do anything. (no nslookup, no ping)
I removed web-authentication from the WLAN config to simplify troubleshooting, but even so, the result is the same.
Host receives IP address and DNS server.
When I do a packet tracer on the outside context, from the guest (wifi) segment to the DNS, I see the packet is dropped.
Phase: 2
Type: ACCESS-LIST
Subtype:
Result: DROP
Config:
Implicit Rule
my config is:
object network Guest_wireless
subnet 192.168.100.0 255.255.255.0
access-list GUEST extended permit ip object Guest_wireless any
access-list GUEST extended permit icmp object Guest_wireless any
access-group GUEST in interface Guest_wireless
interface GigabitEthernet0/3.2
nameif Guest_wireless
security-level 40
ip address 192.168.100.254 255.255.255.0 standby 192.168.100.253
object network Guest_wireless
nat (dmz,outside) dynamic "public ip"
Thanks

Similar Messages

Maybe you are looking for

  • How can I find out the percentage of space taken up by a vector in a document?

    Hi all, I've been doing visual research over the last couple of years, and part of this has resulted in hundreds of in-design documents with vectors of varying sizes in each. Essentially, I'm hoping to find a quick way to find out the percentage of s

  • Laptop freezes.. .slowly...

    I already had my system board (main board)replaced due to the bsod and now that I have gotten it back I have tihs new problem. Occasionally I'll be using the laptop and a program will crash, which is fine so I try to go to the task manager. I ctrl-al

  • Does iPad 1 support Facetime?

    Hello, I know the 1st gen iPad doesn't have the cameras. But is it still possible to support the Facetime, I mean to receive the video/audio from the other user and send only audio out? Thanks!

  • Extending DAM Asset Editor formitems and grouping new fields into a widgetcollection

    Hi, I'm a newbie so be kind pretty please... We have a requirement for one of the websites hosted on our CQ instance to have some extended DAM properties for PDF files. Eg. Summary (textfield) and Search Weighting (selection) We have added a new name

  • The following import prerequisites of OCS Package " " have not been met

    Hi SAP gurus,          Am in upgrading ECC 6.0 to EHP4. in th configuration Phase am facing this erro: " Severe error(s) occured in phase PREP_EXTENSION/SUBMOD_EXTENSION_NEW/EHP_INCLUSION! Last error code set: unable to generate package queue, return