• WAN_DHCP6 Pending/Unknown

    2
    0 Votes
    2 Posts
    787 Views
    T

    @beremonavabi I'm in the exact same boat with Comcast as the ISP.

    Trigger seems to be a loss of upstream connection. IPv4 recovers, IPv6 does not.

    Remedy is to Save WAN and Apply Changes. No actual change is required.

    If I could figure out what part of Applying Changes fixes the issue, I could automate recovery.

  • DNS Resolver problems 2.5.0 (Solved)

    6
    0 Votes
    6 Posts
    771 Views
    VioletDragonV

    @noplan Hi, Sorry for a late reply i have been a bit busy today, so the problem was certain websites wasn't resolving had to refresh the page a few times for it to load but three.co.uk would not load completely but on my phone it would then wouldn't but the IP my Firewall and Workstation resolves too is totally different than my phone resolves too but problem seems to be with three than my Firewall. Since updating Unbound problems are solved but three website is still kinda broken. I think its time i change mobile phone carriers because this network has always had problems.

    Where do i mark as (solved) ?

    Update, Don't worry i've just found the way to mark it.

    Thanks.

    Jack.

  • DNS refused

    2
    0 Votes
    2 Posts
    333 Views
    JKnottJ

    @jknott

    Never mind. I found the fix. Apparently, the DNS server doesn't like ULA addresses, so I had to create an Access list, to allow my ULA prefix.

    Any idea why the resolver won't accept a ULA prefix that it's on?

  • Unbound Connection Refused Logs

    1
    1 Votes
    1 Posts
    593 Views
    No one has replied
  • DDNS upadate to Cloudflare DNS will fail using: Enable Proxy (Cloudflare)

    15
    1 Votes
    15 Posts
    3k Views
    P

    @wepee I switched over to cloudflare and noticed i when proxy is enabled = No Joy, if proxy is disable everything is normal. Is this still an on going bug/problem on pfsense?

  • 2.5 Dynamic DNS not working

    2
    0 Votes
    2 Posts
    254 Views
    K

    I managed to resolve this by replacing what I originally had under "host" with *

  • Rogue machine using gateway ip as the static ip

    3
    0 Votes
    3 Posts
    313 Views
    bmeeksB

    @trumee said in Rogue machine using gateway ip as the static ip:

    Hello,
    Is there a way to block any machine which sets up such a static ip?

    One thing folks new to networking often fail to remember is that the firewall has zero control over local network traffic in a segment. So on your LAN, for example, if device A wants to talk with device B on the same subnet, the firewall is completely out of the picture and powerless to control the behavior of either device A or device B. Same thing applies in your case with a device "stealing" the IP of the firewall. Nothing the firewall can do but complain in its logs (which it did). It is then up to the human to find the offender and cut him off (using the suggestions from @bingo600).

  • DNS Resolver crashes/stops

    5
    0 Votes
    5 Posts
    1k Views
    aaronsshA

    @bloodfilledwater thank you!!

  • Rouge dhcp server on WAN

    8
    0 Votes
    8 Posts
    688 Views
    I

    See solution:
    https://forum.netgate.com/topic/141362/dhcp-client-unable-to-get-lease-from-cable-provider-solved/4?_=1614433865506

  • Unbound Resolver not working with Nextiva desktop App or Ring Central app

    5
    0 Votes
    5 Posts
    762 Views
    GertjanG

    @nicholsnt

    What are you 'looking up' ?
    Not every time a host name is used (to be resolved), a complete DNS lookup is performed.
    The application can cache the DNS answer.
    Your local OS can and will cache the answer.
    unbound will cache the answer.

    How long ? This is determined by the so called the 'TTL' or Time to Live' or the time it should stay valid in the (a) cache. Something like 2 hours is normal.

    So, no problem if you try to resolve 1 million times per second a host name like microsoft.com : it will 'resolve' in less time, as it is cached (locally).

    @nicholsnt said in Unbound Resolver not working with Nextiva desktop App or Ring Central app:

    just something with the many lookups

    You'll be needing thousands of devices (PC's) to do that.
    Or only using domains that have a 1 second TTL.

    @nicholsnt said in Unbound Resolver not working with Nextiva desktop App or Ring Central app:

    Can I create a static entry in the pfsense for each of those aliases to perhaps negate the lookups?

    7c81cb2b-694f-4a9f-88e8-fcac488a978d-image.png

    On the Unbound settings page. As many as you like.

  • Can't connect to bind 9 DNS server configured on VPS?

    1
    0 Votes
    1 Posts
    76 Views
    No one has replied
  • How to connect DNS server on VPS?

    1
    0 Votes
    1 Posts
    80 Views
    No one has replied
  • 21.02-RELEASE - unable to force unbound upgrade to 1.13.1

    Moved
    9
    0 Votes
    9 Posts
    2k Views
    S

    @jimp This is why we love you. Thanks for your insight and guidance!

  • Can DNS Forwarder implement views like Bind?

    5
    0 Votes
    5 Posts
    470 Views
    D

    @nogbadthebad Thanks. I really love that pfSense has an implement to pull this off. The trouble with this is I need to train "non command line" folks on how to make changes too. If it's not a web browser, they'll get all sweaty. Having them make line edits containing quotes and colons is just not going to go well. I appreciate you taking the time to noodle this out though. My pfSense knowledge isn't exactly guru level.

  • DHCP Server max interfaces of 4 since 21.02-RELEASE-p1

    3
    0 Votes
    3 Posts
    501 Views
    No one has replied
  • DNS Unbound errors - No route to host --IPv6

    14
    0 Votes
    14 Posts
    2k Views
    GertjanG

    @suudoxr said in DNS Unbound errors - No route to host --IPv6:

    do I need to be looking at why something on my LAN is trying to go out to IPv6?

    Something on your LAN - a device that is IPv6 capable - would try to use pfSense if pfSense would announce on your LAN that it is a IPv6 gateway.

    Which isn't the case, because you do not have a IPv6 connection to the net.

    This doesn't mean that many devices on your LAN use IPv6 among themselves, as any modern OS prefers IPv6 over IPv4.

  • Home server behind PFSense (using cloudflare) SSL certs breaking

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Tunnel Unbound through OpenVPN client, if available

    1
    0 Votes
    1 Posts
    758 Views
    No one has replied
  • DNS Issue After Upgrade to 21.02 - Release - p1 (arm)

    4
    0 Votes
    4 Posts
    417 Views
    G

    Is it this?

    https://forum.netgate.com/topic/160969/upgrade-to-21-02-release-borked-on-sg-3100/46

  • DNS Resolver returning incorrect result

    3
    0 Votes
    3 Posts
    951 Views
    kohenkatzK

    Seems like some other users of DNS-based filtering have already found this problem in Unbound.

    It looks like they might do something about it for DoT queries at some point, but there hasn't been much activity on that issue.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.