Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Encrypt DNS unable to resolve

    Scheduled Pinned Locked Moved DHCP and DNS
    15 Posts 3 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @Peter_APIIT
      last edited by johnpoz

      @peter_apiit And again - Lets see your settings... You sure your client even pointing to pfsense for dns?

      From that test, you didn't use cloudflare at all.. Are you routing through a vpn? Do you have a router in front of pfsense, your isp doing interception?

      Where was the sniff showing what is going on when you query pfsense, etc..

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      P 1 Reply Last reply Reply Quote 0
      • P
        Peter_APIIT @johnpoz
        last edited by Peter_APIIT

        @johnpoz

        e302ad4e-488a-4c16-a2f5-ab5abf3ec8b1-image.png

        I don't have router in front of pfsense. I don't use VPN at all. I don't know whether my ISP doing interception to see my browsing history.

        Where was the sniff showing what is going on when you query pfsense, etc..
        What u mean by this?

        1c1353e1-0dd1-4c05-93ff-4a5c42e951c9-image.png

        johnpozJ GertjanG 2 Replies Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @Peter_APIIT
          last edited by

          @peter_apiit why do you have those others in there?

          Just set cloudflare, or other dot enabled services. But I would start with just the 1 to make sure its working.

          Under diagnostic menu, the packet capture..

          Why do you have 127.0.0.1 listed there?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          P 1 Reply Last reply Reply Quote 0
          • P
            Peter_APIIT @johnpoz
            last edited by

            @johnpoz Let me remove the others dns service.

            1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @Peter_APIIT
              last edited by

              @peter_apiit

              My pfSense DNS/Resolver worked just fine from day one. Never had anything to change. I guess I've enforced DNSSEC on my initiative.

              Step one :

              54d57668-d086-4580-b3bd-d6e69531e69c-image.png

              Step two : resolvers settings :

              bbb52f18-f2ed-4465-b795-ba5dcf108c77-image.png

              Step three : I de activated pfBlockerNG-devel as I normally block all these :

              02a7593f-6ab1-4440-b627-f7de19628366-image.png

              Note that by default "pfBlockerNG-deve" isn't present on pfSense, so this step is optional.

              I tested :

              4b157ed7-a93c-47a4-bb1c-524a89acfc64-image.png

              So, it works for me : forwarding to 1.1.1.1 using DNS over TLS (port 853).

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              P 2 Replies Last reply Reply Quote 1
              • P
                Peter_APIIT @Gertjan
                last edited by

                @gertjan After removed all others dns services, the dns over tls is working as show in the pic.

                22393d91-83e1-4569-9978-d880bc623de0-image.png

                1 Reply Last reply Reply Quote 0
                • P
                  Peter_APIIT @Gertjan
                  last edited by

                  @gertjan Anything i can do to secure my DNS query process except the one that I did?

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @Peter_APIIT
                    last edited by

                    @peter_apiit said in Encrypt DNS unable to resolve:

                    secure my DNS query

                    From who for why?

                    You do understand your isp still knows where you go, IP, and even your https has the clear fqdn right there for them to see, just like your dns query..

                    Your not actually hiding anything from you isp doing your dns over a tunnel.

                    Until such time that esni actually is a thing and deployed across the internet.. Well now ECH because esni died before it really got any traction. While you can hide the actual dns query from them, they still know exactly where your going via the clear sni sent when you make your https connection.

                    encrypted dns is more about circumvention, be it your isp was doing interception of dns. Or bypassing your local dns by doing doh..

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    P 1 Reply Last reply Reply Quote 0
                    • P
                      Peter_APIIT @johnpoz
                      last edited by Peter_APIIT

                      @johnpoz I want to secure the DNS query process from my ISP because I suspect my ISP seeing my browse website history so I want to completely hide it.

                      May I know what is the step to configure this process?

                      johnpozJ 1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator @Peter_APIIT
                        last edited by johnpoz

                        @peter_apiit said in Encrypt DNS unable to resolve:

                        ISP seeing my browse website history so I want to completely hide it.

                        Which your not with encrypted dns.. because while they don't see the dns query - they still see where you go via IP when or the actual sni included in the https handshake that is in the clear..

                        It is trivial for a company that was sniff your dns traffic, to just sniff https and get the sni, etc.

                        The only way to hide where you actually go from your isp is a vpn.. Then all they see is the amount of traffic between you and the vpn service IP. But that is just handing off trust from your isp to the vpn service, etc. And then paying them too boot ;)

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.