Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Resolver not working for Link-Local addresses

    Scheduled Pinned Locked Moved IPv6
    9 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      son1c
      last edited by son1c

      Hi,

      I use Pfsense 22.01 Home Edition and the DNS Resolver over the link-local address which doesn't work.
      The IPv4 addresses and the global-unicast address work fine.

      The Network Interfaces setting in the DNS Resolver tab is set to all and there are no firewall rules set who will block the requests.

      Cu
      son1c

      JKnottJ johnpozJ 2 Replies Last reply Reply Quote 0
      • JKnottJ
        JKnott @son1c
        last edited by

        @son1c

        Given you don't normally use link local addresses for carrying app data etc. why do you want them in DNS?

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @son1c
          last edited by johnpoz

          @son1c said in DNS Resolver not working for Link-Local addresses:

          there are no firewall rules set who will block the requests.

          Did you change source from say lan net to any? By default the IPv6 lan net any rule for internet would not allow link-local..

          Also I do not believe the automatic access list for unbound would include link-local..

          I also not sure why anyone would want to do this - but it does work.. So I enabled a IPv6 any rule for source vs just lan net.

          So I can ping pfsense link-local address.

          ping.jpg

          But you can see got back refused for dns query.

          rfused.jpg

          I then edited the access list to allow for link local address..

          accesslist1.jpg

          And now I can query the linklocal address

          dnsquery.jpg

          But just at a loss to actual use case for this to be honest.. But it works if you allow for it.

          But default lan net IPv6 would not include linklocal network, nor would the default access lists in unbound.. I have always used my own access lists, but if lan net doesn't include the link local space, I doubt the auto access lists would..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

          1 Reply Last reply Reply Quote 1
          • S
            son1c
            last edited by

            Thank you for your help!

            I use a DNS Filter, so my goal was to forward the DNS querys to the pfsense.
            This should be no problem but my internet connection is over DSL, so every time the modem reconnects I get new ipv6 prefixes from my provider. That's why I need a static IP address to forward.

            johnpozJ JKnottJ 2 Replies Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @son1c
              last edited by

              @son1c why would you not just forward to your IPv4 address - does that change as well?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              S 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @son1c
                last edited by

                @son1c said in DNS Resolver not working for Link-Local addresses:

                This should be no problem but my internet connection is over DSL, so every time the modem reconnects I get new ipv6 prefixes from my provider. That's why I need a static IP address to forward.

                You can use Unique Local Addresses. I use them here, even though my prefix doesn't change.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                S 1 Reply Last reply Reply Quote 1
                • S
                  son1c @johnpoz
                  last edited by

                  @johnpoz no, i just want try a ipv6 only setup

                  johnpozJ 1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator @son1c
                    last edited by

                    @son1c said in DNS Resolver not working for Link-Local addresses:

                    no, i just want try a ipv6 only setup

                    Well good luck with that - you understand your not going to be able to get to MOST of the internet ;)

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 1
                    • S
                      son1c @JKnott
                      last edited by

                      @jknott I see, i need to take a closer look to the virtual IP settings

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.