Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Slow DNS after 22.05

    Scheduled Pinned Locked Moved DHCP and DNS
    270 Posts 31 Posters 133.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • bmeeksB
      bmeeks @domnado
      last edited by

      @domnado said in Slow DNS after 22.05:

      @bmeeks

      Unbound started acting up again, same error messages. I did make a change to the DNS Resolver settings, but only to the Network Interfaces section. I had to halt the system and unplug power for it to operate normally again.

      I think you tickled a clue there -- "make a change to the DNS Resolver settings, but only to the Network Interfaces section."

      What specifically did you change there? What setting was working versus what setting you changed it to that resulted in the error message?

      D 1 Reply Last reply Reply Quote 0
      • D
        domnado @bmeeks
        last edited by domnado

        @bmeeks

        At first "Network Interfaces" was set to ALL, first I changed it to everything but ALL (LAN, WAN IPv6 Link-Local, LAN IPv6 Link-Local, and Localhost), then I just changed it to LAN and Localhost. I also turned off both Prefetch options in Advanced Settings when I selected LAN and Localhost interfaces. Both changes were fine after a halt and power cord pull. The errors only started after clicking the Apply Changes button.

        1 Reply Last reply Reply Quote 0
        • J
          Jax
          last edited by

          I'm having the same problem with slow DNS after 22.05.
          I've had my setup (Netgate 2100) for over a year, everything has been fine.
          Suddenly DNS queries are timing out.
          No, I didn't change anything, other than to install the upgrade when prompted to do so.
          Any suggestions?

          M 1 Reply Last reply Reply Quote 0
          • M
            mihaifpopa @Jax
            last edited by

            @jax I moved to a virtualized OPNsense instance since the start of the thread. For now, having a better experience. No problems resolving DNS.

            J 1 Reply Last reply Reply Quote 1
            • J
              Jax @mihaifpopa
              last edited by

              @mihaifpopa said in Slow DNS after 22.05:

              virtualized OPNsense instance

              That's good. I'm on a Netgate device and I'd like it to go back to working correctly!

              R 1 Reply Last reply Reply Quote 0
              • R
                rcoleman-netgate Netgate @Jax
                last edited by

                @jax What are you seeing when you go to the Diagnostics->DNS Lookup page?

                Ryan
                Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                Requesting firmware for your Netgate device? https://go.netgate.com
                Switching: Mikrotik, Netgear, Extreme
                Wireless: Aruba, Ubiquiti

                J 2 Replies Last reply Reply Quote 0
                • J
                  Jax @rcoleman-netgate
                  last edited by

                  @rcoleman-netgate

                  First try: about a 9 second wait followed by the correct answer.
                  Second try: about a 22 second wait followed by the correct answer.

                  The pfSense display shows that 127.0.0.1 is timing out.
                  I have no idea why the Netgate device is querying itself.
                  As soon as it queries the next device upstream it gets an answer.

                  Name server 	Query time
                  127.0.0.1	938 msec
                  192.168.xx.xx	48 msec
                  
                  1 Reply Last reply Reply Quote 0
                  • J
                    Jax @rcoleman-netgate
                    last edited by

                    @rcoleman-netgate

                    Ha! In General Setup -> DNS Resolution Behavior I chose "Use remote DNS servers, ignore local DNS" and things look better now. We'll see if that fixes it.

                    R 1 Reply Last reply Reply Quote 0
                    • R
                      rcoleman-netgate Netgate @Jax
                      last edited by

                      @jax Sounds like DNS Resolver is stopped.
                      Go to the Service->DNS Resolver page and click the "start" icon in the header, of Status->Services and click it there.

                      FWIW reliance on the ISP DNS servers may result in being handed misleading DNS records. Remember when ISPs would resolve unresolving IPs and pass you to a search page? This helps you avoid that, among other things.

                      Ryan
                      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                      Requesting firmware for your Netgate device? https://go.netgate.com
                      Switching: Mikrotik, Netgear, Extreme
                      Wireless: Aruba, Ubiquiti

                      J 2 Replies Last reply Reply Quote 0
                      • J
                        Jax @rcoleman-netgate
                        last edited by

                        @rcoleman-netgate Okay, I restarted the DNS Resolver and have set the DNS Resolution Behavior back to use local DNS with fallback to remote. We'll see how this goes.

                        1 Reply Last reply Reply Quote 1
                        • Cool_CoronaC
                          Cool_Corona
                          last edited by

                          Do you run Suricata by any chance??

                          J 1 Reply Last reply Reply Quote 0
                          • J
                            Jax @Cool_Corona
                            last edited by

                            @cool_corona No, I don't.

                            1 Reply Last reply Reply Quote 0
                            • J
                              Jax @rcoleman-netgate
                              last edited by

                              @rcoleman-netgate Goes back to lousy performance. I've set it back to using remote DNS.

                              Cool_CoronaC 1 Reply Last reply Reply Quote 0
                              • Cool_CoronaC
                                Cool_Corona @Jax
                                last edited by

                                @jax Do you have any DNS specified in general settings??

                                J 1 Reply Last reply Reply Quote 0
                                • J
                                  Jax @Cool_Corona
                                  last edited by

                                  @cool_corona No, no specified DNS servers. It's just using the default, the upstream WAN DHCP-assigned server.

                                  Cool_CoronaC 1 Reply Last reply Reply Quote 0
                                  • Cool_CoronaC
                                    Cool_Corona @Jax
                                    last edited by

                                    @jax Can you pls. uncheck it

                                    c685d12f-9bc8-4dfa-86df-a5ac8f143816-billede.png

                                    No DNS server overrides and test again.

                                    R J 3 Replies Last reply Reply Quote 0
                                    • R
                                      rcoleman-netgate Netgate @Cool_Corona
                                      last edited by

                                      @cool_corona What package(s) are installed?

                                      Ryan
                                      Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
                                      Requesting firmware for your Netgate device? https://go.netgate.com
                                      Switching: Mikrotik, Netgear, Extreme
                                      Wireless: Aruba, Ubiquiti

                                      J 1 Reply Last reply Reply Quote 0
                                      • J
                                        Jax @Cool_Corona
                                        last edited by

                                        @cool_corona Trying it unchecked with local + fallback.

                                        1 Reply Last reply Reply Quote 1
                                        • J
                                          Jax @rcoleman-netgate
                                          last edited by

                                          @rcoleman-netgate no packages installed, just the default Netgate installation

                                          1 Reply Last reply Reply Quote 0
                                          • J
                                            Jax @Cool_Corona
                                            last edited by

                                            @cool_corona Testing with no dns server overrides as you suggested seems to give me the same good performance that was only achieved previously by bypassing the pfSense resolver.

                                            Can you explain this a little bit, please?

                                            Cool_CoronaC J 2 Replies Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.