Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Slow DNS after 22.05

    Scheduled Pinned Locked Moved DHCP and DNS
    270 Posts 31 Posters 136.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      Jax @Cool_Corona
      last edited by

      @cool_corona No, no specified DNS servers. It's just using the default, the upstream WAN DHCP-assigned server.

      Cool_CoronaC 1 Reply Last reply Reply Quote 0
      • Cool_CoronaC
        Cool_Corona @Jax
        last edited by

        @jax Can you pls. uncheck it

        c685d12f-9bc8-4dfa-86df-a5ac8f143816-billede.png

        No DNS server overrides and test again.

        R J 3 Replies Last reply Reply Quote 0
        • R
          rcoleman-netgate Netgate @Cool_Corona
          last edited by

          @cool_corona What package(s) are installed?

          Ryan
          Repeat, after me: MESH IS THE DEVIL! MESH IS THE DEVIL!
          Requesting firmware for your Netgate device? https://go.netgate.com
          Switching: Mikrotik, Netgear, Extreme
          Wireless: Aruba, Ubiquiti

          J 1 Reply Last reply Reply Quote 0
          • J
            Jax @Cool_Corona
            last edited by

            @cool_corona Trying it unchecked with local + fallback.

            1 Reply Last reply Reply Quote 1
            • J
              Jax @rcoleman-netgate
              last edited by

              @rcoleman-netgate no packages installed, just the default Netgate installation

              1 Reply Last reply Reply Quote 0
              • J
                Jax @Cool_Corona
                last edited by

                @cool_corona Testing with no dns server overrides as you suggested seems to give me the same good performance that was only achieved previously by bypassing the pfSense resolver.

                Can you explain this a little bit, please?

                Cool_CoronaC J 2 Replies Last reply Reply Quote 0
                • Cool_CoronaC
                  Cool_Corona @Jax
                  last edited by

                  @jax It overrides the WAN DHCP DNS provided by your ISP provider and that can take some speed out of the equation.

                  You dont have to handshake and verify the DNS by the ISP and oes directly to the 13 root DNS servers.

                  1 Reply Last reply Reply Quote 1
                  • J
                    Jax @Jax
                    last edited by

                    Hmm, there still seems to be weird intermittent slowness in name resolution.
                    I dunno. This may be beyond my personal ability to debug.

                    J 1 Reply Last reply Reply Quote 0
                    • J
                      Jax @Jax
                      last edited by

                      The slowness seems to be mostly focused on cdn services.

                      J 1 Reply Last reply Reply Quote 0
                      • J
                        Jax @Jax
                        last edited by

                        This is really quite frustrating, I'm not getting anywhere debugging this slowness problem.

                        bmeeksB A 2 Replies Last reply Reply Quote 0
                        • bmeeksB
                          bmeeks @Jax
                          last edited by bmeeks

                          @jax said in Slow DNS after 22.05:

                          This is really quite frustrating, I'm not getting anywhere debugging this slowness problem.

                          The first step in troubleshooting is to isolate the problem. Since you've tried a number of things on pfSense itself, why not take pfSense's DNS completely out of the picture?

                          1. Do this -- in the SYSTEM > GENERAL SETUP page, down in the DNS Settings area, put 8.8.8.8 (the Google DNS server IP) in the DNS Servers box. Save that change.

                          2. Next, go to SERVICES > DHCP SERVER and in Servers in the DNS Servers box also put 8.8.8.8. This will tell the DHCP server to give your LAN clients the Google DNS server for name resolution.

                          Now pfSense is out of the picture unless you have created any DNS related firewall rules previously. See how things behave with this test setup. If things are good, then you can assume you are having issues with unbound on your box when using the default settings. Those default settings configure the DNS Resolver to "resolver mode" and hand out the address of the pfSense box as the DNS server for your DHCP clients.

                          If things are still poor, then pfSense it likely not at fault here (assuming you don't have a firewall rule in the way), and you need to look elsewhere for the problem.

                          If you have any DNS related firewall rules, make sure you are allowing both UDP and TCP for port 53 as some DNS lookups will need to use TCP.

                          1 Reply Last reply Reply Quote 0
                          • V vaidas referenced this topic on
                          • V
                            vaidas
                            last edited by vaidas

                            I am too having problems after 22.05 upgrade with dns resolves timing out completely
                            unbound logs does not show any problems.
                            config haven't changed from 22.01 where dns worked perfectly.
                            running bare metal
                            plugins: openvpn client export, nut service for ups, watchdog that's it.

                            lohphatL 1 Reply Last reply Reply Quote 2
                            • J
                              Jax
                              last edited by

                              @bmeeks I took your suggestion and this morning things seem to be working better.
                              We'll see how things go on later in the day, thanks for your help.

                              J 1 Reply Last reply Reply Quote 0
                              • J
                                Jax @Jax
                                last edited by

                                @bmeeks of course this very much suggests pfSense DNS is indeed the problem.

                                bmeeksB 1 Reply Last reply Reply Quote 0
                                • bmeeksB
                                  bmeeks @Jax
                                  last edited by

                                  @jax said in Slow DNS after 22.05:

                                  @bmeeks of course this very much suggests pfSense DNS is indeed the problem.

                                  But it's not a widespread problem or the forum here would be overflowing with posts about it. There are only a few. Not saying there can't be a problem, but it's not affecting everyone it seems.

                                  It's entirely possible your virtualization environment could be at fault here as well. There could be an issue with the latest pfSense (FreeBSD) version and Proxmox.

                                  J 1 Reply Last reply Reply Quote 0
                                  • J
                                    Jax @bmeeks
                                    last edited by

                                    @bmeeks Thanks again for your help.

                                    I'm on a Netgate device that I purchased with pfSense already installed so no virtualization issues that would be unique to my setup. I have made no software modifications. There are many variables here:

                                    • pfSense DNS
                                    • pfSense DHCP interacting with desktop operating system
                                    • pfSense DNS interacting with service provider premises devices

                                    ... and so forth.

                                    In any case, the setup has been working for about 18 months for me, I personally made no changes and the problem seemed to emerge with pfSense 22.05. However, Correlation ≠ Causation as we all have been taught 🙄 So I suppose I will have to continue to gather clues and see what I can figure out over time 🤕 .

                                    bmeeksB 1 Reply Last reply Reply Quote 0
                                    • lohphatL
                                      lohphat @vaidas
                                      last edited by lohphat

                                      @vaidas I've come to report the same thing.

                                      I thought it was PfBlockerNG-devel but even with that off I'm seeing CDN content fail (e.g. YouTube). If I bypass unbound by using a client VPN, no problems.

                                      Seeing a lot of timeout and "domain not found" and have to manually reload pages to get them to load.

                                      No changes were made to the unbound settings between 22.01 and 22.05.

                                      SG-3100 24.11-RELEASE (arm) | Avahi (2.2_6) | ntopng (5.6.0_1) | openvpn-client-export (1.9.5) | pfBlockerNG-devel (3.2.1_20) | System_Patches (2.2.20_1)

                                      J 1 Reply Last reply Reply Quote 0
                                      • J
                                        Jax @lohphat
                                        last edited by Jax

                                        @lohphat Yes, I'm seeing the same thing, that the problem seems to be mostly with cdn site resolution.

                                        1 Reply Last reply Reply Quote 0
                                        • bmeeksB
                                          bmeeks @Jax
                                          last edited by bmeeks

                                          @jax said in Slow DNS after 22.05:

                                          @bmeeks Thanks again for your help.

                                          I'm on a Netgate device that I purchased with pfSense already installed so no virtualization issues that would be unique to my setup.

                                          Sorry, I confused your post with another at the top of this thread where the OP said they were running on Proxmox.

                                          I see where you said you were running on an SG-2100. That is an ARM-based appliance (not Intel). Another poster in this thread has an SG-3100 in his signature. That is also an ARM-based appliance. Could be an issue with the latest unbound version and ARM hardware. I did notice that when my SG-5100 updated it pulled down a new unbound version as part of the upgrade. I've not seen any issue on my SG-5100, but it is Intel-based hardware.

                                          There have, in the past, been some weird issues with software running on ARM hardware due in part to some quirkiness with the llvm compiler used.

                                          J 1 Reply Last reply Reply Quote 1
                                          • J
                                            Jax @bmeeks
                                            last edited by

                                            @bmeeks Thanks again for clarifying ... @rcoleman-netgate do you have any further observations on this issue? It does seem to be Netgate-specific.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.