Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfsense blocking certain/some sites

    Scheduled Pinned Locked Moved General pfSense Questions
    74 Posts 7 Posters 13.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      viragomann @Gurveer
      last edited by

      @gurveer
      I tried to explain above in a view words.
      By default the DNS Resolver used root DNS servers (https://www.iana.org/domains/root/servers) to resolve DNS requests.

      However, in forwarding mode it sends request to the servers you've stated in general setup, to 1.1.1.1 in your case.

      There should be reason for the root servers not working. Maybe restrictions in your country, I don't know.

      1 Reply Last reply Reply Quote 0
      • bingo600B
        bingo600 @Gurveer
        last edited by bingo600

        @gurveer

        On the screenshot above this is clearly in error

        34a381d3-c139-4793-a0ca-74527e16b321-image.png

        linux:~$ host 1.1.1.1
        1.1.1.1.in-addr.arpa domain name pointer one.one.one.one.
        
        linux:~$ host cloudflare-dns.com
        Host cloudflare-dns.com not found: 3(NXDOMAIN)
        

        And as suggested
        Disable forwarding , Remote DNS servers and let pfSense resolve directly.

        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

        pfSense+ 23.05.1 (ZFS)

        QOTOM-Q355G4 Quad Lan.
        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

        stephenw10S G 2 Replies Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator @Gurveer
          last edited by

          @gurveer said in pfsense blocking certain/some sites:

          it worked (tho disabled dns resolver )

          You mean you disabled the resolver (Unbound) and enabled the forwarder (DNSMasq)?

          If so that shouldn't be required and probably indicates some underlying issue.

          Steve

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator @bingo600
            last edited by

            @bingo600 said in pfsense blocking certain/some sites:

            On the screenshot above this is clearly in error

            Ah, well spotted. Yes if DoT is enabled that would be an issue. Though I would expect it to break everything not just that site

            1 Reply Last reply Reply Quote 0
            • G
              Gurveer @bingo600
              last edited by

              @bingo600 removed the cloudflare-dns.com but nothing happened site still not working (enabled dns resolver ,disabled forwarder)

              bingo600B 1 Reply Last reply Reply Quote 0
              • bingo600B
                bingo600 @Gurveer
                last edited by bingo600

                @gurveer
                Remove the 1.1.1.1 too

                @stephenw10
                1: I'd expect the "bad domain" to affect all DOT lookups.

                2:
                As i read it , with the current selection , the local (127.0.0.1) should take precedence , and just use the 1.1.1.1 stuff if the local fails to resolve correct ?
                Since pfSense should be able to resolve, the 1.1.1.1 stuff should not be used at all.

                @Gurveer
                The DNS Resolver is also called "Unbound ... The program name"
                The settings are here Services --> DNS Resolver

                d2b64fd5-f176-447d-8b1a-c3492021f719-image.png

                What does your config look like there ??

                All of it ?

                If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                pfSense+ 23.05.1 (ZFS)

                QOTOM-Q355G4 Quad Lan.
                CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                G 2 Replies Last reply Reply Quote 0
                • G
                  Gurveer @bingo600
                  last edited by Gurveer

                  @bingo600 still same , stopped resolving portal.bsnl.in and portal.bsnl.in but opens using https://117.239.179.10/

                  bingo600B 1 Reply Last reply Reply Quote 0
                  • bingo600B
                    bingo600 @Gurveer
                    last edited by

                    @gurveer
                    Read my "above post" again , i asked something else.

                    What is the ip address of the PC , that is not resolving ?
                    Is it located within your Lan ip range ?

                    If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                    pfSense+ 23.05.1 (ZFS)

                    QOTOM-Q355G4 Quad Lan.
                    CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                    LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                    G 1 Reply Last reply Reply Quote 0
                    • G
                      Gurveer @bingo600
                      last edited by

                      @bingo600 it ditto same as yours

                      bingo600B 1 Reply Last reply Reply Quote 0
                      • bingo600B
                        bingo600 @Gurveer
                        last edited by

                        @gurveer
                        But there is MUCH more below

                        Show it all

                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                        pfSense+ 23.05.1 (ZFS)

                        QOTOM-Q355G4 Quad Lan.
                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                        1 Reply Last reply Reply Quote 0
                        • G
                          Gurveer @bingo600
                          last edited by

                          @bingo600 ya its in lan ip range and non of device opens this site

                          bingo600B 1 Reply Last reply Reply Quote 0
                          • bingo600B
                            bingo600 @Gurveer
                            last edited by bingo600

                            @gurveer
                            If you don't show the Full Resolver config, we have no way of helping you further.

                            See : https://forum.netgate.com/post/1064462

                            And in Status --> Services is unbound running (the Green Dot)

                            1297f065-56a6-44f6-99fc-ba77f15fae59-image.png

                            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                            pfSense+ 23.05.1 (ZFS)

                            QOTOM-Q355G4 Quad Lan.
                            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                            G 1 Reply Last reply Reply Quote 0
                            • stephenw10S
                              stephenw10 Netgate Administrator
                              last edited by

                              That. Also please show the full output of Diag > DNS Lookup against one of the failing sites.

                              That test checks all configured DNS servers, so Unbound resolving locally plus any you added in Sys > Gen. Setup plus anything passed by DHCP. But clients only use Unbound (by default).
                              So if Diag > Lookup succeeds but clients cannot resolve it's probably because Unbound is failing but some other server is allowing pfSense to resolve that. The full output would show it.

                              Steve

                              G 1 Reply Last reply Reply Quote 0
                              • G
                                Gurveer @bingo600
                                last edited by

                                @bingo600 ya its in lan ip range and non of device opens this site also if its fine by you i have no problem giving remote access !
                                Screenshot 2022-10-04 at 12.09.25 AM.png Screenshot 2022-10-04 at 12.10.05 AM.png Screenshot 2022-10-04 at 12.10.38 AM.png Screenshot 2022-10-04 at 12.15.41 AM.png Screenshot 2022-10-04 at 12.16.19 AM.png Screenshot 2022-10-04 at 12.17.41 AM.png

                                1 Reply Last reply Reply Quote 0
                                • G
                                  Gurveer @stephenw10
                                  last edited by

                                  @stephenw10 here it isScreenshot 2022-10-04 at 12.32.32 AM.png

                                  bingo600B 1 Reply Last reply Reply Quote 0
                                  • bingo600B
                                    bingo600 @Gurveer
                                    last edited by

                                    @gurveer

                                    Is unbound running ?
                                    See here
                                    https://forum.netgate.com/post/1064464

                                    Btw: Your Unbound config looks fine to me

                                    If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                    pfSense+ 23.05.1 (ZFS)

                                    QOTOM-Q355G4 Quad Lan.
                                    CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                    LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                    G 1 Reply Last reply Reply Quote 0
                                    • G
                                      Gurveer @bingo600
                                      last edited by

                                      @bingo600 said in pfsense blocking certain/some sites:

                                      https://forum.netgate.com/post/1064464

                                      yup Screenshot 2022-10-04 at 12.36.50 AM.png

                                      bingo600B 1 Reply Last reply Reply Quote 0
                                      • bingo600B
                                        bingo600 @Gurveer
                                        last edited by

                                        @gurveer
                                        Now things get "hairy" .....

                                        I see no reason why unbound shouldn't resolve that : portal.bsnl.in

                                        In diag --> Dns lookup , can you resolve ie. google.com or cnn.com or bbc.co.uk

                                        If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

                                        pfSense+ 23.05.1 (ZFS)

                                        QOTOM-Q355G4 Quad Lan.
                                        CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
                                        LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

                                        G 1 Reply Last reply Reply Quote 0
                                        • G
                                          Gurveer @bingo600
                                          last edited by

                                          @bingo600 all three got resolved

                                          1 Reply Last reply Reply Quote 0
                                          • stephenw10S
                                            stephenw10 Netgate Administrator
                                            last edited by

                                            Hmm, curious. I have one VM here that fails to resolve those. If I turn up the logging to level to 3 I see:

                                            Oct 3 20:59:53 	unbound 	40999 	[40999:1] info: validator operate: query portal2.bsnl.in. A IN
                                            Oct 3 20:59:53 	unbound 	40999 	[40999:1] debug: cache memory msg=36309 rrset=50168 infra=10801 val=35656
                                            Oct 3 20:59:53 	unbound 	40999 	[40999:0] error: read (in tcp s): Connection refused for 218.248.240.178 port 53
                                            Oct 3 20:59:53 	unbound 	40999 	[40999:0] debug: outnettcp got tcp error -1 
                                            

                                            But other VMs configured identically and using the same public IP work fine.. šŸ¤”

                                            bingo600B 1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.