Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Resolver and Forwarder not Working

    Scheduled Pinned Locked Moved DHCP and DNS
    17 Posts 5 Posters 1.6k Views 5 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      tactilebiscuit4 @SteveITS
      last edited by

      @steveits I have firewall rules like the image for LAN OPT1 and OPT2.
      5e20089a-339b-49da-bcb5-2ef9e0da5861-image.png

      Network interfaces is set to all and Forwarding is off currently, but doesn't fix the issue when its on.

      1 Reply Last reply Reply Quote 0
      • V Offline
        viragomann @tactilebiscuit4
        last edited by

        @tactilebiscuit4
        Did you mess with the outbound NAT?

        T 1 Reply Last reply Reply Quote 0
        • T Offline
          tactilebiscuit4 @viragomann
          last edited by

          @viragomann I haven't messed with it at all. It's still the default setting.

          V 1 Reply Last reply Reply Quote 0
          • V Offline
            viragomann @tactilebiscuit4
            last edited by

            @tactilebiscuit4
            Did you also state the Cloudflare and Googel server in System > General Setup?

            What if you try to resolve a host name on pfSense in Diagnostics > DNS Lookup?

            What do you get if you resolve a name with nslookup on Windows? What is the responding server?

            T 1 Reply Last reply Reply Quote 0
            • GertjanG Offline
              Gertjan @tactilebiscuit4
              last edited by

              @tactilebiscuit4

              Your image is strange.

              A modem in bridge mode on the left side.
              The line between this modem goes to the pfSense box : to it's WAN interface.
              What is the other WAN round circle in the right bottom corner ?

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator @Gertjan
                last edited by

                @gertjan said in DNS Resolver and Forwarder not Working:

                What is the other WAN round circle in the right bottom corner ?

                Good question ;)

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                T 1 Reply Last reply Reply Quote 0
                • T Offline
                  tactilebiscuit4 @viragomann
                  last edited by

                  @viragomann I did set them in General Setup. I get the below picture when doing DNS lookup from the pfsense box. 8c514b9a-563d-4cba-bc4d-79824c3710f9-image.png

                  On windows it gives me the IP of the PFSense router but doesn't resolve the hostname of my router and then tells me the DNS request timed-out.

                  S 1 Reply Last reply Reply Quote 0
                  • T Offline
                    tactilebiscuit4 @johnpoz
                    last edited by tactilebiscuit4

                    @johnpoz @gertjan Sorry its my poor diagraming skills lol. I was thinking about the 4 ports on the box and didn't think out how that looked. d07b861b-cf3a-43a5-9491-3c93fe6de720-image.png

                    Modem is plugged into the WAN port and getting a valid Public IP

                    GertjanG 1 Reply Last reply Reply Quote 0
                    • GertjanG Offline
                      Gertjan @tactilebiscuit4
                      last edited by

                      @tactilebiscuit4

                      Ok, that looks pretty basic to me.
                      I have nearly the same setup, with the exception my ISP device is a router, delivering a RFC1918 like "192.168.10.3" as a WAN IP to my pfSense.
                      When setting up pfSense it has initially just a LAN (no OPTx) and a WAN.
                      Just giving it a host name, a domain name and leaving the DNS server list empty :

                      a74dd599-0e5f-4431-a0bc-ace1f2130cf1-image.png

                      and everything start to work.

                      A less known secret is (and please keep this for yourself) is that pfSense is like every other router you can buy out there.
                      I presume you had to chose as a WAN access the "pppoe" mode, and enter a ISP user + password. And that's it, DNS will start working. pfSense will work.

                      Now you can create your OPTx interfaces like this :

                      4c54cd62-adf5-4e6d-9eda-55455ad81bb8-image.png

                      and define a pass firewall rule for these interfaces.
                      Then add a DHCP server instance for these interfaces with a IP pool.
                      And done.

                      No "help me" PM's please. Use the forum, the community will thank you.
                      Edit : and where are the logs ??

                      T 1 Reply Last reply Reply Quote 0
                      • S Offline
                        SteveITS Rebel Alliance @tactilebiscuit4
                        last edited by

                        @tactilebiscuit4 Can pfSense traceroute to 8.8.8.8? (Diagnostics menu)

                        Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to reboot, or more depending on packages, and device or disk speed.
                        Upvote 👍 helpful posts!

                        T 1 Reply Last reply Reply Quote 0
                        • T Offline
                          tactilebiscuit4 @SteveITS
                          last edited by

                          @steveits 91e6e0e2-a0de-472e-a10a-649b5443c6d2-image.png

                          It can traceroute Googles DNS IP

                          1 Reply Last reply Reply Quote 0
                          • T Offline
                            tactilebiscuit4 @Gertjan
                            last edited by

                            @gertjan Right, I have done that. However, I didn't set up the WAN interface with PPPoE. I set it using DHCP. It gets the correct Public IP. The DNS didn't work even before I set up my OPT1 and OPT2 interfaces. I have a 1200 mbit connection with Xfinity.

                            V GertjanG 2 Replies Last reply Reply Quote 0
                            • V Offline
                              viragomann @tactilebiscuit4
                              last edited by

                              @tactilebiscuit4
                              Can you please post the outputs of

                              ifconfig
                              

                              and also of

                              dig @8.8.8.8 google.com
                              
                              1 Reply Last reply Reply Quote 0
                              • GertjanG Offline
                                Gertjan @tactilebiscuit4
                                last edited by

                                @tactilebiscuit4 said in DNS Resolver and Forwarder not Working:

                                I set it using DHCP.

                                Have you checked (set) this option on the General > System setup page :

                                fe206c0f-3747-4d5c-b273-60a574fc3d1d-image.png

                                ?

                                Is there a open access to "all internet addresses", port 53, protocol UDP and TCP ?

                                No "help me" PM's please. Use the forum, the community will thank you.
                                Edit : and where are the logs ??

                                T 1 Reply Last reply Reply Quote 0
                                • T Offline
                                  tactilebiscuit4 @Gertjan
                                  last edited by

                                  @gertjan @johnpoz @viragomann @SteveITS I seem to have fixed the issue over the weekend. I am not sure what was wrong but re-installing with the newest version allowed me to use the DNS Resolver. I was using an older version. But installing with 2.6.0 fixed the issue for me. I did notice, however, that when rebooting with the older version, the DNS Resolver service was taking a while to start up. I never actually chekced the services running on the router so its possible that the service was just not able to start. I did "Restart" the service through the Web GUI a few times and it never gave me any indication that it didn't work. Its possible the service was not actually started or in a hung state. Thanks for all your help though, really appreciate all the responses!

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.