Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS check

    Scheduled Pinned Locked Moved DHCP and DNS
    7 Posts 3 Posters 804 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      stgeorge
      last edited by

      I'm running pFsense 2.6.0 on a protectli vault FW4B and have the Cloudlare DNS'es (1.1.1.1 + 1.0.0.1) in the DNS settings but when I check which DNS is getting pinged via IPLeak.net, it's showing that my system is using my ISP's DNS ? Am I missing something here ? Do certain devices on my LAN (e.g. Windows pc) ignore the DNS settings in pFsense? Perhaps I don't understand IPLeak.net that well?

      V GertjanG 2 Replies Last reply Reply Quote 0
      • V
        viragomann @stgeorge
        last edited by

        @stgeorge
        You should explain your DNS settings on pfSense. By default pfSense has the DNS Resolver enabled and provide it to the internal devices.
        The Resolver uses root servers to resolve host names.

        If you have enabled the forwarding mod in the DNS resolver, requests are forwarded to the servers stated in System > General.
        If "DNS Server Override" is checked there, the DNS entries you did can be overridden by the ISP.

        Also set "DNS Resolution Behavior" to your desired value.

        1 Reply Last reply Reply Quote 0
        • GertjanG
          Gertjan @stgeorge
          last edited by

          @stgeorge said in DNS check:

          Do certain devices on my LAN (e.g. Windows pc) ignore the DNS settings in pFsense?

          Only you can tell ...

          @stgeorge said in DNS check:

          Perhaps I don't understand IPLeak.net that well?

          dns forwarding has nothing to do with what IPLeak.net can show you.

          Btw : dns forwarding isn't the default setting.
          Resolving is.

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          S 1 Reply Last reply Reply Quote 0
          • S
            stgeorge @Gertjan
            last edited by

            @gertjan and @viragomann - Thanks for the comments- I think it's pretty clear that I need to learn more about DNS Resolver. I do not have 'DNS Server Override' checked, but I seem to recall not liking seeing the default 127.0.0.0 listed in my DNS prefs, so I somehow removed it. Don't laugh- I'm still learning! ;-) How can I reset the resolver so that it's working properly? Thanks.

            GertjanG 1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan @stgeorge
              last edited by

              @stgeorge

              Default :

              710f6e7d-f4d7-4603-82b2-0732ba62254d-image.png

              which means you'll see this :

              c2d68162-d717-4608-9def-9d6e10d992e5-image.png

              You can't and shouldn't remove this 127.0.0.1, as it used for pfSense itself.

              Services > DNS Resolver > General Settings, checked are :

              Enable
              Network Interfaces : All
              Outgoing Network Interfaces : All
              DNSSEC
              Python Module
              Static DHCP
              Display Custom Options : Custom options : nothing

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              S 1 Reply Last reply Reply Quote 0
              • S
                stgeorge @Gertjan
                last edited by

                @gertjan Thank you for going through those options- I've run through them and had most of them, but added a couple- regardless though, I somehow did remove the 127.0.0.1 and can't seem to figure out how to reset it. After running through your suggested settings, and save/apply, it's not yet back.

                Capture.JPG

                S 1 Reply Last reply Reply Quote 0
                • S
                  stgeorge @stgeorge
                  last edited by

                  Update-> I was able to resolve the DNS issues as stated above by selecting DNS Resolution Behavior = Use Local DNS (127.0.0.1), fallback to remote DNS servers (Default), and, thanks to @viragomann's comment about enabling the DNS query forwarding mode in the DNS Resolver settings, I am finally getting somewhere!

                  Now- I have two DNS addresses for my VPN (PIA), and two DNS addresses for my WAN (Cloudflare's DNServers), and the correct Gateway is selected for each. Now when I conduct a DNS leaktest, it shows me pfSense is resolving to both Cloudflare and to the PIA DNS addresses...? Firstly, I'm just happy that my ISP's DNS is no longer being resolved. Secondly, I guess I'm wondering if DNSleaktest.com is showing both because different devices on my LAN are using different gateways to resolve DNS queries or is it that my device which is being directed to use the VPN(PIA) gateway is actually resolving to all of the DNS addresses? I'm hoping it's the former and not the latter! Thanks.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.