Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Domain Override doesn't work

    Scheduled Pinned Locked Moved DHCP and DNS
    3 Posts 3 Posters 443 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • MaxPresiM
      MaxPresi
      last edited by MaxPresi

      I have a network with Cisco SG550 Layer 3 Switches that manage VLANs and DHCP, and DNS in pfSense. Everything is working fine, except the domain override, which points to the ad that is in the cloud. We have about 10 sites with pfsense configured with domain override to AD in the cloud, via ipsec, but only here it does not work. Here is also the only place with Switch L3, but I don't know if that's the problem, since even through the firewall I can't ping to domain.

      This is also where the old AD was, and DHCP and DNS were on it. After moving to the cloud, I passed DHCP to the main Switch L3 and configured it to use DNS on the Firewall.

      I tried DNS Forward too, I tried to configure the AD ip in the DNS Server in General Setup and activate the DNS Forwarder in DNS Resolver, but that completely drops the internet (bad_config). I can ping and access the AD normally via IP. Tried config the domain override with "domain.local" and "local" only.

      Anything else I can try?

      G johnpozJ 2 Replies Last reply Reply Quote 0
      • G
        guile @MaxPresi
        last edited by guile

        @MaxPresi i had this issue before and what fixed for me was:

        • pfSense System > General Setup: Set AD IP;
        • pfSense Services > DNS Resolver > General Settings: Check "Enable Forwarding Mode"

        Go to your AD DNS and Forward to extern DNS like OpenDNS or Google.

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @MaxPresi
          last edited by johnpoz

          @MaxPresi said in Domain Override doesn't work:

          I tried DNS Forward too

          When ever you forward to ask a question, be it you forward everything or just a domain override - a domain override is a forward. You have to setup your rebind protection. Set the domain to private, if you forward and get back a rfc1918 address it is considered rebind and unbound will not hand that back to the client unless you set the domain as private, or turn off rebind protection.

          https://docs.netgate.com/pfsense/en/latest/services/dns/rebinding.html

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.