Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    One DNS per interface

    Scheduled Pinned Locked Moved DHCP and DNS
    4 Posts 3 Posters 346 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      baumkuchen
      last edited by baumkuchen

      I'm stuck while I'm trying to setup my new 4-Port device. One port is for WAN the others are LAN and one is a DMZ.

      DMZ has a separate gateway and relies on the VPN, as described in the NordVPN tutorial 2.5
      LAN ports have no gateway, so they use the default gateway on WAN, which relies on another NordVPN DNS too. If possible, I would change the LAN ports to a public DNS but I don't know how I setup a "DNS per Interface policy".

      DNS resolver settings from the NordVPN tutorial 2.5
      DNS advanced resolver settings from the NordVPN tutorial 2.5

      so far and interestingly enough any site except google.com can be resolved from all the all interfaces. However, only the DMZ network resolves google.com successfully.

      What am I missing here?

      P 1 Reply Last reply Reply Quote 0
      • P
        paoloposo @baumkuchen
        last edited by

        @baumkuchen I'm not sure Unbound supports querying different DNS servers based on the client, much less that this functionality would be exposed in the pfSense GUI.

        What you can do is assign different DNS servers to clients using DHCP.

        1 Reply Last reply Reply Quote 1
        • planedropP
          planedrop
          last edited by

          Like @paoloposo mentioned, your easiest solution here is going to be using DHCP to give each client on a different subnet a different public DNS server, otherwise they are using pfSense as their resolver which is going to use whatever you set as the upstream provider in pfSense itself (in this case the one over the VPN).

          1 Reply Last reply Reply Quote 1
          • B
            baumkuchen
            last edited by

            That put me in the right direction!
            Thank you gentlemen.

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.