Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Forwarder Domain Override for a public domain

    Scheduled Pinned Locked Moved DHCP and DNS
    4 Posts 2 Posters 243 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      McMurphy
      last edited by

      Testing...

      I have specified 8.8.8.8 in System => General Setup and enabled the DNS Forwarder

      In the Forwarder settings I have specified a Domain Override for openvpn.com to use 1.1.1.1

      When I perform an nslookup in pfSense for openvpn.com it is still using 8.8.8.8

      Is it possible to use the Domain Override to force a public domain to use a DNS server other than the one used by the Forwarder/Resolver (in forwarding mode)

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @McMurphy
        last edited by johnpoz

        @McMurphy a domain override tells the ns vs asking X that it is set to use, if anyone looking for domainX.tld ask this guy.. Yes that can be a public domain.

        But that is kind of pointless to be honest. since 8.8.8.8 can resolve whatever public domain - why would you ask 1.1.1.1 for domainx.tld when 8.8.8.8 is more than capable of answering that question.

        Domain overrides are normally used when where you forward would not be able to answer the query.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        M 1 Reply Last reply Reply Quote 0
        • M
          McMurphy @johnpoz
          last edited by

          @johnpoz

          I agree. This is just for testing purposes to confirm the functionality

          I set a Domain Override for opendns.com to 9.8.7.6 (should not resolve)
          30.03.2024_23.30.57_REC.png

          nslookup still resolves it at 8.8.8.8
          30.03.2024_23.31.15_REC.png

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @McMurphy
            last edited by johnpoz

            @McMurphy maybe its being redirected upstream? There are currently multiple threads about on how nord is intercepting dns traffic..

            If you want to know if your override is working.. Sniff your traffic.. A domain override can be used on just a resolver as well.

            Also keep in mind using the diagnostic lookup window isn't a good choice for this sort of test, because depending on how you have it setup, pfsense would fallback to or could just ask what is in its dns settings.

            Here.. I setup domain override for openvpn.com

            You can see when I ask unbound for it from a client on my network - it tries to ask 1.2.3.4 via sniff on the wan interface.

            settings1.jpg

            You can see from your response there - it asked loopback, got no answer, but then asked 8.8.8.8 directly.. This is pfsense asking, not what unbound did via its settings.. You would prob need to set this to do not use external..

            ignore.jpg

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.