Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Resolver failing after 23.x to 24.03 upgrade

    Scheduled Pinned Locked Moved DHCP and DNS
    6 Posts 3 Posters 354 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bchipman
      last edited by

      I lost DNS resolution after upgrading to 24.03 on my Netgate 4200. I had to add an ACL to allow requests from my internal network. This was not required prior.

      GertjanG johnpozJ 2 Replies Last reply Reply Quote 0
      • GertjanG
        Gertjan @bchipman
        last edited by

        @bchipman

        I've a 4100 myself, with 24.03.

        I totally forgot about these ACLs - I had several of them.
        But I don't recall why I had to add them ....
        I'm far more sure there is no official pfSEnse manual that says that I had to make some to make my networks work, or make DNS work.

        Can you tell me where it was said that ACL need to bet set ?

        So, I'll testing right now these simple ACL settings :

        d1a37c6c-125d-429e-a42e-e25f8a46a748-image.png

        Yep : none.
        I took my phone, and several PCs and others devices - restarted some of them. Everything - DNS - still works just fine.

        Btw : my resolver settings are the default one : My resolver resolves.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator @bchipman
          last edited by

          @bchipman unless you have disabled creation of the auto acls, any networks that are directly attached would be in your auto acls.

          I personally disable them, and create my own - I want to know exactly what the acls are, and might create specific ones that do different stuff.

          acl.jpg

          You sure it was a acl thing that got it working, or maybe just the restart when you changed the acl?

          I just recently updated to 24.03 from 23.09.1, kept putting it off because wanted to change to ssd vs emmc - but with everything going in on in RL, 24.08 would be out before I get to it.. So I just did a in place upgrade and I had zero issues with dns or dhcp.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          B 2 Replies Last reply Reply Quote 0
          • B
            bchipman @johnpoz
            last edited by

            @johnpoz
            Where is that option?
            I don't think I have changed it.

            BTW, I figured this out after 20+ years working in networking and security and programming at enterprises.

            1 Reply Last reply Reply Quote 0
            • B
              bchipman @johnpoz
              last edited by

              @johnpoz
              Ok, I found it and that option was not selected.
              The new ACL for DNS was the only change made before DNS resolution started working. I had previously turned the resolver off and back on - no impact.

              johnpozJ 1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator @bchipman
                last edited by

                @bchipman well then your auto acls should work unless this network your clients are on not directly attached.

                Here fired up one of my vms.. You can see the auto acls in the config.

                acl.jpg

                Then I added a new network via a vlan, enabled it gave it an IP 192.168.42.1/24

                Restarted unbound and you see it updated the access list to include my new 192.168.42 network

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.