Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    After upgrade to PLUS from CE 2.7.2

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 2 Posters 249 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • UnoptanioU
      Unoptanio
      last edited by Unoptanio

      hello good morning
      I upgraded from pfsense ce 2.72 to pfsense plus ver 24.03.
      After the update these DNS addresses appeared with ::1.
      What are they? where do you change it?

      I didn't have them before upgrading.

      fdfafdec-7c87-40a8-b724-461368381bcb-image.png

      pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
      CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
      n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

      johnpozJ 1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator @Unoptanio
        last edited by johnpoz

        @Unoptanio that is just the localhost IPv6 address, think 127.0.0.1 but for IPv6.. You can make it go away if you want.. But not really any reason too. If me I would remove the the cloudflare IPs - are you actually forwarding.. Or did you just think you needed to add dns.. Out of the box unbound resolves. There is no need to add any other dns to pfsense.

        noipv6.jpg

        There are multiple threads around here about this - notice not showing it in mine on 24.03 - because I just never changed it back from a somewhat recent thread showing someone else how to remove it if they wanted too. I will see if I can dig up the previous thread and link to it.

        Here is one of the threads.

        https://forum.netgate.com/post/1178723

        Simple work around to remove it.. Is set dns to 127.0.0.1 and set unbound to only use "remote" which it now thinks is the loopback address only ;)

        nomore.jpg

        No more ::1 listed in your dns ;)

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        UnoptanioU 1 Reply Last reply Reply Quote 2
        • UnoptanioU
          Unoptanio @johnpoz
          last edited by Unoptanio

          @johnpoz
          abbb3d49-291d-4cf2-b817-d85fac498715-image.png

          b52ccd4b-5b84-4f08-8a09-01611290aaa5-image.png

          647685c7-b046-40c9-84c0-d69e924ab9dc-image.png

          pfSensePlus24.03 2U BareMetal Asrock Industrial IMB-X1314MicroATX
          CPU: i7-13700@5.2GHz, RAM:32GB ECC, n°2 Samsung 870EVO SATA 2.5” SSD 1TB (ZFS) Raid1
          n°3 Intel i225-LM 2500/1000/100Mbps, n°1 NIC Intel i350-T4V2 10/100/1000 Mbps 4*GLAN, n°1 Intel X520-DA2

          johnpozJ 1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator @Unoptanio
            last edited by johnpoz

            @Unoptanio not sure what your trying to show there? Yeah that is how it works.. If you ask dns to lookup something it will ask all the ns you have listed..

            Whats your question?

            I take it your doing dot forwarding since you have the fqdn listed their for cloudflare.

            Keep in mind when you tell pfsense to lookup something, or it needs to lookup something itself and uses those.. Say for a check if there is an update - it isn't going to be using dot.. Only unbound would use dot when it get asks to lookup something and your forwarding. If you have 1.1.1.1 listed as pfsense dns, and pfsense itself goes to lookup something from 1.1.1.1 its just going to use a normal in the clear dns over 53.

            If you want to make sure pfsense never asks in the clear and only via dot, then you put your NS in there you want to ask using dot, and set pfsense itself to ignore remote and only ask local host.

            uselocal.jpg

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.