Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense Firewall rules don't seem to have any effect ?

    Scheduled Pinned Locked Moved Firewalling
    19 Posts 4 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      abesh @viragomann
      last edited by

      @viragomann If I want to catch any rogue DNS requests to a internet DNS server and redirect that to pihole, how would I go about it ? I am guessing I need to create a rule for the WAN interface ?

      AndyRHA V 2 Replies Last reply Reply Quote 0
      • AndyRHA
        AndyRH @abesh
        last edited by

        @abesh It is not hard to force to PiHole. There are similar instructions to force to pfSense.

        https://forum.netgate.com/topic/156453/pfsense-dns-redirect-to-local-dns-server?_=1663853296484

        o||||o
        7100-1u

        1 Reply Last reply Reply Quote 0
        • V
          viragomann @abesh
          last edited by

          @abesh
          You want to redirect DNS requests to the internet, I guess?

          All well explained by @AndyRH already. ๐Ÿ˜Š

          A 2 Replies Last reply Reply Quote 0
          • A
            abesh @viragomann
            last edited by

            @viragomann @AndyRH You guys rock! I have my work cut out :) Thank you !

            1 Reply Last reply Reply Quote 0
            • A
              abesh @viragomann
              last edited by

              @viragomann @AndyRH

              I have been reading up on this and am going to try it out tomorrow. Couple of questions :

              • Do I need a managed switch to get this working ? I am guessing YES.
              • Do I have to create two VLANs - Home (all home devices) and DMZ (pihole) or can I do with LAN and a VLAN (DMZ for Pihole). Which subnet should pfSense be part of ? pfSense has a passthough external ipas well as an internal one (192.168.1.1 - same subnet as mt ATT modem)
              • The pfSense web interface is also accessible via the external IP. Is there a way to disable this ?
              • And lastly, i have configured the pfSense DNS Resolver as a forwarder to Pihole and also set the DNS settings to the Pihole DNS. This actually causes all DNS traffic to go solely to the Pihole. Therefore do I achieve anything extra in going through with the effort of setting up VLANs?
              S AndyRHA 2 Replies Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @abesh
                last edited by

                itโ€™s a bad idea to have pfSense exposed to the Internet. By default it is not. Are you accessing the WAN IP from the internet, or LAN? The latter is allowed because LAN has a default allow rule. (The packet is through the gate and pfSense knows what to do with it, โ€œthatโ€™s me!โ€). WAN has no rules so blocks all traffic by default.

                Re: DNS:
                https://docs.netgate.com/pfsense/en/latest/recipes/dns-redirect.html

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote ๐Ÿ‘ helpful posts!

                A 3 Replies Last reply Reply Quote 1
                • A
                  abesh @SteveITS
                  last edited by

                  @SteveITS You are correct ! I was accessing the WAN Ip from the LAN !!! Thanks so much !

                  1 Reply Last reply Reply Quote 0
                  • A
                    abesh @SteveITS
                    last edited by

                    @SteveITS And also, are you implying that I donot need to do the entire setup at all?

                    S 1 Reply Last reply Reply Quote 0
                    • AndyRHA
                      AndyRH @abesh
                      last edited by

                      @abesh said in pfSense Firewall rules don't seem to have any effect ?:

                      Do I have to create two VLANs

                      No, this will work with a single subnet. My example covers multi-VLAN. Just do the steps for your 1 VLAN.

                      o||||o
                      7100-1u

                      1 Reply Last reply Reply Quote 0
                      • S
                        SteveITS Galactic Empire @abesh
                        last edited by

                        @abesh said in pfSense Firewall rules don't seem to have any effect ?:

                        are you implying that I donot need to do the entire setup at all?

                        No, tbh I didn't read the rest. It was late for me and I thought I'd address that one point about the WAN IP.

                        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                        Upvote ๐Ÿ‘ helpful posts!

                        A 1 Reply Last reply Reply Quote 1
                        • A
                          abesh @SteveITS
                          last edited by

                          @SteveITS @AndyRH Thank you so much !!!

                          1 Reply Last reply Reply Quote 0
                          • A
                            abesh @SteveITS
                            last edited by

                            @SteveITS said in pfSense Firewall rules don't seem to have any effect ?:

                            Re: DNS:
                            https://docs.netgate.com/pfsense/en/latest/recipes/dns-redirect.html

                            So I tried this but landed into issues. I think I know what the issue but but not quite sure how to solve it.
                            On my pfSense I run the DNS Resolver with forwarding turned on to pihole. Pihole runs unbound locally and answers queries.
                            The NAT port forwarding above redirects all DNS queries back to the pihole, including the ones originating from it and thus I am not able to resolve anything.
                            Any idea how would I get past this other than moving the pihole to a VLAN of its own ? Thanks again @AndyRH @SteveITS !

                            AndyRHA 1 Reply Last reply Reply Quote 0
                            • AndyRHA
                              AndyRH @abesh
                              last edited by

                              @abesh This may help. I point pfSense and PiHole to an outside DNS. DHCP points the clients to PiHole. PiHole points to pfSense for the local domain home.arpa.
                              This arrangement prevents a reference loop. pfSense is the root for home.arpa.
                              My PiHoles serve DNS for several VLANs, including the one they are on.

                              pfSense does not do anything where it would need ad blockings so there is no useful reason to have it go to PiHole.

                              Another tidbit, the OS running PiHole sometimes will have DNS resolution problems, to prevent this I also point the PiHole OS to an outside DNS. This also solves the problem of how to fix PiHole if the OS cannot resolve internet names. I like to use DHCP reservations, so I do it with DHCP. It is also valid to use static settings.
                              Later consider having 2 PiHoles for redundancy, with the settings to force DNS to PiHole, if PiHole is down you cannot resolve names.

                              o||||o
                              7100-1u

                              A 1 Reply Last reply Reply Quote 1
                              • A
                                abesh @AndyRH
                                last edited by

                                @AndyRH Awesome ! Thank you :) Isn't the setup then sort of similar to one that I started with ?

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.