Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Netgate 4200 - connection problems / DNS Resolver

    Official Netgate® Hardware
    4
    8
    206
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      johndoe102
      last edited by johndoe102

      Hello here,
      the title is a bit misleading, but I really didn't find a better one.

      To be honest , slowly I am tired of using this device (Netgate 4200). I had previously Netgate 2100 and I had no issues at all. I also cannot say if it is hardware or software, that is causing so many problems I have.

      Here is the problem (not the only one with this device/software).

      Very often (not each time) I cannot go outside to the public internet.

      So I am switching my PC on and trying to call any of the web sides in the web browser, but I cannot. I can reach pfsense GUI , but no DNS resolution works either from my PC nor directly from pfsense. So e.g. "ping google.com" doesn't work neither from my PC nor from pfsense box. Every time this problems occur, I need to restart either "unbound DNS Resolver" from the pfsense dashboard or my PC... then it works.

      Here is my setup:

      1. My PC is directly connected to igc1 (this LAN2 with local IP 192.168.2.2) - I assume some of you will write , that I should place a switch in between and connect my PC thru the switch and not directly to the pfsense, but hey, this is also a switch on Netgate device , so why I cannot do this ?
      2. I am using quad9 as DNS - everything is setup as described on quad9 page -> https://docs.quad9.net/Setup_Guides/Open-Source_Routers/pfSense_%28Encrypted%29/

      I am also attaching the pfsense.log. As you can see from the log I switched my PC at Mar 29 20:15:48 on.

      best regards
      Tom

      pfsense_general_log.txt

      S 1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee
        last edited by JonathanLee

        What are your DNS port rules in terms of interface ACLs ?

        Did you create a NAT rule for DNS?

        Can you screenshot your rules for the interface that has issues?

        What packages are you using?

        Do you see the DNS listed when you look at status?

        Make sure to upvote

        J 1 Reply Last reply Reply Quote 0
        • S
          SteveITS Galactic Empire @johndoe102
          last edited by

          @johndoe102 The 4200 doesn’t have a switch built in. Powering off your PC will cause pfSense to detect the interface disconnect/reconnect and restart packages/services.

          Do you have DNSSEC disabled since you are forwarding? It’s in the doc, but often missed.

          Are you registering hostnames in DHVP? That restarts ISC DHCP server at each lease renewal.

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote 👍 helpful posts!

          J 1 Reply Last reply Reply Quote 0
          • J
            johndoe102 @SteveITS
            last edited by

            @SteveITS

            Do you have DNSSEC disabled since you are forwarding? It’s in the doc, but often missed. -> Yes I do.
            Screenshot from 2025-03-30 00-04-06.png

            Are you registering hostnames in DHVP?. -> I am not aware about DHVP ... I am not using it. I didn't setup it ... at least not me. If there is something setup out-of-the-box then I am not aware about that.

            The only thing I do is , that for all clients in my home network I am using static IPs based on MAC and for all clients I do create ARP table static entries.
            Screenshot from 2025-03-30 00-11-07.png

            best regards
            Tom

            S 1 Reply Last reply Reply Quote 0
            • J
              johndoe102 @JonathanLee
              last edited by johndoe102

              @JonathanLee
              Hello,

              Did you create a NAT rule for DNS? -> No.

              Can you screenshot your rules for the interface that has issues?
              Screenshot from 2025-03-30 00-19-21.png

              Screenshot from 2025-03-30 00-16-26.png

              Screenshot from 2025-03-30 00-14-37.png

              What packages are you using?
              Screenshot from 2025-03-30 00-38-59.png

              Screenshot from 2025-03-30 00-36-07.png

              Screenshot from 2025-03-30 00-35-29.png

              patient0P 2 Replies Last reply Reply Quote 0
              • S
                SteveITS Galactic Empire @johndoe102
                last edited by

                @johndoe102 DHCP, typo

                Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                Upvote 👍 helpful posts!

                1 Reply Last reply Reply Quote 0
                • patient0P
                  patient0 @johndoe102
                  last edited by

                  @johndoe102 I know it is boring but please add a switch between pfSense and your PC on LAN2 (the 4200 does not have a built-in switch, in contrast to the 2100).

                  The log shows LAN2/opt2/igc1 going up/down a few times in half a minute or so. That triggers a whole lot of scripts each time, wan restart is one of them. Removes and adds the gateway and so on.

                  1 Reply Last reply Reply Quote 0
                  • patient0P
                    patient0 @johndoe102
                    last edited by

                    This post is deleted!
                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.