Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfBlockerNG and another DNS server within LAN

    pfBlockerNG
    2
    3
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      belgiumrom
      last edited by

      Hi guys,

      If the question has been asked before I apologize.
      My setup is as follows:
      pfsense v2.4.2 x64 with squid, squidguard, dhcp and dnsresolver with forwarding mode disabled.
      Another DNS server within LAN, a bind9 running on a ubuntu 16.04 forwarding all the requests to the pfsense DNS.
      My LAN devices are getting both DNS addresses (pfsense and ubuntu) when dhcp address is assigned as dns autoconfiguration.
      My question:
      Is this setup going to work if I want to use pfblockerng or I am defeating the purpose of this package?
      In my mind, I believe it should work but I just need another opinion to be sure.

      Thanks

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        You can still use an internal DNS server. You just have to make sure that the internal DNS server has its external forwarders set to only pfSense. To utilize DNSBL, you will need to use Unbound and not the DNSMasq forwarder in pfSense.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • B
          belgiumrom
          last edited by

          @BBcan177:

          You can still use an internal DNS server. You just have to make sure that the internal DNS server has its external forwarders set to only pfSense. To utilize DNSBL, you will need to use Unbound and not the DNSMasq forwarder in pfSense.

          That's what I thought, thank you!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.