Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Firewall DNS Rules

    Scheduled Pinned Locked Moved DHCP and DNS
    5 Posts 2 Posters 10.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mgc6288
      last edited by

      Ok, I'm a little lost on making DNS Server Rules where Rule1 would allow the usage of the OpenDNS and then Rule2 would deny the use of anything else.  Reasoning is so that my son can statically change his DNS to avoid being filtered…

      1 Reply Last reply Reply Quote 0
      • X
        XIII
        last edited by

        To make an alias:
        Go to Firewall->Aliases
        Click the + sign
        Type in the name and description
        Click the + sign at the bottom twice
        add the following IPs each on their own line: your firewall, 208.67.222.222, 208.67.220.220.

        Now for the rules:
        Go to Firewall->Rules->Opt1
        Click the + sign

        then (I have listed only the options which you need to edit):
        Protocol: TCP/UDP
        Destination Type: Single Host or Alias
        Destination  Address: whatever you named the alias
        Destination Port Range from & to: DNS

        Click save.

        -Chris Stutzman
        Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
        Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
        freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
        Check out the pfSense Wiki

        1 Reply Last reply Reply Quote 0
        • M
          mgc6288
          last edited by

          @XIII:

          To make an alias:
          Go to Firewall->Aliases
          Click the + sign
          Type in the name and description
          Click the + sign at the bottom twice
          add the following IPs each on their own line: your firewall, 208.67.222.222, 208.67.220.220.

          Now for the rules:
          Go to Firewall->Rules->Opt1
          Click the + sign

          then (I have listed only the options which you need to edit):
          Protocol: TCP/UDP
          Destination Type: Single Host or Alias
          Destination  Address: whatever you named the alias
          Destination Port Range from & to: DNS

          Click save.

          Wow.  You have really been helpful.  I created an Alias just for OpenDNS so that is all that would be accepted under the OPT1 interface.  Then the second rule rejects all port 53.  Thanks again for taking the time to explain this.

          1 Reply Last reply Reply Quote 0
          • X
            XIII
            last edited by

            Correct. You are welcome. I got this from the pfSense Docs/Book.

            -Chris Stutzman
            Sys0:2.0.1: AMD Sempron 140 @2.7 1024M RAM 100GHD
            Sys1:2.0.1: Intel P4 @2.66 1024M RAM 40GHD
            freedns.afraid.org - Free DNS dynamic DNS subdomain and domain hosting.
            Check out the pfSense Wiki

            1 Reply Last reply Reply Quote 0
            • M
              mgc6288
              last edited by

              @XIII:

              Correct. You are welcome. I got this from the pfSense Docs/Book.

              You know I've skimmed through it but I never even thought about an Alias as I've never used them before.  Very handy.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.