Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS lookups failing from Windows 7 using pfSense 2.0-BETA5/Unbound 1.4.8

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    4 Posts 2 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      salvor
      last edited by

      [solved by disabling DNSSEC, saving, re-enabling DNSSEC, and saving]

      I'm probably overlooking something very simple.  The regular "DNS Forwarder" works fine, but "Unbound DNS Forwarder" doesn't work for me.

      Unbound Status tab instantly shows new entries of the DNS queries I'm making from Windows 7, along with their correct IP addresses, etc.  So that part appears to be fine (and fast).

      But these results are not making it back to the Windows 7 clients which are on same LAN subnet as pfSense.

      In the unbound ACL tab, I set "Allow" for 192.168.0.0/24 (WAN) and 192.168.1.0/24 (LAN).  In Windows 7 (192.168.1.123 static, not DHCP), I set DNS server to 192.168.1.1 (pfSense) and leave 2nd DNS server blank for this test.

      When using Unbound, do we require additional Firewall rules that aren't needed with the plain DNS Forwarder?

      I'm new to pfSense, so any pointers–no matter how obvious--would be appreciated.

      I'm using pfSense-2.0-BETA5-amd64 Feb 5 build.

      Thanks.

      1 Reply Last reply Reply Quote 0
      • S Offline
        salvor
        last edited by

        When I uncheck "DNSSEC" option, queries from Windows 7 work fine.

        I suppose I'll have to RTFM on Windows 7 and DNSSEC.  Please share links, especially if you have a tutorial that is hard to find with Google.

        1 Reply Last reply Reply Quote 0
        • S Offline
          salvor
          last edited by

          I re-enabled DNSSEC, saved changes, and now it works fine as well.  I tested with domain names that were already in Unbound's cache as well as new ones.

          So now, I have DNSSEC checked, and Fowarding Mode unchecked.  All is well.

          1 Reply Last reply Reply Quote 0
          • W Offline
            wagonza
            last edited by

            Did you do anything specific besides disabling and enabling DNSSec?

            Follow me on twitter http://twitter.com/wagonza
            http://www.thepackethub.co.za

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.