Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Bind package for pfsense 2.1

    Scheduled Pinned Locked Moved pfSense Packages
    153 Posts 44 Posters 66.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcellocM
      marcelloc
      last edited by

      Check version 0.1.5

      main changes

      • Add forward zone option

      • Add rndc config to named.conf

      • Add widget to dashboard

      • Include dev/random,null and zero on named chroot dir

      • Check slave zone dir permissions

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • marcellocM
        marcelloc
        last edited by

        and on pkg 0.2

        • dnssec

        :)

        Treinamentos de Elite: http://sys-squad.com

        Help a community developer! ;D

        1 Reply Last reply Reply Quote 0
        • S
          stalks
          last edited by

          This is awesome :) All seems to be working great, nice work indeed.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            Ok – wtf, now getting refused..

            C:>dig pfsense.local.lan

            ; <<>> DiG 9.9.4 <<>> pfsense.local.lan
            ;; global options: +cmd
            ;; Got answer:
            ;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 16069
            ;; flags: qr rd; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 1
            ;; WARNING: recursion requested but not available

            ;; OPT PSEUDOSECTION:
            ; EDNS: version: 0, flags:; udp: 4096
            ;; QUESTION SECTION:
            ;pfsense.local.lan.            IN      A

            ;; Query time: 4 msec
            ;; SERVER: 192.168.1.253#53(192.168.1.253)
            ;; WHEN: Fri Oct 18 07:48:22 Central Daylight Time 2013
            ;; MSG SIZE  rcvd: 46

            I have edited the ACL every which way I can think of, I see the configs in the zones.. Gone and updated them - restared.. Let me take a look at the named.conf and see what it says for acls, etc..

            This package is looking like one sweet deal -- just not able to get it work ;)

            edit:  YEAH!!!  Its working!!!  have to actually highlight the lists in vies section.

            ; <<>> DiG 9.9.4 <<>> pfsense.local.lan
            ;; global options: +cmd
            ;; Got answer:
            ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 31349
            ;; flags: qr aa rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 1, ADDITIONAL: 1

            ;; OPT PSEUDOSECTION:
            ; EDNS: version: 0, flags:; udp: 4096
            ;; QUESTION SECTION:
            ;pfsense.local.lan.            IN      A

            ;; ANSWER SECTION:
            pfsense.local.lan.      86400  IN      A      192.168.1.253

            ;; AUTHORITY SECTION:
            local.lan.              86400  IN      NS      pfsense.local.lan.

            ;; Query time: 4 msec
            ;; SERVER: 192.168.1.253#53(192.168.1.253)
            ;; WHEN: Fri Oct 18 07:53:50 Central Daylight Time 2013
            ;; MSG SIZE  rcvd: 76

            Got my PTR zones working -- yeah this seems to ROCK!!!!  Will have to test out the dnssec stuff today..  But THANK YOU!  This has been a long awaited addition to pfsense...

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • AhnHELA
              AhnHEL
              last edited by

              Is there a setup tutorial for this that I can follow?

              AhnHEL (Angel)

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Might not be a bad idea - seems you have to have a view setup, and ACLs - and you have to highlight them in the zone or it doesn't like to work.

                I just broke mine again with trying to enable the dnssec, had to delete the zone files and then go back in into the zones so they were recreated, etc.

                Might be nice to allow checkconf from the gui to see its output.. But there is clearly some stuff with the chroot that I don't quite get..  still looks like /etc/namedb/named.conf - but this is really in /cf/named/etc/namedb but there there is also something to do with /usr/pbi/bind-i386/etc/named.conf ???

                Some info on how this chroot stuff works for this package would be just fantastic!!!

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • marcellocM
                  marcelloc
                  last edited by

                  @AhnHEL:

                  Is there a setup tutorial for this that I can follow?

                  Just follow package tabs from left to right.

                  All you need is there :)

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • marcellocM
                    marcelloc
                    last edited by

                    @johnpoz:

                    Might not be a bad idea - seems you have to have a view setup, and ACLs - and you have to highlight them in the zone or it doesn't like to work.

                    These are all bind requirementes but I've included more info on acl options to get it clear.

                    @johnpoz:

                    I just broke mine again with trying to enable the dnssec, had to delete the zone files and then go back in into the zones so they were recreated, etc.

                    what erros? I'm testing it massively and getting no errors.

                    @johnpoz:

                    Might be nice to allow checkconf from the gui to see its output.. But there is clearly some stuff with the chroot that I don't quite get..  still looks like /etc/namedb/named.conf - but this is really in /cf/named/etc/namedb but there there is also something to do with /usr/pbi/bind-i386/etc/named.conf ???

                    Some info on how this chroot stuff works for this package would be just fantastic!!!

                    Just take a look on named process:
                    ps ax | grep -i named
                    83446  ??  Is    0:00.02 /usr/pbi/bind-amd64/sbin/named -c /etc/namedb/named.conf -u bind -t /cf/named/

                    Join chroot dir and conf dir to understand how it works.

                    Treinamentos de Elite: http://sys-squad.com

                    Help a community developer! ;D

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      I get SERVFAIL - thought I posted up a screenie before, anyway can repeat the error.

                      So as you can see working fine - did a query for pfsense.local.lan get an answer all is good.

                      Then I go into the zone, click "Enable inline DNSSEC Signing for this zones. "  hit save in the zone, then on the overall zone tab hit save again.  Do my query again and get SERVFAIL

                      Going back into the zone and unchecking it and resaving does not correct the problem.. Have to delete all the files for that zone in the zone file area - for me its /cf/named/etc/namedb/master/everyone and then resave then it its back to working.  Because I call my view everyone.

                      My point about having to highlight, I understand those are requirements for the configuration.  But it doesn't auto use if there is only 1.. You still have to actually click on it so its highlighted on the gui page, or its not used in the config.  Was like what the hell.  It says its using my all acl allow..  No not really have to highlight them for it to work - see second pic

                      So notes about having to highlight might be good thing to add to documentation on the section, etc.

                      errordnssec.png
                      errordnssec.png_thumb
                      highlighted.png
                      highlighted.png_thumb

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • marcellocM
                        marcelloc
                        last edited by

                        @johnpoz:

                        Then I go into the zone, click "Enable inline DNSSEC Signing for this zones. "  hit save in the zone, then on the overall zone tab hit save again.  Do my query again and get SERVFAIL

                        I'm not a DNSSEC specialist but if IRC, you need a parent zone to validate your dnssec zone(DS record on parent/root domain).

                        take a look on this whitepaper.

                        page 3
                        The Chain of trust
                        "…Surely the
                        public key isn’t just signed by the zone’s private key, which would mean that the public key would validate itself..."

                        "...No, the public key’s validity is established by the zone’s parent. For example, if our signed zone is called infoblox.
                        com, it’s the com zone that vouches for the infoblox.com zone’s public key..."

                        "...after the infoblox.com zone has been signed, the administrator sends a copy of his public key to the administrator of the com zone..."

                        @johnpoz:

                        Going back into the zone and unchecking it and resaving does not correct the problem

                        I'll test it here.

                        Other point. I've updated field info for zone acl. Transfer and updated acl should be restricted, not allowed to everyone. If you do not select any acl on it, means no access. That's why the package does not select automatically when only one acl is defined.

                        Treinamentos de Elite: http://sys-squad.com

                        Help a community developer! ;D

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          This goes back to the request for documentation/guide on using the package, etc.

                          From what I can tell so far you have put created one hell of a package!!!  Freaking should be part of pfsense base install for bind support..  Dude this package just ROCKS!!!  Ability for user to run full bind with a simple gui interface is fantastic!!!  I can not say that enough.

                          But it needs a bit of documentation on its use is all - bind is a very complicated product, so to let users use it with a simple gui interface is going to put pfsense way above all other sim distro's for sure!!!  So its going to draw in more and more users than just don't even understand the basics.  Which is why it needs to be documented very well.

                          Let me know how I can help is what I am saying.. I am on the road but when I get some free time will dive into testing this package more - love the fact that you show the actual config file, etc..

                          I have never gotten into details of the jail stuff, so some basics on how that works would really help in the documentation..  Because looking at the logs saying conf is in loaded from /etc/namedb when that is not really the case is confusing.

                          And then details of how to get dnssec to work will help - what I can tell you from limited play time with the package so far is if I click on that setting is it breaks bind..  If there is something need to do – that needs to be documented, etc..

                          please let me know how I can help - this package is just pure gold and want to see it become part of the base install options, etc..  What I see so far is gold.. just needs some documentation and a few tweaks and it will be ready for prime time!!

                          thank you for all the work you have put into this!!

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • marcellocM
                            marcelloc
                            last edited by

                            The bind documentation is really rich on internet. Most part of this packages was written based on it. chroot and dnssec are a good example of that.

                            I do not have that free time to spend on documentation guide. I do my best on field descriptions and a left to right configuration style package.

                            IMHO you need to know something about the package you are configuring on your network to prevent serious security problems.

                            Thank's for testing this package. This week I'll put in production and based on result change it to release or stable version.

                            Treinamentos de Elite: http://sys-squad.com

                            Help a community developer! ;D

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              I hear ya – I will be more than happy to put up some docs in the wiki, etc.. With pictures for the basic users on bring up a zone for example -- what you have to highlight, and how to work through the tabs left to right, etc.

                              And your field descriptions are very good to be honest!!  Just needs a overall how to doc is all for the users that don't know the basics.  I am very limited in my understanding of dnssec and jails myself - but I am more than happy to get more familiar with both for my own benefit and helping in documentation on using your great package!!

                              And I am with you - you allowing for enabling dnssec in bind via a gui, does not mean you have the time to write a how to for dnsses.  And I would prefer actually that you spend your time enabling great features in your interface..

                              This looks to me to be one of the all time great packages for pfsense..  But as of now it seems to me there is something that the user needs to do other than click that check box to get dnssec to work..  Maybe a note about understanding dnssec and its requirements in the field would work for now ;)  I checked it just playing around and it broke bind for my my local zone.  That is not on you -- that is just lack of understanding on my part as well  - same with chroot and jails, that is on me to understand.

                              Was just a note that it can be confusing for us that don't understand jails and such while the log says its loading one path, when that path is not really the actual path.

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • Q
                                qnarferao
                                last edited by

                                I just wanted to chime in and say this package is brilliant. Everything works beautifully, and while polish would be some Wiki Docs as others have mentioned, the core of it works great and any BIND veteran will be very pleased with this.

                                I cannot say how frustrated I've been that the tinydns package crashes all the time when attempting to set up a multi-vlan response (not to mention how difficult it is to set one up with it to begin with…NAT to localhost et al).

                                People should note that BIND of course has been the subject of MANY flaws over the years and if you plan on using it on your FIREWALL you should probably not allow BIND access to external networks or even untrusted (guest) internal ones if you are very paranoid. Even with chroot there is the potential for issues. Having said all that, the ability to use this for multi-view internal VLANs is priceless and head and shoulders above anything else.

                                -Q

                                1 Reply Last reply Reply Quote 0
                                • marcellocM
                                  marcelloc
                                  last edited by

                                  So far so good. Working flawless on my network. ;D

                                  I'll test sync code today.

                                  Treinamentos de Elite: http://sys-squad.com

                                  Help a community developer! ;D

                                  1 Reply Last reply Reply Quote 0
                                  • marcellocM
                                    marcelloc
                                    last edited by

                                    I've updated the package with some fixes and improvements. :)

                                    What's new on bind 0.3 RC package?

                                    • Backup/restore dnssec keys to xml option

                                    • A lot of logging options

                                    • Moved bind logs do Resolver tab on system logs(may require a reboot or restart on syslogd)

                                    • Add forward zone type

                                    • Enable/disable zone option

                                    • Fixed sync code. Backup servers receive zones configured on master server as slave

                                    Treinamentos de Elite: http://sys-squad.com

                                    Help a community developer! ;D

                                    1 Reply Last reply Reply Quote 0
                                    • marcellocM
                                      marcelloc
                                      last edited by

                                      Anybody else testing it? I'm planning to change status to release as it's running fine here.

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • johnpozJ
                                        johnpoz LAYER 8 Global Moderator
                                        last edited by

                                        I updated this morning with no issues.. I have my local.lan forward running and 2 ptr's setup working great.  Have not had time to play with dnssec or zone transfers.

                                        I liked how you linked to info for dnssec and give the actual configs in the gui, etc.  This is a rocking package!!

                                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                                        If you get confused: Listen to the Music Play
                                        Please don't Chat/PM me for help, unless mod related
                                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                                        1 Reply Last reply Reply Quote 0
                                        • marcellocM
                                          marcelloc
                                          last edited by

                                          I've included an extra field(custom zone records) on zone configuration tab with no package version bump.

                                          This way you can do a intermediate/faster server migration.

                                          Also tested backup DNSSEC keys on master and restore on slave. All working fine! ;D

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • johnpozJ
                                            johnpoz LAYER 8 Global Moderator
                                            last edited by

                                            enable dnssec validation?

                                            I have played with adding custom options to enable dnssec validation - but not working..

                                            So if I query my ubuntu box that has bind installed as just a resolver I can get the AD flag showing zone was validated via dnssec

                                            ; <<>> DiG 9.9.4 <<>> @192.168.1.7 pir.org +dnssec
                                            ; (1 server found)
                                            ;; global options: +cmd
                                            ;; Got answer:
                                            ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60520
                                            ;; flags: qr rd ra ad; QUERY: 1, ANSWER: 2, AUTHORITY: 5, ADDITIONAL: 9

                                            ;; OPT PSEUDOSECTION:
                                            ; EDNS: version: 0, flags: do; udp: 4096
                                            ;; QUESTION SECTION:
                                            ;pir.org.                      IN      A

                                            ;; ANSWER SECTION:
                                            pir.org.                300    IN      A      50.63.189.22
                                            pir.org.                300    IN      RRSIG  A 5 2 300 20131109085000 20131026085000 51527 pir.org. tZk+v1mE8zRnwxGZZ21F6vCOSLMMPoJu3LTJVn4gWp5ZZMWZgQ7aPHAr NMr4xffHPtfHcWGImIr2Tc0eMGbbCBLbz2IVCAtq0bfGW8RDJpEOhFyh nTByNna4ggQaMfn0anAg4Q+yIaptfINI0Dtl3tSziWk8RNY02mNaY8gz Aqw=

                                            But if I query pfsense no AD flag?

                                            ; <<>> DiG 9.9.4 <<>> @192.168.1.253 pir.org +dnssec
                                            ; (1 server found)
                                            ;; global options: +cmd
                                            ;; Got answer:
                                            ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 9091
                                            ;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 5, ADDITIONAL: 8

                                            ;; OPT PSEUDOSECTION:
                                            ; EDNS: version: 0, flags: do; udp: 4096
                                            ;; QUESTION SECTION:
                                            ;pir.org.                      IN      A

                                            ;; ANSWER SECTION:
                                            pir.org.                300    IN      A      50.63.189.22
                                            pir.org.                300    IN      RRSIG  A 5 2 300 20131109085000 20131026085000 51527 pir.org. tZk+v1mE8zRnwxGZZ21F6vCOSLMMPoJu3LTJVn4gWp5ZZMWZgQ7aPHAr NMr4xffHPtfHcWGImIr2Tc0eMGbbCBLbz2IVCAtq0bfGW8RDJpEOhFyh nTByNna4ggQaMfn0anAg4Q+yIaptfINI0Dtl3tSziWk8RNY02mNaY8gz Aqw=

                                            So how do enabled dnssec validation so that say if go to site like this - shows protected? http://dnssectest.sidn.nl

                                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                                            If you get confused: Listen to the Music Play
                                            Please don't Chat/PM me for help, unless mod related
                                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.