Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Prevent external queries to dns

    Scheduled Pinned Locked Moved DHCP and DNS
    11 Posts 3 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • pttP Offline
      ptt Rebel Alliance
      last edited by

      Are you sure ? How you have checked/determined that ?

      Can you attach a screenshot of your WAN FW rules

      1 Reply Last reply Reply Quote 0
      • M Offline
        mendilli
        last edited by

        if you just want your clients to use only your dns servers specified in pfsense;
        in system->general tab uncheck(disable) "Allow DNS server list to be overridden by DHCP/PPP on WAN" option and that is it

        1 Reply Last reply Reply Quote 0
        • pttP Offline
          ptt Rebel Alliance
          last edited by

          @mendilli:

          if you just want your clients to use only your dns servers specified in pfsense;
          in system->general tab uncheck(disable) "Allow DNS server list to be overridden by DHCP/PPP on WAN" option and that is it

          Are you sure about that  ?

          How the "Allow DNS server list to be overridden by DHCP/PPP on WAN" option  will prevent the FW to answer DNS queries on the WAN interface ?

          @rbutler:

          I am trying to find a way to prevent my pfsense firewall from replying to dns queries on the wan interface.  I added a rule to block port 53 udp/tcp on the wan interface but it still answers. any advice would be helpful

          1 Reply Last reply Reply Quote 0
          • R Offline
            rbutler
            last edited by

            Thanks for the reply.  this is not for clients on my lan network but is for computers on the internet. If someone does a dns query using the ip of the wan interface of pfsense as the dns server they get a response. I want to prevent this. I have attached a screenshot of the wan firewall rule I created to block request to port 53.

            port53.png
            port53.png_thumb

            1 Reply Last reply Reply Quote 0
            • R Offline
              rbutler
              last edited by

              @ptt:

              Are you sure ? How you have checked/determined that ?

              Can you attach a screenshot of your WAN FW rules

              here is a screenshot of the firewall rules for the wan interface

              port53.png
              port53.png_thumb

              1 Reply Last reply Reply Quote 0
              • pttP Offline
                ptt Rebel Alliance
                last edited by

                How are you checking/testing ?

                What is the purpose of the "total bandwith up/down" Rule ?

                1 Reply Last reply Reply Quote 0
                • R Offline
                  rbutler
                  last edited by

                  @ptt:

                  How are you checking/testing ?

                  What is the purpose of the "total bandwith up/down" Rule ?

                  when off site at home I do an nslookup querying the pfsense wan interface and get a reply.

                  1 Reply Last reply Reply Quote 0
                  • R Offline
                    rbutler
                    last edited by

                    @ptt:

                    How are you checking/testing ?

                    What is the purpose of the "total bandwith up/down" Rule ?

                    it was used for bandwidth limiter but it currently not used.

                    1 Reply Last reply Reply Quote 0
                    • pttP Offline
                      ptt Rebel Alliance
                      last edited by

                      Your "Block" rule is wrong….

                      The Source port should be "Any"  not 53...  Only the "Dest" port should be 53  :)

                      Also, the "total bandwith up/down" Rule, allows traffic from "Any" to "Any".... get rid of that rule  ;)

                      1 Reply Last reply Reply Quote 0
                      • R Offline
                        rbutler
                        last edited by

                        @ptt:

                        Your "Block" rule is wrong….

                        The Source port should be "Any"  not 53...  Only the "Dest" port should be 53  :)

                        Also, the "total bandwith up/down" Rule, allows traffic from "Any" to "Any".... get rid of that rule  ;)

                        thanks for the response.  I did change the source port to any and removed the bandwith up down rule. the up/down rule was to provide a rule for a limiter ( which I guess I do not have configured correctly). Once I removed the bandwith up/down rule dns responses were blocked correctly on the wan interface and I don't need the port 53 rule this was a total meatware problem.  :o

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.