Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Opendns

    Scheduled Pinned Locked Moved Firewalling
    5 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Ritzie
      last edited by

      I'm trying to setup opendns to block skype and some other sites. I did the the test for open dns and pass the last two but not the first. http://www.opendns.com/support/article/64 I added the following ip addresses (208.67.220.220 and 206.67.222.222) to general-setup-dns servers. My lan rules are attached. I appreciate any help I can get. Thanks!
      Lanrules.JPG
      Lanrules.JPG_thumb

      1 Reply Last reply Reply Quote 0
      • R
        rjcrowder
        last edited by

        Not sure why you have NAT rules… I've attached my rules - simply allow access to the OpenDNS servers and the LAN server and block any other attempt to hit port 53 outbound.

        Also, on the General tab you should uncheck the box that says "Allow DNS server list to be overridden by DHCP/PPP on WAN"

        ![Screenshot from 2013-12-25 17:10:33.png](/public/imported_attachments/1/Screenshot from 2013-12-25 17:10:33.png)
        ![Screenshot from 2013-12-25 17:10:33.png_thumb](/public/imported_attachments/1/Screenshot from 2013-12-25 17:10:33.png_thumb)

        1 Reply Last reply Reply Quote 0
        • R
          Ritzie
          last edited by

          Thank you so much rjcrowder. I removed the NAT settings and made changes in firewall. That worked!!!

          1 Reply Last reply Reply Quote 0
          • P
            phil.davis
            last edited by

            I added the following ip addresses (208.67.220.220 and 206.67.222.222)

            There is also a typo in that 2nd OpenDNS address - might just be in your post, but check your actual system:
            208.67.220.220 and 208.67.222.222

            As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
            If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

            1 Reply Last reply Reply Quote 0
            • M
              MikeX
              last edited by

              Why not set all internal hosts to use the DNS server built into pfsense? You can enable the DNS forwarder, and have the pfsense box itself use the Opendns resolvers.

              This was you don't need to open up any additional holes in your firewall, and you will get the added benefit of local address caching via pfsense.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.