Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Config For Enterprise SEtup ?

    Scheduled Pinned Locked Moved DHCP and DNS
    11 Posts 3 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      ciscoboy
      last edited by

      Hi PFsense Masters,

      Good day!

      Need help , almost done with the setup but our setup is having a different DNS server on the client field.

      ex.

      Ip add: 172.25.99.x
                  255.255.255.0
                  172.25.99.1

      DNS:              172.25.99.10
      SECONDARY : 172.25.89.11

      All is working if pfsense ip is used as DNS server but need to setup as such due to Active Directory Setup….

      Thank you in advance team...

      1 Reply Last reply Reply Quote 0
      • B Offline
        bryan.paradis
        last edited by

        You are going to have to be much clearer about what you would lik to do.

        1 Reply Last reply Reply Quote 0
        • C Offline
          ciscoboy
          last edited by

          Hi Sir Bry / PFsense Team,

          Please see diagram for details.

          Basically I need to use my internal DNS/ DC for windows clients but its not working..

          Thank you..

          1 Reply Last reply Reply Quote 0
          • C Offline
            ciscoboy
            last edited by

            any other alternative with this config:

            on client workstation:

            primary: 172.25.85.20 (internal dns)
            secondary: 172.25.85.91 (pfsense)

            1 Reply Last reply Reply Quote 0
            • B Offline
              bryan.paradis
              last edited by

              @ciscoboy:

              any other alternative with this config:

              on client workstation:

              primary: 172.25.85.20 (internal dns)
              secondary: 172.25.85.91 (pfsense)

              You can tell pfsense to forward all domain DNS queries to your authoritative DNS server? Would that make sense? Have a look at domain overrides in the DNS Forwarder section.

              1 Reply Last reply Reply Quote 0
              • C Offline
                ciscoboy
                last edited by

                Hi Sir,

                Thank for the reply..

                scenario : when set as primary dns:

                172.25.85.20 (internal dns) - cannot resolve websites - google.com etc.

                172.25.85.91 (pfsense) - can resolve websites.. but need to set my primary to internal dns inorder to login to domain. :(

                1 Reply Last reply Reply Quote 0
                • johnpozJ Offline
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Dude setup forwarder on your AD dns to point to pfsense, or google or opendns or 4.2.2.2 or have it directly query the roots.  And setup the correct firewall rules to allow whatever your choose to do.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                  1 Reply Last reply Reply Quote 0
                  • C Offline
                    ciscoboy
                    last edited by

                    Thanks Sir John for the great idea… it's becoming more clearer....  need to test.

                    Again many thanks...!

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      ciscoboy
                      last edited by

                      Hi Sir,

                      I have some problems with the DC / internal DNS server , I cannot querry forwarders for dns..

                      DNS - Request timeout..

                      -> Already allowed subnet for any connection &  to any destination..

                      Thank you sir..

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ Offline
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        What are the rules on the interface your DC is connected too, looks like you have multiple vlans or segments there.  Can you post it its rules?

                        If the DC can not do a query to say 4.2.2.2 or or whatever public dns your trying to forward too then sure your going to have problems.  How a bout just forwarding to pfsense IP on that network?  Pfsense can query dns can it not, and dnsmasq is running since you say when you point to pfsense internet works.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                        1 Reply Last reply Reply Quote 0
                        • C Offline
                          ciscoboy
                          last edited by

                          Hi Sir Johnpoz,

                          Thank you very much Sir Johnpoz, you're solution worked! You're the best!!!

                          For others who have the same problem follow the solution provided by Sir John:

                          @johnpoz:

                          Dude setup forwarder on your AD dns to point to pfsense, or google or opendns or 4.2.2.2 or have it directly query the roots.  And setup the correct firewall rules to allow whatever your choose to do.

                          Thank you thank you…

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.