Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Config For Enterprise SEtup ?

    Scheduled Pinned Locked Moved DHCP and DNS
    11 Posts 3 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      bryan.paradis
      last edited by

      You are going to have to be much clearer about what you would lik to do.

      1 Reply Last reply Reply Quote 0
      • C Offline
        ciscoboy
        last edited by

        Hi Sir Bry / PFsense Team,

        Please see diagram for details.

        Basically I need to use my internal DNS/ DC for windows clients but its not working..

        Thank you..

        1 Reply Last reply Reply Quote 0
        • C Offline
          ciscoboy
          last edited by

          any other alternative with this config:

          on client workstation:

          primary: 172.25.85.20 (internal dns)
          secondary: 172.25.85.91 (pfsense)

          1 Reply Last reply Reply Quote 0
          • B Offline
            bryan.paradis
            last edited by

            @ciscoboy:

            any other alternative with this config:

            on client workstation:

            primary: 172.25.85.20 (internal dns)
            secondary: 172.25.85.91 (pfsense)

            You can tell pfsense to forward all domain DNS queries to your authoritative DNS server? Would that make sense? Have a look at domain overrides in the DNS Forwarder section.

            1 Reply Last reply Reply Quote 0
            • C Offline
              ciscoboy
              last edited by

              Hi Sir,

              Thank for the reply..

              scenario : when set as primary dns:

              172.25.85.20 (internal dns) - cannot resolve websites - google.com etc.

              172.25.85.91 (pfsense) - can resolve websites.. but need to set my primary to internal dns inorder to login to domain. :(

              1 Reply Last reply Reply Quote 0
              • johnpozJ Offline
                johnpoz LAYER 8 Global Moderator
                last edited by

                Dude setup forwarder on your AD dns to point to pfsense, or google or opendns or 4.2.2.2 or have it directly query the roots.  And setup the correct firewall rules to allow whatever your choose to do.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                1 Reply Last reply Reply Quote 0
                • C Offline
                  ciscoboy
                  last edited by

                  Thanks Sir John for the great idea… it's becoming more clearer....  need to test.

                  Again many thanks...!

                  1 Reply Last reply Reply Quote 0
                  • C Offline
                    ciscoboy
                    last edited by

                    Hi Sir,

                    I have some problems with the DC / internal DNS server , I cannot querry forwarders for dns..

                    DNS - Request timeout..

                    -> Already allowed subnet for any connection &  to any destination..

                    Thank you sir..

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ Offline
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      What are the rules on the interface your DC is connected too, looks like you have multiple vlans or segments there.  Can you post it its rules?

                      If the DC can not do a query to say 4.2.2.2 or or whatever public dns your trying to forward too then sure your going to have problems.  How a bout just forwarding to pfsense IP on that network?  Pfsense can query dns can it not, and dnsmasq is running since you say when you point to pfsense internet works.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                      1 Reply Last reply Reply Quote 0
                      • C Offline
                        ciscoboy
                        last edited by

                        Hi Sir Johnpoz,

                        Thank you very much Sir Johnpoz, you're solution worked! You're the best!!!

                        For others who have the same problem follow the solution provided by Sir John:

                        @johnpoz:

                        Dude setup forwarder on your AD dns to point to pfsense, or google or opendns or 4.2.2.2 or have it directly query the roots.  And setup the correct firewall rules to allow whatever your choose to do.

                        Thank you thank you…

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.