Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    2.1.4 Fresh Install DNS Not resolving

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    19 Posts 5 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T Offline
      Thoro
      last edited by

      @phil.davis:

      Thinking that it was a FW rule issue, I've added rules on the WAN to PASS port 53 to\from my DNS servers.

      Also you do not need to open anything on WAN for outgoing DNS queries to work. That rule will let the outside world use your DNS, which is not a good idea.

      Yeah, I recognize that but I was trying to grasp as straws.

      @cmb:

      Can you ping your configured DNS servers? The symptoms match a basic network connectivity problem. There is no requirement to have DHCP or anything else enabled for DNS to function.

      I discounted that earlier due to some rules on the gw but I checked those and retested.

      pfsense  –> 8.8.8.8    == Failure
      gateway --> 8.8.8.8    == Success
      pfsense  --> gateway == Success
      gateway --> pfsense  == Success
      gateway --> next hop == Success
      pfsense --> next hop == Failure

      Using the Diagnostics: Routing Table I see that 8.8.8.8 uses the correct gateway.

      I'm not trying to be difficult but I must be missing some obvious.. so I'll ask the question.  How is the WAN and the gateway supposed to be configured?

      1 Reply Last reply Reply Quote 0
      • K Offline
        kejianshi
        last edited by

        Well - The gateway and wan IP should be on same subnet…

        Your wan should match what your ISP is providing.

        Example.  If they provide a /24 and you enter /16 it wouldn't work well maybe.

        Just little nit-noid things like that.

        Also, try it with nothing more than basic default default WAN and LAN rules at first.

        1 Reply Last reply Reply Quote 0
        • T Offline
          Thoro
          last edited by

          @kejianshi:

          Example.  If they provide a /24 and you enter /16 it wouldn't work well maybe.

          Yeah, the WAN IP is using /24 and they are providing /16.  I'll tinker with that and see what happens.

          1 Reply Last reply Reply Quote 0
          • K Offline
            kejianshi
            last edited by

            I can't tell if you are being serious or sarcastic.  haha.
            But I really do hope it works.  I've seen typos like that on the wan before that people had missed.
            Not trying to suggest you can't set up a WAN.  I know I've made my share of mistakes.

            1 Reply Last reply Reply Quote 0
            • C Offline
              cmb
              last edited by

              @Thoro:

              How is the WAN and the gateway supposed to be configured?

              However your ISP tells you. Matching the IP, subnet mask, and gateway provided (for static IP connectivity, which sounds like what you have here).

              1 Reply Last reply Reply Quote 0
              • T Offline
                Thoro
                last edited by

                @kejianshi:

                Well - The gateway and wan IP should be on same subnet…

                Example.  If they provide a /24 and you enter /16 it wouldn't work well maybe.

                Yes, the gateway was on /16 and the FW was on /24. After changing the GW to match still no dice.

                @kejianshi:

                I can't tell if you are being serious or sarcastic.  haha.

                No problem.. I've been banging my head against this with no luck for almost two weeks now.. so I'm more frustrated than anything else.

                Is there an easy way to test DNS in pfsense to ensure that "before the FW" there is connectivity?  I can not easily just plug in a computer on that port as it's remote.

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  Is there an easy way to test DNS in pfsense to ensure that "before the FW" there is connectivity?

                  Sure.  Create a static DNS entry (Host Override) in Services->DNS Forwarder then:

                  dig @pfsenseip host_override_fqdn

                  From behind pfSense (ie from LAN)

                  If you don't have dig you'll need to use nslookup, or ping the hostname or something but you won't be specifically asking pfSense to resolve a name so you might not be testing what you want to be testing.

                  I can not easily just plug in a computer on that port as it's remote.

                  You might have to take a trip or get some remote hands going.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    Thoro
                    last edited by

                    Cool, I'll try that.

                    Is there a better place to track\log the activity of the DNS REsolver? In my screwing around with it now I'm getting nothing in the REsolver tab of the System Logs after using the DNS Resolver in Diagnostics.

                    1 Reply Last reply Reply Quote 0
                    • T Offline
                      Thoro
                      last edited by

                      @Derelict:

                      Is there an easy way to test DNS in pfsense to ensure that "before the FW" there is connectivity?

                      Sure.  Create a static DNS entry (Host Override) in Services->DNS Forwarder then:

                      dig @pfsenseip host_override_fqdn

                      From behind pfSense (ie from LAN)

                      If you don't have dig you'll need to use nslookup, or ping the hostname or something but you won't be specifically asking pfSense to resolve a name so you might not be testing what you want to be testing.

                      Awesome, using the override I have confirmed that the resolver can work.. but only internally.

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        Thoro
                        last edited by

                        I was able to get a box on the outside of the PFsense and test the DNS… no dice. So this is looking like a gateway issue.  I'll update when I know more.

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          Thoro
                          last edited by

                          Issue was found to be in the gateway. Thanks for all your help guys.

                          1 Reply Last reply Reply Quote 0
                          • K Offline
                            kejianshi
                            last edited by

                            Cool - Hope its good now.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.