Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Alternative DNS Servers - no filter/censorship (buydomains.com problem)

    Scheduled Pinned Locked Moved General pfSense Questions
    72 Posts 11 Posters 15.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      That's how they found Bin Laden, or so I hear.  Constant DNS cache refreshes for 72virgins.haha.sexyfun.net.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • K
        kejianshi
        last edited by

        I'll be  expecting boots at my door any moment then I guess…

        Since I couldn't find a good answer on how hardening DNSSEC and glue might impact my DNS performance, and no one answered my several posts on the subject, I just turned it on, turned on the Unwanted Reply Threshold also...

        If it does something unwanted, I will post back - somewhere...

        1 Reply Last reply Reply Quote 0
        • F
          firewalluser
          last edited by

          Just trying TTL 2147483647 which will generate its own operational signature.

          https://www.ietf.org/rfc/rfc2181.txt Section 8 TTL.

          Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

          Asch Conformity, mainly the blind leading the blind.

          1 Reply Last reply Reply Quote 0
          • K
            kejianshi
            last edited by

            Ohhhhh. Tell me how that turns out…

            1 Reply Last reply Reply Quote 0
            • KOMK
              KOM
              last edited by

              Just today

              D-Link Routers Vulnerable To DNS Hijacking

              1 Reply Last reply Reply Quote 0
              • K
                kejianshi
                last edited by

                Actually anything not running DNSSEC is vulnerable to this attack:

                1st Man on the side attack where you someone listening passively on the side does packet injection and spoofs a DNS response faster than the real DNS server.  They send you to their fake server loaded with forged certs and forged websites that look like the real thing.  (Thats the really evil version) or perhaps they just redirect you to some BS crap shopping site.

                2nd Once your server connects to theirs they fake the website you were trying to visit and complete the HTTPS transaction and forward you on to the real site - via their server.  Now they are the man in the middle and can read your supposedly encrypted traffic, inject packets inject malware, whatever.

                So, thats pretty much 99% of the web users are vulnerable.

                IMHO pfsense doesn't sell its self hard enough on its security features.  Not in terms average buyers can grasp anyway.

                1 Reply Last reply Reply Quote 0
                • T
                  Trel
                  last edited by

                  @kejianshi:

                  1st Man on the side attack where you someone listening passively on the side does packet injection and spoofs a DNS response faster than the real DNS server.  They send you to their fake server loaded with forged certs and forged websites that look like the real thing.  (Thats the really evil version) or perhaps they just redirect you to some BS crap shopping site.

                  Wonder if that was the case with this one: https://forum.pfsense.org/index.php?topic=87491.0

                  1 Reply Last reply Reply Quote 0
                  • K
                    kejianshi
                    last edited by

                    No idea - maybe.

                    1 Reply Last reply Reply Quote 0
                    • M
                      MrGlasspoole
                      last edited by

                      Ok, i made some screen shoots of the settings i have now.

                      @kejianshi
                      I'm still not sure about the gateway.
                      You said pointing to the modem is how grandmother did it: https://forum.pfsense.org/index.php?topic=87678.msg483085#msg483085
                      But then you said: "Don't mess with the gateways".

                      And to make sure i get it right: With this settings i get name resolving directly from the 13 Root-Nameservers (Anycast aside)?
                      If thats the case then why everywhere are this alternative DNS server lists and why is this not the default in routers from ISPs?

                      I guess i change the title of this thread - maybe it helps others.

                      Interfaces---LAN.png
                      Interfaces---LAN.png_thumb
                      Interfaces---WAN.png
                      Interfaces---WAN.png_thumb
                      Services---DNS-Resolver.png
                      Services---DNS-Resolver.png_thumb
                      Services---DNS-Resolver---Advanced.png
                      Services---DNS-Resolver---Advanced.png_thumb
                      System---Gateways---Edit-gateway.png
                      System---Gateways---Edit-gateway.png_thumb
                      System---General-Setup.png
                      System---General-Setup.png_thumb

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Name servers that return a bullshit IP address instead of NXDOMAIN for A records that don't exist are an abomination.

                        I will be switching over to a resolver-based configuration this weekend now that I'm on 2.2.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          well your resolver is on all all, which is not how I would set it up.

                          Resolver should only listen on your lan port, and should only talk to other dns on your wan.

                          And don't see how you expect pfsense to resolve anything - so its not going to be able to check for updates..

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • K
                            kejianshi
                            last edited by

                            You could deselect WAN without hurting anything or you could just not open port 53 on WAN…  Either way.  (P.S. Its not open) 
                            It should work and resolve just fine the way you have it here.

                            Easy way to check if your system is resolving and if you can get updates is to go to the main pfsense gui and see if it show "you are on current version"

                            If it does, your pfsense is resolving fine for its self and probably for all the other machines on the LAN.

                            Now, go to https://www.dnsleaktest.com/ and see how many resolvers show up.

                            Hopefully its like...1

                            1 Reply Last reply Reply Quote 0
                            • M
                              MrGlasspoole
                              last edited by

                              Selecting just LAN on "Network Interfaces" and "Outgoing Network Interfaces" gives the error:
                              This system is configured to use the DNS Resolver as its DNS server, so Localhost or All must be selected in Network Interfaces.

                              1 Reply Last reply Reply Quote 0
                              • K
                                kejianshi
                                last edited by

                                Select all.  Port 53 is closed on the WAN.  No issues there.

                                1 Reply Last reply Reply Quote 0
                                • M
                                  MrGlasspoole
                                  last edited by

                                  Now only the gateway question is still open :)

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by

                                    Then select both lan and localhost ;)  ALL is BAD practice!!

                                    Here is mine

                                    setupdnsresolver.png
                                    setupdnsresolver.png_thumb

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • K
                                      kejianshi
                                      last edited by

                                      I wouldn't screw with the gateway…  unless you are in the mood to upgrade to a ISP/Modem combo that gets you a public IP on the pfsense wan?

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        kejianshi
                                        last edited by

                                        Not sure if you know, but you select individual interfaces by holding the cntl key while clicking on the ones you want.

                                        What johnpoz is saying is best - I was trying to keep it simple…

                                        1 Reply Last reply Reply Quote 0
                                        • M
                                          MrGlasspoole
                                          last edited by

                                          @kejianshi:

                                          Not sure if you know, but you select individual interfaces by holding the cntl key while clicking on the ones you want.

                                          I know that :-) - My computer knowledge is good but pfSense is overwhelming :-)

                                          So the important part here is that on "Network Interfaces" you just have the internal and
                                          on "Outgoing Network Interfaces" the external stuff?

                                          Gateway:
                                          I did check my ISP router and i have the bridge option now.
                                          I made the hack a year ago and the option was not there - seems like after
                                          some firmware update it changed.
                                          I have a warning "from manufacture not supported change".

                                          So i can select LAN2 as bridged.
                                          But if i do that and connect my pfSense WAN NIC to LAN2 i can not reach the router anymore with 10.0.0.1.

                                          What changes do i need to make in pfSense to test it?
                                          I guess in "Interfaces > WAN" and "System > Routing > Gateways"

                                          1 Reply Last reply Reply Quote 0
                                          • DerelictD
                                            Derelict LAYER 8 Netgate
                                            last edited by

                                            Is your WAN DHCP or PPPoE?

                                            (Or Static?)

                                            Chattanooga, Tennessee, USA
                                            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                            Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.