Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can't reverse lookup anymore wen going from dns Forwarder to DNS resolver

    Scheduled Pinned Locked Moved DHCP and DNS
    12 Posts 3 Posters 2.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      Gerard64
      last edited by

      I have reverse zone files setup a long time ago they work perfectly with DNS forwarder. If I send reverse queries directly to the dns it works also just not wen i use DNS resolver.

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        I have no idea what are you trying to tell us. You are missing the domain overrides for the reverse zones, as already said.

        1 Reply Last reply Reply Quote 0
        • G
          Gerard64
          last edited by

          Thank you!

          1 Reply Last reply Reply Quote 0
          • G
            Gerard64
            last edited by

            I tested it and you're right it works.
            This is not needed btw in DNS forwarder.
            Thank you again!

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              @Gé:

              This is not needed btw in DNS forwarder.

              Forwarder (as the name suggests) normally forwards all queries to specified DNS servers unless told otherwise. Resolver (as the name suggests) resolves queries on its own recursively (unless explicitly told to forward them to a specific DNS server.)

              1 Reply Last reply Reply Quote 0
              • G
                Gerard64
                last edited by

                Thank you for clarifying that.

                1 Reply Last reply Reply Quote 0
                • G
                  Gerard64
                  last edited by

                  I learned something today ;)

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    You know you could just point 168.192.in-addr.arpa an 10.in-addr.arpa to your local dns… Tell you for sure none of the rfc1918 space is going to resolve on the public internet that is for sure ;)  Might as well point 172.16-31 to your local dns as well ;)

                    On a side note I am curious to your selection of interfaces..  So you listen on wan1 and wan2 for queries?  And you need to use all those other interfaces other than wan based ones to get to your 1 local name server?

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.8, 24.11

                    1 Reply Last reply Reply Quote 0
                    • G
                      Gerard64
                      last edited by

                      Thank you for the tips and advise.

                      actually that is a good idee to add the whole rfc1918 address space. Going to change that ;)

                      I don't have WAN1 and/or WAN2. I do have WLAN1 & WLAN2 those are vlans were wireless clients live.

                      On outgoing interfaces I selected almost all the interfaces just to be save while fiddling around with stuff. Because of your tips I changed that to DMZ interface only.

                      Also in general settings I removed my local dns. Only 127.0.0.1 is set as dns server.

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        my bad yeah now that look closer its wlan1 and wlan2, that makes more sense to listen on..  So yeah if pfsense is going to only ask your AD and it looks up say google, then sure you only need its query interface to the be the one to be able to get to your local nameserver.

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.8, 24.11

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.