Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Authoritative secondary DNS

    Scheduled Pinned Locked Moved DHCP and DNS
    7 Posts 3 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      davorin
      last edited by

      Hello

      I'm currently running two microserver boxes in m y home LAN. One is the pfSense gateway and the second one is for testing, asterisk and also as a secondary DNS for all my domains.

      I'd like to collapse now those two machines into the pfSense box…so my question is if pfSense can do the secondary DNS task as well and not mixing it up with the internal DHCP/DNS forwarder....

      1 Reply Last reply Reply Quote 0
      • D Offline
        doktornotor Banned
        last edited by

        Install bind package and disable the forwarder.

        1 Reply Last reply Reply Quote 0
        • D Offline
          davorin
          last edited by

          Would it collide with my current internal DNS setup as I've setup forwarders for several company internal domains hooked up via OpenVPN connections.

          As I've specified them under "advanced settings"
          like:

          server=/customer1.net/x.x.x.x
          
          
          1 Reply Last reply Reply Quote 0
          • D Offline
            doktornotor Banned
            last edited by

            When you disable the forwarder, there is nothing to collide. I do not get your question at all.

            1 Reply Last reply Reply Quote 0
            • D Offline
              davorin
              last edited by

              Ah okay, I thought when I disable the forwarder the advanced options for specific DNS servers for specific domains will be lost then for dnsmasq…

              1 Reply Last reply Reply Quote 0
              • D Offline
                doktornotor Banned
                last edited by

                After you have disabled the DNS forwarder, dnsmasq will obviously NOT be runniing at all… So, whatever custom settings for that will be useless and unused. They certainly won't get picked up by bind.

                1 Reply Last reply Reply Quote 0
                • jimpJ Offline
                  jimp Rebel Alliance Developer Netgate
                  last edited by

                  Move the forwarder (dnsmasq) to port 5353 (or something else), then setup NAT rules to redirect your local interface queries to localhost:5353 and then your local clients can continue to perform recursive lookups via dnsmasq even with some other DNS server using port 53 for authoritative responses.

                  Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                  Need help fast? Netgate Global Support!

                  Do not Chat/PM for help!

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.