Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS Resolver Question

    Scheduled Pinned Locked Moved DHCP and DNS
    12 Posts 4 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      ghkrauss
      last edited by

      When using the DNS resolver if other DNS servers are listed (ie Google IPv4 and IPv6) what is the impact? Does the DNS Resolver still go the to the DNS Root servers to start the resolution process.

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        if your using the resolver in resolver mode - those are never going to be used.

        Why would you have those listed if your using the resolver?  Did you set them in general settings?  Why?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07 | Lab VMs 2.8, 25.07

        1 Reply Last reply Reply Quote 0
        • P Offline
          pfcode
          last edited by

          @johnpoz:

          if your using the resolver in resolver mode - those are never going to be used.

          Why would you have those listed if your using the resolver?  Did you set them in general settings?  Why?

          NTP?

          Release: pfSense 2.4.3(amd64)
          M/B: Supermicro A1SRi-2558F
          HDD: Intel X25-M 160G
          RAM: 2x8Gb Kingston ECC ValueRAM
          AP: Netgear R7000 (XWRT), Unifi AC Pro

          1 Reply Last reply Reply Quote 0
          • G Offline
            ghkrauss
            last edited by

            Thanks John for the update. I am not using any entries in the General Setup for DNS. I just wanted a double check on the issue. It works great with just the DNS Resolver.

            Howard

            1 Reply Last reply Reply Quote 0
            • johnpozJ Offline
              johnpoz LAYER 8 Global Moderator
              last edited by

              NTP??? What does that have to do with google for dns?  Pfsense should be set to use itself, ie the resolver..  NTP would then use that to resolve any ntp servers.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 25.07 | Lab VMs 2.8, 25.07

              1 Reply Last reply Reply Quote 0
              • P Offline
                pfcode
                last edited by

                @johnpoz:

                NTP??? What does that have to do with google for dns?  Pfsense should be set to use itself, ie the resolver..  NTP would then use that to resolve any ntp servers.

                if you go System/General setup/Localization/Timeservers, there is a hint:

                Use a space to separate multiple hosts (only one required). Remember to set up at least one DNS server if a host name is entered here!

                The hosts were entered by NTP

                Release: pfSense 2.4.3(amd64)
                M/B: Supermicro A1SRi-2558F
                HDD: Intel X25-M 160G
                RAM: 2x8Gb Kingston ECC ValueRAM
                AP: Netgear R7000 (XWRT), Unifi AC Pro

                1 Reply Last reply Reply Quote 0
                • JKnottJ Offline
                  JKnott
                  last edited by

                  if your using the resolver in resolver mode - those are never going to be used

                  I had assumed pfSense used the servers listed on General Setup page.  But I just noticed the Enable Forwarding option on the DNS Resolver page.  So, since that isn't enabled, I'm apparently not using the specified servers, as verified with Wireshark.  As someone who's only running a home network, is there any advantage to either option?  I currently have 4 Google DNS servers configured, 2 IPv6 and 2 IPv4.

                  BTW, is there any higher authority than Google?  ;)

                  PfSense running on Qotom mini PC
                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                  UniFi AC-Lite access point

                  I haven't lost my mind. It's around here...somewhere...

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ Offline
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    "Remember to set up at least one DNS server if a host name is entered here!"

                    Well yeah pfsense going to need to be able to resolve.. Which using loopback, ie 127.0.0.1 and the resolve does that ;)

                    If your using the resolver, pfsense has NO use for any other dns settings.. It just needs to know to ask itself, ie the resolver running on it for anything pfsense directly would need to lookup or any services running on pfsense.

                    ntp-nameresolution.jpg
                    ntp-nameresolution.jpg_thumb

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 25.07 | Lab VMs 2.8, 25.07

                    1 Reply Last reply Reply Quote 0
                    • P Offline
                      pfcode
                      last edited by

                      @johnpoz:

                      "Remember to set up at least one DNS server if a host name is entered here!"

                      Well yeah pfsense going to need to be able to resolve.. Which using loopback, ie 127.0.0.1 and the resolve does that ;)

                      If your using the resolver, pfsense has NO use for any other dns settings.. It just needs to know to ask itself, ie the resolver running on it for anything pfsense directly would need to lookup or any services running on pfsense.

                      Thanks for the explanation.

                      Release: pfSense 2.4.3(amd64)
                      M/B: Supermicro A1SRi-2558F
                      HDD: Intel X25-M 160G
                      RAM: 2x8Gb Kingston ECC ValueRAM
                      AP: Netgear R7000 (XWRT), Unifi AC Pro

                      1 Reply Last reply Reply Quote 0
                      • P Offline
                        pfcode
                        last edited by

                        @johnpoz:

                        "Remember to set up at least one DNS server if a host name is entered here!"

                        Well yeah pfsense going to need to be able to resolve.. Which using loopback, ie 127.0.0.1 and the resolve does that ;)

                        If your using the resolver, pfsense has NO use for any other dns settings.. It just needs to know to ask itself, ie the resolver running on it for anything pfsense directly would need to lookup or any services running on pfsense.

                        one more question:  for OpenVPN server setup, if there is no DNS server defined in OpenVPN, should it use 127.0.0.1, or I have manually enter the loopback??

                        Release: pfSense 2.4.3(amd64)
                        M/B: Supermicro A1SRi-2558F
                        HDD: Intel X25-M 160G
                        RAM: 2x8Gb Kingston ECC ValueRAM
                        AP: Netgear R7000 (XWRT), Unifi AC Pro

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          What??  No a vpn use would use the IP address of pfsense as its dns.. Just like your dhcp clients use pfsense IP address in that network.  Set your openvpn to hand out say your lan IP of pfsense.  If you had a client 127.0.0.1… Its just going to try and ask itself..  Thats not going to work, unless its running a resolver of his own ;)

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07 | Lab VMs 2.8, 25.07

                          1 Reply Last reply Reply Quote 0
                          • P Offline
                            pfcode
                            last edited by

                            @johnpoz:

                            What??  No a vpn use would use the IP address of pfsense as its dns.. Just like your dhcp clients use pfsense IP address in that network.  Set your openvpn to hand out say your lan IP of pfsense.  If you had a client 127.0.0.1… Its just going to try and ask itself..  Thats not going to work, unless its running a resolver of his own ;)

                            I see, thanks.

                            Release: pfSense 2.4.3(amd64)
                            M/B: Supermicro A1SRi-2558F
                            HDD: Intel X25-M 160G
                            RAM: 2x8Gb Kingston ECC ValueRAM
                            AP: Netgear R7000 (XWRT), Unifi AC Pro

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.