Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Alternative DNS Servers - no filter/censorship (buydomains.com problem)

    Scheduled Pinned Locked Moved General pfSense Questions
    72 Posts 11 Posters 16.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MrGlasspoole
      last edited by

      @hda:

      Meh, what is your connection protocol to your ISP ….

      What do you mean by protocol?
      It's DOCSIS, IPv4…

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Static - pictures of WAN and gateway settings are ad top of this page  :)

        At the top of what page?

        Forum users can set how many messages per page are shown.

        Please provide a link to the exact post or attach it again.  Thanks.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • M
          MrGlasspoole
          last edited by

          Sorry: https://forum.pfsense.org/index.php?topic=87678.msg483594#msg483594

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Yeah, that's a static on 10.0.0.1.  If you're bridged to the internet you should, somehow, get a public IP on WAN.  This is usually accomplished with DHCP or PPPoE.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • H
              hda
              last edited by

              @MrGlasspoole:

              What do you mean by protocol?
              It's DOCSIS, IPv4…

              So, then probably your protocol is a DHCP on WAN, anyway you have to test.
              Beware if it works or is supported by ISP Unitymedia:

              • "front door" is open, control inbound ports on WAN
                -  may lose the phone capabilities.
              1 Reply Last reply Reply Quote 0
              • chpalmerC
                chpalmer
                last edited by

                You don't have any DNS servers set up on your General page but your WAN is setup for static!

                I believe the pfSense box will use DHCP to locate needed DNS. (Ive not tested this)

                On the General page fill in at least one DNS and click both boxes below.

                Triggering snowflakes one by one..
                Intel(R) Core(TM) i5-4590T CPU @ 2.00GHz on an M400 WG box.

                1 Reply Last reply Reply Quote 0
                • M
                  MrGlasspoole
                  last edited by

                  I made a test with the settings in the attachments.
                  I also tried it with setting 8.8.8.8 in the general page.

                  In the dashboard i see then:
                  WAN (DHCP): a public ip but different then the one i have in my ISPs router
                  DNS server(s): the same like in my ISPs router

                  and i get "unable to obtain update status" - so no internet.

                  1 Reply Last reply Reply Quote 0
                  • K
                    kejianshi
                    last edited by

                    I guess you don't like the way I suggested to do it?

                    1 Reply Last reply Reply Quote 0
                    • M
                      MrGlasspoole
                      last edited by

                      Just testing and you wrote: pointing to the modem is how grandmother did

                      The DMZ way (how it is now) works. But if it's better without double NAT and i can get it to work?

                      But from looking around more on that topic and this box it seems like nobody has it working.
                      Looks like only business tariff customers can use the bridge cause they get a second IP.

                      1 Reply Last reply Reply Quote 0
                      • M
                        MrGlasspoole
                        last edited by

                        I got a new router from the ISP and had to change stuff because on that stupid thing you can't change the IP to another subnet.
                        So i did read through this thread again and need to ask again even if you kill me :(

                        I can't get bridge mode here so i have to set:
                        Interfaces > WAN
                        IPv4 Upstream gateway: GW_WAN - 192.168.0.1
                        Right?

                        I had kejianshi's suggestion running now the last 2 years:
                        @kejianshi:

                        Go to system > General

                        delete all your server IPs.

                        uncheck Allow DNS server list to be overridden by DHCP/PPP on WAN

                        uncheck  Do not use the DNS Forwarder as a DNS server for the firewall

                        save.

                        Then go to DNS forwarder and make sure its off.  Save.

                        Then go to DNS resolver and make sure its on.
                        Turn on DNSSEC

                        Save

                        BUT still don't understand if for this setting and with no bridge mode his statement is true:
                        @kejianshi:

                        Now, you should have raw, un-tampered unmolested DNS from the root servers.

                        Also still others here wrote you have to put a DNS server in System > General Setup

                        So with kejianshi's suggestion and without bridge mode I'm using the ISP's DNS server - yes or no?

                        I also saw on the Timeserves setting:
                        Remember to set up at least one DNS server if a host name is entered here!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.