Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Second DNS how to?

    Scheduled Pinned Locked Moved pfBlockerNG
    6 Posts 2 Posters 990 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      MrGlasspoole
      last edited by

      It happened what i thought will happen if i but a block on the whole network.
      My parents bitch why this and that site is not working.

      So how can i make a second DNS for other peoples devices here in the house that does not use pfBlockerNG?

      1 Reply Last reply Reply Quote 0
      • BBcan177B
        BBcan177 Moderator
        last edited by

        It's basic networking. Just change the LAN devices to use a different DNS server in its IP settings. Set it to something like 8.8.8.8. If the Lan devices are DHCP, then you could define different settings for the pool.

        "Experience is something you don't get until just after you need it."

        Website: http://pfBlockerNG.com
        Twitter: @BBcan177  #pfBlockerNG
        Reddit: https://www.reddit.com/r/pfBlockerNG/new/

        1 Reply Last reply Reply Quote 0
        • M
          MrGlasspoole
          last edited by

          Not using pfSense as DNS means my DNS Resolver rules do not work anymore i guess?

          1 Reply Last reply Reply Quote 0
          • BBcan177B
            BBcan177 Moderator
            last edited by

            You could try to use the DNS forwarder (DNSMasq) on port 53 for general users and then set the resolver to port 5353 for specific Lan clients. Then you have some configurability. Never done it myself but I'm sure it's doable.

            "Experience is something you don't get until just after you need it."

            Website: http://pfBlockerNG.com
            Twitter: @BBcan177  #pfBlockerNG
            Reddit: https://www.reddit.com/r/pfBlockerNG/new/

            1 Reply Last reply Reply Quote 0
            • M
              MrGlasspoole
              last edited by

              Hm, i was told to disable the DNS forwarder for raw, un-tampered unmolested DNS from the root servers here:
              https://forum.pfsense.org/index.php?topic=87678.msg483054#msg483054

              1 Reply Last reply Reply Quote 0
              • BBcan177B
                BBcan177 Moderator
                last edited by

                You are mixing things up.

                pfSense has two DNS services:

                1. DNS Forwarder (DNSmasq)
                2. DNS Resolver (Unbound)

                Unbound can be configured in Forwarder or Resolver mode.

                So my suggestion was to use DNSmasq for port 53 (general user) and then have unbound on port 5353. So you can then force the LAN users to the correct DNS service.

                If you need more help with that. Check the DNS threads and/or post there for more detailed help.

                "Experience is something you don't get until just after you need it."

                Website: http://pfBlockerNG.com
                Twitter: @BBcan177  #pfBlockerNG
                Reddit: https://www.reddit.com/r/pfBlockerNG/new/

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.