Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS - Removing Service Provider Defauits

    Scheduled Pinned Locked Moved DHCP and DNS
    16 Posts 5 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD Offline
      Derelict LAYER 8 Netgate
      last edited by

      That's great, but there is a lot more to it than that.

      Is the resolver in resolver or forwarding mode?

      If it is in resolver mode, then your selected DNS servers will not be used in any capacity other than for queries made by the firewall itself.

      Client queries to your resolver will start at the roots and work down to resolve all names not already in its cache.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • C Offline
        CaladorGCS
        last edited by

        @Derelict:

        That's great, but there is a lot more to it than that.

        Is the resolver in resolver or forwarding mode?

        If it is in resolver mode, then your selected DNS servers will not be used in any capacity other than for queries made by the firewall itself.

        Client queries to your resolver will start at the roots and work down to resolve all names not already in its cache.

        Under - System > General Setup> DNS Server Settings
        DNS Server Override is checked
        Disable DNS Forwarder is unchecked

        Under - Services > DNS Forwarder > General DNS Forwarder Options
        Enable DNS forwarder is unchecked

        Under - Services > DNS Resolver > General Settings > General DNS Resolver Options
        Enable DNS forwarder is checked

        pfSense© running on…

        • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

        • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

        Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
        Access Point - (2) Unifi 802.11ac Dual-Radio PRO

        1 Reply Last reply Reply Quote 0
        • DerelictD Offline
          Derelict LAYER 8 Netgate
          last edited by

          One more piece. What DNS servers are you telling your inside clients to use? This is in the DHCP servers or static client configurations.

          Bottom line is if you are using the Resolver you might as well just give up trying to use "highest-performing" DNS servers. The resolver will use what the internet tells it to use. If you are using either DNS resolver or forwarder, once something is in the cache it will be given to inside clients nearly-instantaneously anyway. This probably falls into the "don't overthink it" category.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • C Offline
            CaladorGCS
            last edited by

            @Derelict:

            One more piece. What DNS servers are you telling your inside clients to use? This is in the DHCP servers or static client configurations.

            Bottom line is if you are using the Resolver you might as well just give up trying to use "highest-performing" DNS servers. The resolver will use what the internet tells it to use. If you are using either DNS resolver or forwarder, once something is in the cache it will be given to inside clients nearly-instantaneously anyway. This probably falls into the "don't overthink it" category.

            I didn't input any DNS servers on that list, just left them all blank.

            pfSense© running on…

            • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

            • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

            Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
            Access Point - (2) Unifi 802.11ac Dual-Radio PRO

            1 Reply Last reply Reply Quote 0
            • C Offline
              CaladorGCS
              last edited by

              1st image -    System > General Setup > DNS Server Settings

              2nd image -  Services > DHCP Server > LAN > Server

              pfSenseGen.PNG
              pfSenseGen.PNG_thumb
              pfSenseSer.PNG
              pfSenseSer.PNG_thumb

              pfSense© running on…

              • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

              • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

              Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
              Access Point - (2) Unifi 802.11ac Dual-Radio PRO

              1 Reply Last reply Reply Quote 0
              • pttP Offline
                ptt Rebel Alliance
                last edited by

                Just "Uncheck"  Allow DNS server list to be overridden by DHCP/PPP on WAN

                DNS.PNG_thumb
                DNS.PNG

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  It is up to you how to design your DNS. What is it you are looking for? What are you looking to accomplish?

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • C Offline
                    CaladorGCS
                    last edited by

                    Nice, that definitely took care of them!
                    DNS server(s)

                    127.0.0.1
                      63.251.129.1
                      68.105.28.11
                      156.154.71.22
                      8.8.8.8

                    Mostly just trying to get as secure as possible without affecting the speed I love so much.

                    Thank you so much! For your time and patience!

                    pfSense© running on…

                    • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

                    • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

                    Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
                    Access Point - (2) Unifi 802.11ac Dual-Radio PRO

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      CaladorGCS
                      last edited by

                      @Derelict:

                      It is up to you how to design your DNS. What is it you are looking for? What are you looking to accomplish?

                      I need to read up more on the different DNS setups so I can really figure that out. "Secure as possible without affecting the speed" sounds too general for what your asking.

                      pfSense© running on…

                      • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

                      • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

                      Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
                      Access Point - (2) Unifi 802.11ac Dual-Radio PRO

                      1 Reply Last reply Reply Quote 0
                      • T Offline
                        TS_b Banned
                        last edited by

                        https://calomel.org/unbound_dns.html

                        1 Reply Last reply Reply Quote 0
                        • C Offline
                          CaladorGCS
                          last edited by

                          @TS_b:

                          https://calomel.org/unbound_dns.html

                          Thank you!

                          pfSense© running on…

                          • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

                          • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

                          Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
                          Access Point - (2) Unifi 802.11ac Dual-Radio PRO

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.