• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to use non-standard DNS port in pfSense? In OpenWRT I simply add # after IP

Scheduled Pinned Locked Moved DHCP and DNS
6 Posts 2 Posters 963 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • W
    warheat1990
    last edited by Aug 26, 2017, 1:01 PM

    In OpenWRT, I can add # after IP to specify which port I want to use for DNS.

    Pic here:

    The reason I want to do this is because my ISP is hijacking the DNS port. Please don't bother with "it's time to change to another ISP" because I don't have that choice.

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Aug 26, 2017, 2:07 PM

      Not sure why you think your isp is not going to just intercept 5353 as well.. Do they also listen on 443?  You could try that.. But setting dnsmasq (forwarder) to use a different port is simple server line in the custom options line

      server=208.67.222.222#5353

      See attached test of this.. You could prob do it on the resolver as well, but to be honest the resolver (unbound) in forwarder mode is just pointless ;)  If your going to just forward might as well just use the forwarder..

      dnson5353.png
      dnson5353.png_thumb

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • W
        warheat1990
        last edited by Aug 26, 2017, 2:38 PM

        @johnpoz:

        Not sure why you think your isp is not going to just intercept 5353 as well.. Do they also listen on 443?

        Because I've been using 208.67.222.222#5353 for years in my OpenWRT, I just changed from OpenWRT to pfSense recently. They're stupid enough to ignore 5353 but not 443.

        1 Reply Last reply Reply Quote 0
        • W
          warheat1990
          last edited by Aug 26, 2017, 3:06 PM

          @johnpoz:

          Not sure why you think your isp is not going to just intercept 5353 as well.. Do they also listen on 443?  You could try that.. But setting dnsmasq (forwarder) to use a different port is simple server line in the custom options line

          server=208.67.222.222#5353

          See attached test of this.. You could prob do it on the resolver as well, but to be honest the resolver (unbound) in forwarder mode is just pointless ;)  If your going to just forward might as well just use the forwarder..

          By the way, it's not working for me. IPLeak and dnsleaktest is still showing my ISP DNS.

          I also tried changing Listen Port from 53 to 5353 and I no longer have internet access unless I change it back.

          Any idea why? Do I also need to remove DNS Server in System > General Setup?

          1 Reply Last reply Reply Quote 0
          • J
            johnpoz LAYER 8 Global Moderator
            last edited by Aug 26, 2017, 3:47 PM

            Well yeah or they would also be forwarded too..

            You also need to make sure you do not allow override from dhcp.

            uncheckdnsfromdhcp.png
            uncheckdnsfromdhcp.png_thumb

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • W
              warheat1990
              last edited by Aug 26, 2017, 4:45 PM

              @johnpoz:

              Well yeah or they would also be forwarded too..

              You also need to make sure you do not allow override from dhcp.

              I already unchecked "do not allow" but removing DNS Server from General Setup did it. Thanks for the help! Appreciate it.

              1 Reply Last reply Reply Quote 0
              6 out of 6
              • First post
                6/6
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                This community forum collects and processes your personal information.
                consent.not_received