Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Does DNS Redirection Bypass DNSBL?

    pfBlockerNG
    4
    6
    938
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mifronte
      last edited by

      If I am redirecting all DNS Requests to pfSense as specified in this How-To,will DNSBL be by passed or will the DNSBL still take effects?

      SuperMicro Atom C2758 A1SRI-2758F 16GB
      2.7.2 (amd64)

      1 Reply Last reply Reply Quote 0
      • RonpfSR
        RonpfS
        last edited by

        If you are redirecting DNS Requests to a pfsense with DNSBL enabled, then DNSBL will NOT be bypassed.

        2.4.5-RELEASE-p1 (amd64)
        Intel Core2 Quad CPU Q8400 @ 2.66GHz 8GB
        Backup 0.5_5, Bandwidthd 0.7.4_4, Cron 0.3.7_5, pfBlockerNG-devel 3.0.0_16, Status_Traffic_Totals 2.3.1_1, System_Patches 1.2_5

        1 Reply Last reply Reply Quote 0
        • M
          mifronte
          last edited by

          Thanks.  Yes, I am redirecting to pfSense so that all DNS requests goes through DNSBL.

          SuperMicro Atom C2758 A1SRI-2758F 16GB
          2.7.2 (amd64)

          1 Reply Last reply Reply Quote 0
          • T
            Tom7755
            last edited by

            Why would someone want to do this?

            1 Reply Last reply Reply Quote 0
            • M
              mifronte
              last edited by

              I am doing this to ensure that all DNS requests goes through my local DNS resolver and any DNS servers that I have configured to be the upstream DNS.  Some clients can manually set their DNS settings and this will prevent that attempt to by-pass my DNS policy.

              For example, for a family with children, the parents may want to use OpenDNS to implement some parental filtering.  A smart teenager may by-pass OpenDNS by specifying the Google DNS on their client.  This redirection will intercept all DNS queries and ensure that OpenDNS is used.

              I personally use pfBlocerNG with DNSBL to block access to sites that are on the lists that I have configured.  I discovered that some Google devices have Google's DNS hardcoded into their firmware to reach Google's data collection servers.  This redirection ensure that these devices don't circumvent my blocked lists.  Off course this does nothing if the IP address is hardcoded, but then I hope pfBlockerNG IPv4 and Ipv6 feature will prevent those scenarios.

              SuperMicro Atom C2758 A1SRI-2758F 16GB
              2.7.2 (amd64)

              1 Reply Last reply Reply Quote 0
              • valnarV
                valnar
                last edited by

                That's one way, the nice way.  Another way is to simply put in a firewall block on port 53 except for pfSense and let your kids figure out why they can't get anywhere.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.