Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Best configuration option for forced OpenDNS and ability to create override clients

    Scheduled Pinned Locked Moved DHCP and DNS
    4 Posts 2 Posters 447 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      ck42
      last edited by

      There seems to be more than one way to skin this cat, so I'm wondering if maybe there's a better/best way to do it.

      Essentially, what I want to do is: Ensure that all DHCP clients receive the OpenDNS addresses (for filtering) and then block request if they happen to manually enter a non-OpenDNS server. Then....I want to be able to create/update (ideally) an alias list of client addresses that ARE allowed to reach non-OpenDNS servers.

      Thoughts?

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Just create a allow rule above your any any lan rule that uses your alias as source that allows dest tcp/udp 53

        Then below that create block rule to tcp/udp 53, then below that would be your any any rule.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        C 1 Reply Last reply Reply Quote 0
        • C
          ck42 @johnpoz
          last edited by

          @johnpoz

          On the second rule, the block rule to tcp/udp port 53...wouldn't that then prevent all the others from accessing DNS completely then? Wouldn't this second block rule instead be something that restricts those non-privileged users to only using the address of pfsense for DNS? Or....is this somehow maybe understood automatically that it would allow this?

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            you are correct sir - my bad, you need allow rule to the opendns IPs above your block that is allowed by any.. Good catch and my bad..

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.