Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Unable to get DNS on VLAN working

    Scheduled Pinned Locked Moved DHCP and DNS
    14 Posts 3 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mikeelawson
      last edited by

      John,

      attached are some images of the network and screenshots. Rules have been created on VLAN.

      Regards and thanks,

      1_1544711531343_Screenshot 2.png 0_1544711531342_Screenshot 1.png 0_1544711545188_Network.png

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by johnpoz

        dude post up something can actually SEE!!!

        Can not make any of those out...

        How is anyone suppose to be able to make those out?

        0_1544712132647_viewthis.png

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        M 1 Reply Last reply Reply Quote 0
        • M
          mikeelawson @johnpoz
          last edited by

          @johnpoz 0_1544712736985_Network.png

          M 1 Reply Last reply Reply Quote 0
          • M
            mikeelawson @mikeelawson
            last edited by

            @mikeelawson 2_1544712994693_Screenshot 3.png 1_1544712994692_Screenshot 2.png 0_1544712994692_Screenshot 1.png

            1 Reply Last reply Reply Quote 0
            • GertjanG
              Gertjan
              last edited by Gertjan

              Disable your first and second rule.
              Save. Apply.
              DNS goes through ?

              edit : Probably not related : What are your intentions with the "Custom Options" on the DNS General Settings page ?

              No "help me" PM's please. Use the forum, the community will thank you.
              Edit : and where are the logs ??

              1 Reply Last reply Reply Quote 0
              • M
                mikeelawson
                last edited by

                @gertjan

                Ok this did not work. I can ping 9.9.9.9 and 1.1.1.1 but cannot do name resolution (NSLOOKUP does not work). Directly connected avoiding VLAN, all works.

                GertjanG 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Nslookup doesn't work where? You have setup tls forwarding. Can pfsense resolve using that - test with dns lookup under diagnostics..

                  Can your client talk to pfsense even for dns... do a simple query for say pfsense own name.. Does that resolve?

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  M 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @mikeelawson
                    last edited by

                    @mikeelawson said in Unable to get DNS on VLAN working:

                    @gertjan

                    Ok this did not work. I can ping 9.9.9.9 and 1.1.1.1 but cannot do name resolution (NSLOOKUP does not work). Directly connected avoiding VLAN, all works.

                    Make your third rule a "pass-all". Change the source "VLAN30 net" for "any" or "*".
                    Now your firewall is transparent for everything as long as it is "IPv4".

                    Rule 1 and 2 are disabled, right ??

                    It should work.

                    If not, the issue is : your VLAN settings (pfsense and/or your switch).

                    Btw : easy to check if unbound is listening on the "VLAN30" network.

                    sockstat -4 -l | grep "53"
                    

                    I check my interface "192.168.2.1" (my OPT1 interface) :

                    dig @192.168.2.1 microsoft.com +short
                    40.112.72.205
                    40.113.200.201
                    104.215.148.63
                    13.77.161.179
                    40.76.4.15
                    

                    dig will hit 192.168.2.1 using port 53.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mikeelawson @johnpoz
                      last edited by

                      @johnpoz

                      John,

                      NSLOOKUP does not work under VLAN30 but does work under direct connection to LAN

                      I setup TLS forwarding so that I can secure my DNS comms with providers

                      DNS lookup under diagnostics works (see attached) 0_1544720752504_DNS Lookup.png

                      Did a simple query to Pfsense on Corporate LAN worked, under VLAN30 failed

                      1 Reply Last reply Reply Quote 0
                      • M
                        mikeelawson @Gertjan
                        last edited by

                        0_1544721714020_Ping 2.png @gertjan

                        I did this on VLAN30 and didn't work I am dirrectly connecting my Mac onto VLAN30 before I connect to USG switch to test everything works ![0_1544721303922_Ping 2.png](Uploading 0%)

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by johnpoz

                          Well as already asked did you dick with your ACLs for unbound.. Did you validate its actually listening on your vlan30 interface?

                          Do you have any rules floating rules that would be blocking or any port forwards to redirect dns?

                          If unbound is listening on the interface, and you all it on firewall rules.. If unbound doesn't allow you to query then you would get a REFUSED... But since you used the +short can not be sure what the actual details are.

                          BTW: 3.5ms is a pretty shitty local network ping response..

                          user@uc:~$ ping 192.168.2.253
                          PING 192.168.2.253 (192.168.2.253) 56(84) bytes of data.
                          64 bytes from 192.168.2.253: icmp_seq=1 ttl=64 time=0.836 ms
                          64 bytes from 192.168.2.253: icmp_seq=2 ttl=64 time=0.332 ms
                          64 bytes from 192.168.2.253: icmp_seq=3 ttl=64 time=0.304 ms
                          64 bytes from 192.168.2.253: icmp_seq=4 ttl=64 time=0.343 ms
                          64 bytes from 192.168.2.253: icmp_seq=5 ttl=64 time=0.328 ms
                          64 bytes from 192.168.2.253: icmp_seq=6 ttl=64 time=0.364 ms
                          64 bytes from 192.168.2.253: icmp_seq=7 ttl=64 time=0.330 ms
                          ^C
                          --- 192.168.2.253 ping statistics ---
                          7 packets transmitted, 7 received, 0% packet loss, time 6000ms
                          rtt min/avg/max/mdev = 0.304/0.405/0.836/0.177 ms
                          user@uc:~$ 
                          

                          That is a VM on one of my vlans, ping pfsense..

                          And your 2nd upload didn't work!

                          ![0_1544721303922_Ping 2.png](Uploading 0%)
                          

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            mikeelawson @johnpoz
                            last edited by

                            @johnpoz

                            John,

                            Found it, the original config was correct, had a firewall on the Mac that was preventing this. My apologies for taking up your time on this matter. As soon as this was disabled all worked.

                            Regards,

                            Mike

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.