Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS configuration

    Scheduled Pinned Locked Moved DHCP and DNS
    17 Posts 5 Posters 689 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JKnottJ
      JKnott
      last edited by

      @Gertjan said in DNS configuration:

      These DNS requests come from pfSense, or from one of the LAN devices ?

      What I'm seeing on the wire is from pfSense. It's the local DNS server that all my devices use. I've seen requests from Youtube, Indeed and others, that would typically originate from my desktop system. So, they'd request from pfSense, which in turn requests from elsewhere. I'll try deleting those 2 servers and see what happens.

      PfSense running on Qotom mini PC
      i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
      UniFi AC-Lite access point

      I haven't lost my mind. It's around here...somewhere...

      1 Reply Last reply Reply Quote 0
      • JKnottJ
        JKnott
        last edited by JKnott

        I just deleted those servers and rebooted pfSense. I again see a DNS request to 2001:4860:4802:34::a, which is a Google DNS server. The query is for gmail, which is likely coming from my desktop computer, but might also be from my cell phone or tablet. Regardless, the source IP is my pfSense firewall, as would be expected, when it's the local DNS server. Why is it doing this, when configured as a resolver? I am also seeing some that are likely root servers, 2001:500:d937::30. I also see 216.239.34.10, which is Google.

        Why am I seeing Google DNS requests, when there are no servers configured for them? If fact, I have never configured that IPv4 address.

        PfSense running on Qotom mini PC
        i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
        UniFi AC-Lite access point

        I haven't lost my mind. It's around here...somewhere...

        1 Reply Last reply Reply Quote 0
        • johnpozJ
          johnpoz LAYER 8 Global Moderator
          last edited by johnpoz

          If unbound is resolver, which is default.. it talks to roots to get the NS for the tld, then asks the tld NS for for the NS for the domain in question. Then asks the NS for domain.tld for the actual record.

          You state slightly other IPs... So how and the F do you think the IPs you have setup have anything to do with it?

          Yeah in the process of resolving say google.com - going to have to talk to NS that are authoritative for google.com.. Which yeah going to be on a google owned IP ;)

          Do a simple dig +trace if you want understand how the resolving process works.

          How it you have been in the biz for how many years and you don't understand basic dns?

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Not everybody knows everything. I've been doing this for years and I still got schooled for assuming that I could port-forward traffic to a non-existent address until I stopped and thought about it.

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by johnpoz

              Agreed... But dns is how the internet works.. And he is a techy.. Never wondered how www.google.com gets you IP address?

              Pretty sure he has been around for the birth of the internet ;) Same as me - how you got an IP from a name was pretty essential in understanding how the network works, and it didn't come up until now?

              I can understand the nontechy kids of today, or grandma etc. not getting it... But he is a tech guy that works in the biz.. And if not mistaken for many many years - like before there even was an internet ;) So how it 30 some years latter just not getting to figuring it out? That is my question.

              Not asking him how he doesn't know the correct formatting for bind conf file.. Or how to register a authoritative ns, etc But understanding the basic concept of how it works.. You would of thunk would be something he looked into years and years ago just saying.

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              GertjanG 1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott
                last edited by

                @johnpoz said in DNS configuration:

                Agreed... But dns is how the internet works.. And he is a techy.. Never wondered how www.google.com gets you IP address?

                Yes, I have been around for years, but never really focused on DNS. I was just going through the psSense book and decided to see what was happening with my own system.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator
                  last edited by

                  Just nuts... Here is a fantastic book if you want to get some better understanding.
                  http://shop.oreilly.com/product/9780596100575.do

                  They have a dns and IPv6 you prob be more interested in.
                  http://shop.oreilly.com/product/0636920020158.do

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  1 Reply Last reply Reply Quote 0
                  • KOMK
                    KOM
                    last edited by

                    DNS and BIND, 5th Edition: 648 pages

                    DNS and BIND on IPv6: 54 pages

                    d6j542d-6fbbd2d6-8801-4016-94aa-63dae5560124.png

                    1 Reply Last reply Reply Quote 0
                    • kiokomanK
                      kiokoman LAYER 8
                      last edited by

                      eh knowledge come to a price

                      ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                      Please do not use chat/PM to ask for help
                      we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                      Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                      KOMK 1 Reply Last reply Reply Quote 0
                      • KOMK
                        KOM @kiokoman
                        last edited by

                        @kiokoman Yes, but how is the IP6 book a tenth of the size? I assume it's a typo, but I still thought it was funny.

                        1 Reply Last reply Reply Quote 0
                        • kiokomanK
                          kiokoman LAYER 8
                          last edited by

                          nope. "this concise book provides the essentials you need to support this protocol "
                          generally speaking someone should read the first book and than the second one. dns concept are, for the most, the same for ipv4 and ipv6

                          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
                          Please do not use chat/PM to ask for help
                          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
                          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

                          1 Reply Last reply Reply Quote 1
                          • johnpozJ
                            johnpoz LAYER 8 Global Moderator
                            last edited by

                            Yeah you need to read the first one first ;) But I threw in link to IPv6 one because that would get his motor running.. He is the local ipv6 Drum Major ;)

                            An intelligent man is sometimes forced to be drunk to spend time with his fools
                            If you get confused: Listen to the Music Play
                            Please don't Chat/PM me for help, unless mod related
                            SG-4860 24.11 | Lab VMs 2.8, 24.11

                            1 Reply Last reply Reply Quote 0
                            • GertjanG
                              Gertjan @johnpoz
                              last edited by Gertjan

                              [google]
                              @johnpoz said in DNS configuration:

                              he has been around for the birth of the internet ;)

                              I remember very well, in the old days when Compuserve offered something called a 'gateway' to a new network called 'Internet' (had to install a program called "SPRY Mosaic" to 'browse' that network). Yahoo had a site that permits to search the available resources. Google, as a site and competitor, came some time afterwards.

                              No "help me" PM's please. Use the forum, the community will thank you.
                              Edit : and where are the logs ??

                              1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator
                                last edited by johnpoz

                                Remember the old trumpet winsock program to get tcp/ip back in the day ;)

                                So yeah back at the birth... So how is some 25-30 years later just now getting around to figuring out how dns works.. Just funny to me is all. Happy to help... That book is very good read.. Back when I read it 1st or 2nd edition ;) Early 1990s time frame.

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                JKnottJ 1 Reply Last reply Reply Quote 1
                                • JKnottJ
                                  JKnott @johnpoz
                                  last edited by

                                  @johnpoz said in DNS configuration:

                                  So yeah back at the birth... So how is some 25-30 years later just now getting around to figuring out how dns works.

                                  As someone else mentioned, you can't know everything and I hadn't focused on DNS. I am aware of how it works, with root servers etc., but my attention was elsewhere. All I was doing the other day is seeing how pfSense matched up with what was in the book and used Wireshark to see what was happening, as I often do.

                                  PfSense running on Qotom mini PC
                                  i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                                  UniFi AC-Lite access point

                                  I haven't lost my mind. It's around here...somewhere...

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post
                                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.