Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Having issues with pfSense box

    Scheduled Pinned Locked Moved General pfSense Questions
    22 Posts 5 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • maverickwsM
      maverickws @KOM
      last edited by maverickws

      @KOM

      OOHH! Excellent explanation ok it all makes sense. Removing the upstream DNS servers from config!
      I am always curious if you got the time and the will to let know about those other reasons, let it rip! :)

      You've been great, thanks for all the help!

      EDIT: It seems that disabling the option "Enable DNS Forwarding" isn't enough, I MUST remove the upstream DNS servers from General Settings, or it will still query those. Am I wrong?
      (bc I just disabled the option then went on Diagnostics > DNS Lookup and it kept querying the upstream servers.)

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @maverickws
        last edited by

        @maverickws said in Having issues with pfSense box:

        I MUST remove the upstream DNS servers from General Settings, or it will still query those. Am I wrong?

        Yes ;)

        The GUI page "Diagnostics => DNS Lookup" gets a listed of all name servers form the known systemwide resolver.conf file.
        That's where are listed 127.0.0.1 (pfSense itself, thus the Resolver) and all other listed name servers, the ones you added yourself on the "General" page.
        They are all tested by this PHP page.

        The Resolver itself, accsibkle at 127.0.0.1 @ port 53 - using default settings - doesn't use the these servers. It will question the 13 main root servers and dig downwards.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        maverickwsM 1 Reply Last reply Reply Quote 0
        • maverickwsM
          maverickws @Gertjan
          last edited by

          @Gertjan
          Hi there, thanks for your reply!

          So what you say is, just to confirm I am understanding fully, I may keep them under General Settings, they may be used by the webConfigurator when I query via Diagnostics > DNS Lookup, but as long as I have forwarding disabled on the DNS Resolver they won't be used. That's it?

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @maverickws
            last edited by Gertjan

            @maverickws IMHO : Yep.

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            1 Reply Last reply Reply Quote 1
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Yes, Diag > DNS Lookup will test all the defined DNS servers on the system.

              In the default config it will use the resolver directly though.

              That means you are running the resolver (Unbound) not the forwarder (DNSMasq). Unbound is not running in forwarding mode. You have not checked Disable DNS Forwarder in System > General Setup.

              Steve

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                @maverickws said in Having issues with pfSense box:

                I am always curious if you got the time and the will to let know about those other reasons, let it rip! :)

                Resolver is initially slower as it has to walk the DNS tree from the roots down until it gets its answer, but this is more private as you don't have a middleman seeing your DNS requests. Once resolver's cache fills up with the requests you make most frequently, it's just as fast as forwarder.

                Forwarder is fast because it talks to upstream DNS that most likely already has cached the ip address you're requesting, but it's less secure because whomever you're forwarding to knows what you're requesting.

                You can enable DNS over TLS to encrypt your DNS traffic from man-in-the-middle snooping by your ISP, for instance.

                B 1 Reply Last reply Reply Quote 1
                • B
                  bcruze @KOM
                  last edited by

                  @KOM said in Having issues with pfSense box:

                  @maverickws said in Having issues with pfSense box:

                  I am always curious if you got the time and the will to let know about those other reasons, let it rip! :)

                  Resolver is initially slower as it has to walk the DNS tree from the roots down until it gets its answer, but this is more private as you don't have a middleman seeing your DNS requests. Once resolver's cache fills up with the requests you make most frequently, it's just as fast as forwarder.

                  Forwarder is fast because it talks to upstream DNS that most likely already has cached the ip address you're requesting, but it's less secure because whomever you're forwarding to knows what you're requesting.

                  You can enable DNS over TLS to encrypt your DNS traffic from man-in-the-middle snooping by your ISP, for instance.

                  so if you enable DNS over TLS with just the resolver enabled, no other DNS servers listed in general..

                  how do you know the DNS servers are capable of handling that type of service?

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    You don't and generally they are not. You need to use forwarding mode for DNS over TLS to something you know does support it.

                    Steve

                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      I should also clarify that when I said middlemen can't snoop on you with resolver, I meant the DNS servers doing the replying eg Google, Level3 etc. Your ISP can still see what you're requesting, which is where encryption helps.

                      1 Reply Last reply Reply Quote 0
                      • maverickwsM
                        maverickws
                        last edited by

                        Thank you all.
                        I appreciate your comments on DNS Resolver and everything got sorted. Super!

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.