Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense v2.4.5 not able to resolve Domain Overrides against itself

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    5 Posts 3 Posters 870 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      cthomas
      last edited by

      I'm having a new DNS issue, appears to be related to the v2.4.5 upgrade...

      pfSense is configured with 4 external DNS provides (Quad9, IPv4 + IPv6)

      I have a Domain Override configured for home.lan, which forwards to my local Domain Controllers
      5fb62d17-10dd-4565-acbe-7c4c57f53dda-image.png

      DHCP is configured to provide DHCP Users with the IP Address of pfSense

      From my workstation on the user lan, I can resolve A records for home.lan, which means pfsense is correctly applying the domain override and forwarding requests from the user lan to the domain controller(s) in the server network.

      pfSense itself, cannot resolve A records for home.lan, as a result, all of my aliases which reference dns names on home.lan are failing, and the tables are now empty.

      dea95d35-4933-44a9-b9b7-b0fa00bb51e4-image.png

      C 1 Reply Last reply Reply Quote 0
      • C
        cthomas @cthomas
        last edited by

        Was there a behavior change, or setting that might have been reverted as part of the 2.4.5 upgrade that might cause this issue?

        1 Reply Last reply Reply Quote 0
        • nzkiwi68N
          nzkiwi68
          last edited by

          I just tested my 2.4.5 build and it's working as expected.

          • Is your DNS resolver bound to all network interfaces?

          • Are your outbound queries only bound to LAN, I find that works best, esepcially if the domain override server is over a VPN.

          3f818673-afe7-43b2-9477-fdd490226e41-image.png

          0f8871d7-7cef-41c6-87b8-c75419cc88e2-image.png
          9a14e83e-90be-484e-8f11-0a0788f4924f-image.png

          1 Reply Last reply Reply Quote 0
          • C
            cthomas
            last edited by

            Reviewing my settings...

            System > General Settings > Disable DNS Forwarder is unchecked

            DNS Resolver Settings

            a711c467-a7ed-45ea-ab91-c988f084b1a5-image.png

            Custom Options syntax

            server:
            forward-zone:
            name: "."
            forward-ssl-upstream: yes
            forward-addr: 9.9.9.9@853
            forward-addr: 149.112.112.112@853
            forward-addr: 2620:fe::fe@853
            forward-addr: 2620:fe::9@853

            ...ct

            L 1 Reply Last reply Reply Quote 0
            • L
              Liam @cthomas
              last edited by

              @cthomas What do you have System -> General Setup -> DNS Server Settings ->Disable DNS Forwarder set? The description appears apropos to your situation:

              Do not use the DNS Forwarder/DNS Resolver as a DNS server for the firewall
              By default localhost (127.0.0.1) will be used as the first DNS server where the DNS Forwarder or DNS Resolver is enabled and set to listen on localhost, so system can use the local DNS service to perform lookups. Checking this box omits localhost from the list of DNS servers in resolv.conf.

              Cheers, Liam

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.