Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Cannot resolve RFC 1918 ip's

    Scheduled Pinned Locked Moved DHCP and DNS
    6 Posts 3 Posters 784 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • cukalC
      cukal
      last edited by

      I've got a few remote pfSense instances running on remote locations and installed a new one over the weekend but I cannot understand what is going on:

      LAN clients resolve anything except a hostname that has an RFC 1918 ip. The same hostname resolves fine on pfSense itself (ssh access / nslookup).
      The RFC1918 hostname is coming from a domain I set up on Route53/AWS, been running like this for >3 years.

      On a LAN client I can set 8.8.8.8 as name server and then it resolves the same hostname to the RFC1918 ip just fine, switching back to pfSense DNS Resolver (the lan gateway ip basically) breaks RFC1918 hostnames from resolving, hosts with a public IP resolve just fine on the LAN client.

      Is there a settings on either pfSense or DNS Resolver somewhere that blocks LAN clients from resolving hostnames using a WAN name server that return an RFC1918 ip?

      I've got 3 other instances that are seemingly configured in the exact same way, LAN clients on those instances can resolve the hostname just fine.
      It's got me pretty much baffled, perhaps I will just take a backup of one "working" pfsense instances and applying it to this new one but I sure would like to know what I'm missing.

      Any help welcome!

      1 Reply Last reply Reply Quote 0
      • V
        viragomann
        last edited by

        Add its domain as private to the Resolver config. In Advanced Options enter:

        server:
        private-domain: "<the.hosts.domain>"
        
        1 Reply Last reply Reply Quote 0
        • cukalC
          cukal
          last edited by

          Thanks viragomann!! That fixed it straight away! You're faster than Enterprise TAC :p

          Next question is why the other pfSense instances resolve hosts without that entry in the Resolver - Advanced Options.

          1 Reply Last reply Reply Quote 0
          • V
            viragomann
            last edited by

            Possibly these pfSense are members of the requested domain?
            Or DNSSEC disabled?

            cukalC 1 Reply Last reply Reply Quote 0
            • cukalC
              cukal @viragomann
              last edited by

              No, the pfsense's are all configured under the same domain, albeit a different one from the one I'm trying to resolve from the LAN clients. Only difference is that the 3 other pfSense instances are all installs from +- 3-4 years ago (2.3.x) and went over time through all the upgrades to 2.4.5p1. This last instance was a fresh 2.4.5p1 install. Can't figure it out but I'm glad your suggestion worked!

              1 Reply Last reply Reply Quote 0
              • johnpozJ
                johnpoz LAYER 8 Global Moderator
                last edited by

                Pfsense does rebind protection, if you forward or resolve it will not return rfc1918 space.

                Clients like some windows will not do this, doesn't care.. But not good practice to have rfc1918 in public domains. You saying if you point client to 8.8.8.8 you can resolve some fqdn to rfc1918 points to bad idea!!

                As already mentioned you can allow pfsense (unbound or even dnsmasq, different setting) to resolve rfc1918 from something you forward to or resolve with like the above private domain setting.

                Or you could turn off rebind protection completely in pfsense.

                https://docs.netgate.com/pfsense/en/latest/services/dns/rebinding.html

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 24.11 | Lab VMs 2.8, 24.11

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.