Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense with pihole correct configuration?

    Scheduled Pinned Locked Moved DHCP and DNS
    42 Posts 4 Posters 9.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • johnpozJ
      johnpoz LAYER 8 Global Moderator @A Former User
      last edited by johnpoz

      @jwj said in Pfsense with pihole correct configuration?:

      ODoH, is the latest BS

      But the company providing the proxy for that and then the dns provider - they would never collude ;) heheheh... They only have your privacy in mind ;)

      Its like they are on a mission to F up dns beyond nonsense.. In the sake of privacy my ASS!!

      If you are concerned about your isp easy sniffing your dns, then just resolve through a vpn tunnel.. But as stated - they still handling your traffic - so not like they can not find out where your going and when, etc.

      The only way to hide where your going from your isp is full vpn.. But then your just handing all that info over to your vpn provider and giving them money to to boot..

      If you really care about your privacy, DNS is the least of your worries.

      QFT

      Here is the thing - anything that centralizes dns, and lets devices or software just use what they want other than what you tell them for dns.. Is not in anyone's best interest that is for damn sure.

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      ? 1 Reply Last reply Reply Quote 1
      • ?
        A Former User @johnpoz
        last edited by A Former User

        @johnpoz Yeah man. I just don't get the amount of attention this gets or the amount of emotional energy people put into it. Truly a not seeing the forest for the trees situation.

        This guy should know better than give any attention to it:

        https://www.schneier.com/blog/archives/2020/12/oblivious-dns-over-https.html

        and, well, I guess this is an unsurprising bit of click bait:

        https://arstechnica.com/information-technology/2020/12/cloudflare-apple-and-others-back-a-new-way-to-make-the-internet-more-private/

        Was going to wade into the comments. Decided to not inflict that pain on myself.

        1 Reply Last reply Reply Quote 1
        • A
          agaitan026 @A Former User
          last edited by

          @jwj thank you for your tips. I tried but not working. Im not sure if its because i have whm/cpanel on one of my VMs if i try to browse to a website from whm vm doesnt works but if i try google.com it works

          What im doing wrong?

          Thank you

          ? johnpozJ 2 Replies Last reply Reply Quote 0
          • ?
            A Former User @agaitan026
            last edited by A Former User

            @agaitan026 I have no clue. Sorry. 😐

            1 Reply Last reply Reply Quote 1
            • johnpozJ
              johnpoz LAYER 8 Global Moderator @agaitan026
              last edited by johnpoz

              @agaitan026 said in Pfsense with pihole correct configuration?:

              Im not sure if its because i have whm/cpanel on one of my VMs

              Having a hard time coming up with how that would have anything to do with anything... Unless its trying to do something with dns on its own, and not paying attention to your settings in unbound, etc. And your trying to use it to figure out your dns working or not working?

              Forget whatever it is your doing on some vm..

              Do a simple query to pfsense IP.. Does dns work or not? Use your fav tool, dig, host, nslookup, etc..

              Is pfsense running as a VM?

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              A 1 Reply Last reply Reply Quote 0
              • A
                agaitan026 @johnpoz
                last edited by

                @johnpoz correct, pfsense is running on a vm, pihole is in another vm with another vlan

                johnpozJ 1 Reply Last reply Reply Quote 0
                • johnpozJ
                  johnpoz LAYER 8 Global Moderator @agaitan026
                  last edited by

                  Ok so pfsense is a vm, which we have no idea if how you have setup and connected to the internet.

                  Does pfsense dns work or not - its 2 seconds to validate via simple queries to it via your fav tool.. Dig is mine..

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  A 1 Reply Last reply Reply Quote 1
                  • A
                    agaitan026 @johnpoz
                    last edited by agaitan026

                    @johnpoz working
                    1527b1f3-312b-42fe-af29-4c9938ab03ba-image.png

                    i have pfsense 192.168.1.1 and pihole 192.168.20.26 another vlan

                    i can browse any website except websites inside the cpanel vm

                    like this

                    ecbca47e-a912-4163-a923-a85a71dc5011-image.png

                    on yellow a domain from whm vm in the same machine as pfsense and pihole

                    strange by enabling this setting in Services / DNS Resolver / General settings

                    DNS Query Forwarding
                    Enable Forwarding ModeIf this option is set, DNS queries will be forwarded to the upstream DNS servers defined under System > General Setup or those obtained via DHCP/PPP on WAN (if DNS Server Override is enabled there).

                    now i can browse whm websites without issues im not sure if thats the correct behavior and setting

                    johnpozJ 1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator @agaitan026
                      last edited by johnpoz

                      Have already been over this multiple times..

                      There is not right or wrong setting be it you want to forward or not forward...

                      When you enable that - you forward, when its not enabled you resolve..

                      Where you resolving when you tried to lookup dbsnetwork.net?

                      Seems you point the NSs for that to yourself? Your hosting the NS for that domain it seems?

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      A 1 Reply Last reply Reply Quote 1
                      • A
                        agaitan026 @johnpoz
                        last edited by

                        @johnpoz correct ns point to same ip

                        johnpozJ 1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator @agaitan026
                          last edited by

                          Well you have a problem there.. I see that they don't even answer via tcp as well.

                          So you have communication problem talking to yourself it seems then.. Hosting dns on the same device is not a good idea! The 2 NSs are on the same network.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          A 1 Reply Last reply Reply Quote 0
                          • A
                            agaitan026 @johnpoz
                            last edited by

                            @johnpoz yes thats true. I should use maybe amazon route 53 or another service. I got another vm that points to route 53 ns and doesnt have any issue.

                            So that's my big problem. A basic ns thing

                            You recommend another rather than amazon route 53?

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.