Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS resolving issue

    Scheduled Pinned Locked Moved DHCP and DNS
    3 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      spectre694
      last edited by

      I'm running 2.3_1.

      My setup actually has two WAN's (one is disabled for now) When I use my DSL connection pfSense works flawlessly I can browse download watch videos etc.

      If I plug the other WAN [SAT] (same port unplugged DSL first) then only pfSense has internet. I can update install packages on the pfSense box but if I try to browse on any client I get a name cannot be resolved. If I manually set the DNS server on each client PC then browsing works just fine over the second WAN for some reason.

      Setting the DNS servers manually in pfSense did not work (though I may have done that wrong it is my first time using it)

      I can post any logs or anything that you guys might need just let me know.

      1 Reply Last reply Reply Quote 0
      • S Offline
        spectre694
        last edited by

        So switching to DNS forwarder instead of the DNS resolver seems to have solved the issue.

        1 Reply Last reply Reply Quote 0
        • johnpozJ Offline
          johnpoz LAYER 8 Global Moderator
          last edited by

          "WAN [SAT]"  So you mean satellite here, its quite possible on a sat connection your latency is so high that trying to actually resolve would be very problematic.  Resolving means walk the tree to get to the authoritative server for the domain.  So say you wanted to look up www.domain.com.  You would first ask roots, hey roots who do I ask for .com, they would point you to those nameservers, you would go ask them hey who do I ask for domain.com, they would give you the ns for that domain, you would then go directly ask one of those ns for the www record.

          Depending on the domain that NS for that domain might be shitty, or long way away anyway.  Having high latency network could cause problems with that.  While when you forward, your just asking a specific name server hey what is IP for www.domain.com, he most likely has it cached and just gives that IP to you directly.

          Its also possible that your ISP blocks access to dns to anything other than their nameservers, this also breaks resolving.

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.