Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    1 out of 40 hostnames in alias list not passing yet IP matches

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 5 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      JimPhreak
      last edited by

      I've got an alias list of 40 dynamic DNS hostnames which are allowed inbound on my network over a specific port via a NAT/firewall rule.  However, there is one hostname whose associated IP address always gets blocked inbound over the allowed port.  When I do a DNS lookup for the hostname, the returned IP matches the one showing up in the blocks in the firewall.  All 39 other hostnames pass without issue.  I've tried removing the entry from the alias list and recreating it with no change.

      Not sure where to go from here…

      1 Reply Last reply Reply Quote 0
      • N Offline
        NOYB
        last edited by

        @JimPhreak:

        I've got an alias list of 40 dynamic DNS hostnames…
        there is one hostname whose associated IP address always gets blocked... 
        All 59 other hostnames pass without issue. ...

        Not sure where to go from here...

        Math class.

        1 Reply Last reply Reply Quote 0
        • J Offline
          JimPhreak
          last edited by

          @NOYB:

          @JimPhreak:

          I've got an alias list of 40 dynamic DNS hostnames…
          there is one hostname whose associated IP address always gets blocked... 
          All 59 other hostnames pass without issue. ...

          Not sure where to go from here...

          Math class.

          Thanks for the productive reply.

          1 Reply Last reply Reply Quote 0
          • M Offline
            mer
            last edited by

            Without more information, everything is conjecture:
            It's getting blocked by the default deny rule?
            Are you sure your rules are ordered correctly? User added rules are first match wins.
            Have you tried adding the same rule, with just the host name in question in the alias to rule out anything in the web interface mucking things up?
            Have you considered posting screenshots of the rules and ip alias and firewall logs to give others more information to try and help?

            1 Reply Last reply Reply Quote 0
            • H Offline
              Harvy66
              last edited by

              @JimPhreak:

              @NOYB:

              @JimPhreak:

              I've got an alias list of 40 dynamic DNS hostnames…
              there is one hostname whose associated IP address always gets blocked... 
              All 59 40 other hostnames pass without issue. …

              Not sure where to go from here...

              Math class.

              Thanks for the productive reply.

              You allow 40 DNS entries to pass, you have 59 that you need, and one of them is not working. At least this is what you've described based on your words.

              DNS is not meant to be used as a canonical source for everything. It is only meant to return a subset of valid responses. Sometimes that subset is the whole set, but many times it is not. I would not recommend using DNS.

              When you said "you" do a DNS lookup, from where? DNS can give different responses at any time to any client.

              1 Reply Last reply Reply Quote 0
              • J Offline
                JimPhreak
                last edited by

                @Harvy66:

                @JimPhreak:

                @NOYB:

                @JimPhreak:

                I've got an alias list of 40 dynamic DNS hostnames…
                there is one hostname whose associated IP address always gets blocked... 
                All 59 other hostnames pass without issue. ...

                Not sure where to go from here...

                Math class.

                Thanks for the productive reply.

                You allow 40 DNS entries to pass, you have 59 that you need, and one of them is not working. At least this is what you've described based on your words.

                DNS is not meant to be used as a canonical source for everything. It is only meant to return a subset of valid responses. Sometimes that subset is the whole set, but many times it is not. I would not recommend using DNS.

                When you said "you" do a DNS lookup, from where? DNS can give different responses at any time to any client.

                First off the 59 was a typo which I've corrected.

                Secondly, I mentioned Dynamic DNS hostnames.  These are setup since the incoming IP addresses change from time to time.  When I do a DNS lookup it's being done on pfSense.  So IP address 78.2.24.87 for example is being blocked inbound.  However, a DNS Lookup on pfSense shows that IP matches hostname mydomain.com which is in the alias list of allowed hostnames.

                1 Reply Last reply Reply Quote 0
                • DerelictD Offline
                  Derelict LAYER 8 Netgate
                  last edited by

                  Diagnostics > Tables will show you the actual contents of the alias. That should show you what's up.

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    JimPhreak
                    last edited by

                    @Derelict:

                    Diagnostics > Tables will show you the actual contents of the alias. That should show you what's up.

                    The same IP that's shown from a DNS lookup shows up in the table for that alias list.

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      JimPhreak
                      last edited by

                      Removing the hostname from the alias, rebooting, and re-adding seems to have resolved the issue.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.