No traffic on DNS rule?



  • Greetings everyone!

    Going direct to the problem, I have images (attachments) below that will tell all. Its my Traffic Shaper, My Floating, and a putty session to my pfSense box accessing pfTOP.

    as you can see from the pfTop screenshot, no traffic is passing to my qDNS queue, what I did wrong?

    floating rule is placed to the bottom most place and also have a "quick" enabled

    I also did a reset states but it will still not have a traffic for qDNS.

    can anyone help out?






  • LAYER 8 Netgate

    Quick means nothing on a match rule (if processing stopped there the traffic would never be passed). Something else must be matching the traffic. What interface(s) are those rules on?

    I would put those on floating WAN out without being source limited. Unless you want to prefer DNS queries for one LAN and not another.



  • If quick does do nothing, then why its there?

    I will try to see it again the rules regarding if there are any rules that may match it, but I have read that somewhere here on the forums that on floating rules last match wins, that is why I placed it on the bottom part.

    on your last paragraph, how can I implement that? and I don't clearly understand it, I hope you can shed more info on this, thanks



  • On your floating rules, for each one change the interface to WAN, and set the Source from LAN net to any.


  • LAYER 8 Netgate

    Quick is here for pass and block rules.



  • @KOM:

    On your floating rules, for each one change the interface to WAN, and set the Source from LAN net to any.

    thank you on that info, let me try that out.

    @Derelict:

    Quick is here for pass and block rules.

    thank you as well for this, I will note it.
    Anyways, should it be also reflected on the pfSense docs?



  • @KOM:

    On your floating rules, for each one change the interface to WAN, and set the Source from LAN net to any.

    okay, I have cheated a bit and only changed my qDNS entires, qDNS now is populated and it seems to work now as I try to browse the net and try to observe it (refer to attached image).

    and for what I notice, qDNS on the LAN side does not have any activity, is this okay?



Log in to reply