Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    No traffic on DNS rule?

    Scheduled Pinned Locked Moved Traffic Shaping
    7 Posts 3 Posters 5.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      gratis.obake
      last edited by

      Greetings everyone!

      Going direct to the problem, I have images (attachments) below that will tell all. Its my Traffic Shaper, My Floating, and a putty session to my pfSense box accessing pfTOP.

      as you can see from the pfTop screenshot, no traffic is passing to my qDNS queue, what I did wrong?

      floating rule is placed to the bottom most place and also have a "quick" enabled

      I also did a reset states but it will still not have a traffic for qDNS.

      can anyone help out?
      trafficSHAPER.png
      trafficSHAPER.png_thumb
      floating.png
      floating.png_thumb
      pfTOP.png
      pfTOP.png_thumb

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        Quick means nothing on a match rule (if processing stopped there the traffic would never be passed). Something else must be matching the traffic. What interface(s) are those rules on?

        I would put those on floating WAN out without being source limited. Unless you want to prefer DNS queries for one LAN and not another.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • G
          gratis.obake
          last edited by

          If quick does do nothing, then why its there?

          I will try to see it again the rules regarding if there are any rules that may match it, but I have read that somewhere here on the forums that on floating rules last match wins, that is why I placed it on the bottom part.

          on your last paragraph, how can I implement that? and I don't clearly understand it, I hope you can shed more info on this, thanks

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            On your floating rules, for each one change the interface to WAN, and set the Source from LAN net to any.

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              Quick is here for pass and block rules.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • G
                gratis.obake
                last edited by

                @KOM:

                On your floating rules, for each one change the interface to WAN, and set the Source from LAN net to any.

                thank you on that info, let me try that out.

                @Derelict:

                Quick is here for pass and block rules.

                thank you as well for this, I will note it.
                Anyways, should it be also reflected on the pfSense docs?

                1 Reply Last reply Reply Quote 0
                • G
                  gratis.obake
                  last edited by

                  @KOM:

                  On your floating rules, for each one change the interface to WAN, and set the Source from LAN net to any.

                  okay, I have cheated a bit and only changed my qDNS entires, qDNS now is populated and it seems to work now as I try to browse the net and try to observe it (refer to attached image).

                  and for what I notice, qDNS on the LAN side does not have any activity, is this okay?

                  pfTop.png
                  pfTop.png_thumb

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.