Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    DNS server address settings using DNS resolver

    General pfSense Questions
    2
    9
    973
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Q
      qu101 last edited by

      Been trying for some time to use DNS resolver (unbound - with pfblocker)

      Need to use non ISP provided DNS servers

      using OPENVPN interface  for most of the time so everything is thru that connection. (tried using openvpn client override with no luck)

      Worked fine when set in the DNS forwarder bit BUT when using resolver I cant find where to put theDNS server addresses to force the use of these servers .

      obviously missing something here so ant suggestions would be greatly appreciated

      1 Reply Last reply Reply Quote 0
      • johnpoz
        johnpoz LAYER 8 Global Moderator last edited by

        "when using resolver I cant find where to put theDNS server addresses to force the use of these servers ."

        So you just not understanding what a resolver is then??  Why would you be setting dns with a resolver to use specific servers?  Resolver does that it resolves, it doesn't forward.  So it walks its way down from roots to the authoritative server for the domain your looking for..

        Are you wanting to use unbound in forwarder mode?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        2440 2.4.5p1 | 2x 3100 2.4.4p3 | 2x 3100 22.01 | 4860 22.01

        1 Reply Last reply Reply Quote 0
        • Q
          qu101 last edited by

          You're quite right my understanding of it is very poor and just fumbling around attempting to understand how it all functions BUT with a little help the result is way better than whats available in the consumer market!

          Looks like if I enable forwarding mode on the resolver my DNS is restored -Thanks!

          1 Reply Last reply Reply Quote 0
          • johnpoz
            johnpoz LAYER 8 Global Moderator last edited by

            And forwarder mode to be honest in unbound is kind of pointless.. If your not going to use use unbound as resolver might as well just use the forwarder.  It allows you to forward to all the ns you have set at the same time and use the one that answers fastest for example.

            Unbound doesn't do that.

            Why can you not just use resolver mode - this gives you full dnssec support and you know your getting what your asking for from the horses mouth.. Not just some nameserver you asked hey whats in your cache for www.something.com

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            2440 2.4.5p1 | 2x 3100 2.4.4p3 | 2x 3100 22.01 | 4860 22.01

            1 Reply Last reply Reply Quote 0
            • Q
              qu101 last edited by

              This is prob due to my lack of understanding BUT was under the impression that in order to use DNSBL in pfblocker the forwarder must be used which was the beginning of the problem. This was why I was using using Unbound. (all I required is a adblock plus result at a network level)

              1 Reply Last reply Reply Quote 0
              • johnpoz
                johnpoz LAYER 8 Global Moderator last edited by

                no for dnsbl to work, you have to use unbound but you sure and the hell do not need to put it in forwarder mode.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                2440 2.4.5p1 | 2x 3100 2.4.4p3 | 2x 3100 22.01 | 4860 22.01

                1 Reply Last reply Reply Quote 0
                • Q
                  qu101 last edited by

                  Im confused….

                  But without having it in forwarder mode how do I enforce my DNS servers

                  So my question is how can I set all DNS requests to go to the DNS servers I have set in the General setting whilst using DNSBL?

                  1 Reply Last reply Reply Quote 0
                  • johnpoz
                    johnpoz LAYER 8 Global Moderator last edited by

                    Why can you not just let unbound resolve how its suppose to?  Why do you give a shit that dns has to come from some chaching server??

                    But if have your heart set on just asking ns abc for everything, then yes use unbound in forwarder mode..

                    "Need to use non ISP provided DNS servers "

                    You have to use these WHY???

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    2440 2.4.5p1 | 2x 3100 2.4.4p3 | 2x 3100 22.01 | 4860 22.01

                    1 Reply Last reply Reply Quote 0
                    • Q
                      qu101 last edited by

                      well…... anonymity:  where I live the Government insists on keeping a record of everything done online so using the ISP DNS server will have every request logged  (not that the like NSA dont have a direct link to pretty much everything) And google is not much better.

                      But some kinda separation is comforting as is an anonymous VPN  - So really anything that will make data collection harder an more costly has to be good!

                      Actually not concerned over cashing - just thought DNSBL was an useful addition to blocking stuff- maybe Ive missed something?

                      Thanks for your help!

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post