Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DNS - Removing Service Provider Defauits

    Scheduled Pinned Locked Moved DHCP and DNS
    16 Posts 5 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C Offline
      CaladorGCS
      last edited by

      @Derelict:

      Are you using the DNS Forwarder or the DNS Resolver?

      You can prevent ISP/DHCP DNS servers from being added to the list of DNS Servers used by the firewall itself and DNS Resolver (In forwarding mode) or the DNS Forwarder by unchecking "DNS Server Override" in System > General Setup.

      You have to figure out how you want your DNS to work and can either configure your chosen DNS servers for direct use by the clients (in the DHCP server configuration) or use by the DNS Forwarder (or the Resolver in forwarding mode) (In System > General).

      If the clients are set to use pfSense as their DNS server and the Resolver is in Resolver mode, it will query the internet from the root down to fill its cache, but it won't use your configured list of servers.

      There are a lot of different ways to configure this and one might be completely wrong for certain circumstances and perfect for others.

      Thank you this was of great help! And… to answer your question, I'm using the DNS Resolver.

      pfSense© running on…

      • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

      • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

      Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
      Access Point - (2) Unifi 802.11ac Dual-Radio PRO

      1 Reply Last reply Reply Quote 0
      • DerelictD Offline
        Derelict LAYER 8 Netgate
        last edited by

        That's great, but there is a lot more to it than that.

        Is the resolver in resolver or forwarding mode?

        If it is in resolver mode, then your selected DNS servers will not be used in any capacity other than for queries made by the firewall itself.

        Client queries to your resolver will start at the roots and work down to resolve all names not already in its cache.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • C Offline
          CaladorGCS
          last edited by

          @Derelict:

          That's great, but there is a lot more to it than that.

          Is the resolver in resolver or forwarding mode?

          If it is in resolver mode, then your selected DNS servers will not be used in any capacity other than for queries made by the firewall itself.

          Client queries to your resolver will start at the roots and work down to resolve all names not already in its cache.

          Under - System > General Setup> DNS Server Settings
          DNS Server Override is checked
          Disable DNS Forwarder is unchecked

          Under - Services > DNS Forwarder > General DNS Forwarder Options
          Enable DNS forwarder is unchecked

          Under - Services > DNS Resolver > General Settings > General DNS Resolver Options
          Enable DNS forwarder is checked

          pfSense© running on…

          • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

          • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

          Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
          Access Point - (2) Unifi 802.11ac Dual-Radio PRO

          1 Reply Last reply Reply Quote 0
          • DerelictD Offline
            Derelict LAYER 8 Netgate
            last edited by

            One more piece. What DNS servers are you telling your inside clients to use? This is in the DHCP servers or static client configurations.

            Bottom line is if you are using the Resolver you might as well just give up trying to use "highest-performing" DNS servers. The resolver will use what the internet tells it to use. If you are using either DNS resolver or forwarder, once something is in the cache it will be given to inside clients nearly-instantaneously anyway. This probably falls into the "don't overthink it" category.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • C Offline
              CaladorGCS
              last edited by

              @Derelict:

              One more piece. What DNS servers are you telling your inside clients to use? This is in the DHCP servers or static client configurations.

              Bottom line is if you are using the Resolver you might as well just give up trying to use "highest-performing" DNS servers. The resolver will use what the internet tells it to use. If you are using either DNS resolver or forwarder, once something is in the cache it will be given to inside clients nearly-instantaneously anyway. This probably falls into the "don't overthink it" category.

              I didn't input any DNS servers on that list, just left them all blank.

              pfSense© running on…

              • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

              • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

              Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
              Access Point - (2) Unifi 802.11ac Dual-Radio PRO

              1 Reply Last reply Reply Quote 0
              • C Offline
                CaladorGCS
                last edited by

                1st image -    System > General Setup > DNS Server Settings

                2nd image -  Services > DHCP Server > LAN > Server

                pfSenseGen.PNG
                pfSenseGen.PNG_thumb
                pfSenseSer.PNG
                pfSenseSer.PNG_thumb

                pfSense© running on…

                • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

                • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

                Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
                Access Point - (2) Unifi 802.11ac Dual-Radio PRO

                1 Reply Last reply Reply Quote 0
                • pttP Offline
                  ptt Rebel Alliance
                  last edited by

                  Just "Uncheck"  Allow DNS server list to be overridden by DHCP/PPP on WAN

                  DNS.PNG_thumb
                  DNS.PNG

                  1 Reply Last reply Reply Quote 0
                  • DerelictD Offline
                    Derelict LAYER 8 Netgate
                    last edited by

                    It is up to you how to design your DNS. What is it you are looking for? What are you looking to accomplish?

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • C Offline
                      CaladorGCS
                      last edited by

                      Nice, that definitely took care of them!
                      DNS server(s)

                      127.0.0.1
                        63.251.129.1
                        68.105.28.11
                        156.154.71.22
                        8.8.8.8

                      Mostly just trying to get as secure as possible without affecting the speed I love so much.

                      Thank you so much! For your time and patience!

                      pfSense© running on…

                      • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

                      • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

                      Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
                      Access Point - (2) Unifi 802.11ac Dual-Radio PRO

                      1 Reply Last reply Reply Quote 0
                      • C Offline
                        CaladorGCS
                        last edited by

                        @Derelict:

                        It is up to you how to design your DNS. What is it you are looking for? What are you looking to accomplish?

                        I need to read up more on the different DNS setups so I can really figure that out. "Secure as possible without affecting the speed" sounds too general for what your asking.

                        pfSense© running on…

                        • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

                        • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

                        Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
                        Access Point - (2) Unifi 802.11ac Dual-Radio PRO

                        1 Reply Last reply Reply Quote 0
                        • T Offline
                          TS_b Banned
                          last edited by

                          https://calomel.org/unbound_dns.html

                          1 Reply Last reply Reply Quote 0
                          • C Offline
                            CaladorGCS
                            last edited by

                            @TS_b:

                            https://calomel.org/unbound_dns.html

                            Thank you!

                            pfSense© running on…

                            • CPU: Intel Core i5-5250U Processor (3M Cache, up to 2.70GHz, Broadwell) + Intel 4 GBit LAN

                            • Configuration: RAM 8GB DDR3; SSD 128GB; AES-NI; Hyperthreaded; Model: Qotom-Q355G4

                            Switch - NETGEAR ProSAFE JGS516PE 16-Port Gigabit PoE WM (Plus) & GS105Ev2 5-Port WM (Plus)
                            Access Point - (2) Unifi 802.11ac Dual-Radio PRO

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.