Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiple VLANs with different DNS for each VLAN

    Scheduled Pinned Locked Moved DHCP and DNS
    2 Posts 2 Posters 1.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      NickyDoes
      last edited by

      Objective: Two separate networks (VLAN, wifi SSIDs) - one unrestricted, one for kids.

      Restriction summary: Time, MAC address, DNS resolution

      Equipment & tech: pfSense, UniFi, Ubiquiti wifi access point, OpenDNS

      The two VLANs are configured through to the wifi access points. pfSense is configured with two networks via two interfaces: Unrestricted interface, kids interface. Both are also on different subnets and have different DHCP configurations.

      Devices getting IP addresses from the kids' DHCP get configured with DNS addresses from OpenDNS. Devices querying the unrestricted DHCP get DNS from a local BIND server.

      I am at the end of my expertise on how to set up pfSense to forward DNS requests from the kids' network to OpenDNS while allowing requests from the unrestricted network to go to Google DNS. For the kids' network, I must also block DNS requests made to alternate servers.

      I appreciate any help you provide.

      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        In the dhcp server hand out what ever dns you want the dhcp clients to use.  On the firewall rules for that vlan only allow dns to what your handing out. Block all other dns.

        Remember rules are evaluated top down, first rule to trigger wins no other rules are evaluated.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.